Skip to content

Commit c71a692

Browse files
committed
AIR
1 parent f30ded7 commit c71a692

File tree

2 files changed

+33
-32
lines changed

2 files changed

+33
-32
lines changed

defender-office-365/air-about.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ An alert is triggered, and a security playbook starts an automated investigation
6767
During and after each automated investigation, the SecOps team can do the following tasks:
6868

6969
- [View details about an alert related to an investigation](air-view-investigation-results.md#view-details-about-an-alert-related-to-an-investigation)
70-
- [View the results details of an investigation](air-view-investigation-results.md#view-investigation-details-in-the-defender-portal-from-air-in-defender-for-office-365)
70+
- [View the results details of an investigation](air-view-investigation-results.md#view-investigation-details-from-air-in-defender-for-office-365-plan-2)
7171
- [Review and approve actions as a result of an investigation](air-review-approve-pending-completed-actions.md)
7272

7373
## Required permissions and licensing for AIR
@@ -96,6 +96,6 @@ AIR contains data for users with Defender for Office 365 licenses assigned to th
9696
## Next steps
9797

9898
- [AIR examples](air-examples.md)
99-
- [See details and results of an automated investigation](air-view-investigation-results.md#view-investigation-details-in-the-defender-portal-from-air-in-defender-for-office-365)
99+
- [See details and results of an automated investigation](air-view-investigation-results.md#view-investigation-details-from-air-in-defender-for-office-365-plan-2)
100100
- [Review and approve pending actions](air-remediation-actions.md)
101101
- [View pending or completed remediation actions](air-review-approve-pending-completed-actions.md)

defender-office-365/air-view-investigation-results.md

Lines changed: 31 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ By default, investigation details from yesterday and today are shown, but you ca
4242

4343
The following information shown on the **Investigations** page. You can sort the entries by clicking on an available column header. Select :::image type="icon" source="media/m365-cc-sc-customize-icon.png" border="false"::: **Customize columns** to change the columns that are shown. By default, all available columns are selected:
4444

45-
- **ID**: The unique ID of the investigation. Select :::image type="icon" source="media/m365-cc-sc-copy-icon.png" border="false"::: **Open in new window** to open the details of the investigation as described in the [View investigation details](#view-investigation-details-from-air-in-defender-for-office-365) section.
45+
- **ID**: The unique ID of the investigation. Select :::image type="icon" source="media/m365-cc-sc-copy-icon.png" border="false"::: **Open in new window** to open the details of the investigation as described in the [View investigation details](#view-investigation-details-from-air-in-defender-for-office-365-plan-2) section.
4646
- **Status**: The available status values are described in the [Investigation Status values](#investigation-status-values) section.
4747
- **Detection Source**: This value is always **Office365**.
4848
- **Investigation**
@@ -91,7 +91,7 @@ The **Status** values that are used in investigations are described in the follo
9191

9292
- **Failed**: At least one investigation analyzer ran into a problem where it couldn't complete properly.
9393

94-
If an investigation fails after remediation actions were approved, the remediation actions might still have succeeded. For more information, [view the investigation details](#view-investigation-details-from-air-in-defender-for-office-365).
94+
If an investigation fails after remediation actions were approved, the remediation actions might still have succeeded. For more information, [view the investigation details](#view-investigation-details-from-air-in-defender-for-office-365-plan-2).
9595

9696
- **No Threats Found**: The investigation finished and no threats were identified (compromised user accounts, email messages, URLs, or files).
9797

@@ -112,15 +112,15 @@ The **Status** values that are used in investigations are described in the follo
112112

113113
- **Pending Action**: The investigation found a threat (for example, a malicious email, a malicious URL, or a risky mailbox setting), and an action to remediate the threat is [awaiting approval](air-review-approve-pending-completed-actions.md).
114114

115-
The list of pending actions can increase as an investigation runs. [View the investigation details](#view-investigation-details-from-air-in-defender-for-office-365) to see if other items are still pending completion.
115+
The list of pending actions can increase as an investigation runs. [View the investigation details](#view-investigation-details-from-air-in-defender-for-office-365-plan-2) to see if other items are still pending completion.
116116

117117
- **Queued By Throttling**: An investigation is being held in a queue. When other investigations complete, queued investigations begin. Throttling helps avoid poor service performance.
118118

119119
Pending actions can limit how many new investigations can run. Make sure to [approve or reject pending actions](air-review-approve-pending-completed-actions.md#approve-or-reject-pending-actions-from-the-investigations-page-in-defender-for-office-365).
120120

121121
- **Remediated**: The investigation finished and all remediation actions were approved (noted as fully remediated).
122122

123-
Approved remediation actions can have errors that prevent the actions from being taken. Regardless of whether remediation actions are successfully completed, the investigation status doesn't change. For more information, [view the investigation details](#view-investigation-details-from-air-in-defender-for-office-365).
123+
Approved remediation actions can have errors that prevent the actions from being taken. Regardless of whether remediation actions are successfully completed, the investigation status doesn't change. For more information, [view the investigation details](#view-investigation-details-from-air-in-defender-for-office-365-plan-2).
124124

125125
- **Running**: The investigation process is underway. This status value also occurs when [pending actions](air-review-approve-pending-completed-actions.md#approve-or-reject-pending-actions-from-the-investigations-page-in-defender-for-office-365) are approved.
126126

@@ -136,7 +136,7 @@ The **Status** values that are used in investigations are described in the follo
136136

137137
You can [start an investigation from Threat Explorer (Explorer)](air-examples.md#example-a-security-administrator-triggers-an-investigation-from-threat-explorer).
138138

139-
## View investigation details from AIR in Defender for Office 365
139+
## View investigation details from AIR in Defender for Office 365 Plan 2
140140

141141
When you select :::image type="icon" source="media/m365-cc-sc-copy-icon.png" border="false"::: **Open in new window** in the **ID** column of an entry on the **Investigations** page at <https://security.microsoft.com/airinvestigation>, a new page opens with the investigation details.
142142

@@ -258,30 +258,31 @@ Clicking anywhere else in the row other than the check box next to the first col
258258
#### Manage alert
259259

260260
:::image type="icon" source="media/m365-cc-sc-edit-icon.png" border="false"::: **Manage alert**: Opens a **Manage alert** flyout where you can view and modify details about the incident. You can modify the following alert properties:
261-
- **Status**: Select one of the following values:
262-
- **New**
263-
- **In progress**
264-
- **Resolved**
265-
- **Classification**: Select one of the following values:
266-
- **Not set**
267-
- **True positive** section:
268-
- **Multi staged attack**
269-
- **Malware**
270-
- **Malicious user activity**
271-
- **Unwanted software**
272-
- **Phishing**
273-
- **Compromised account**
274-
- **Other**
275-
- **Informational, expected activity** section:
276-
- **Security testing**
277-
- **Confirmed activity**
278-
- **Line of business application**
279-
- **Other**
280-
- **False positive** section:
281-
- **Not malicious**
282-
- **Not enough data to validate**
283-
- **Other**
284-
- **Comment**: Enter an optional comment.
261+
262+
- **Status**: Select one of the following values:
263+
- **New**
264+
- **In progress**
265+
- **Resolved**
266+
- **Classification**: Select one of the following values:
267+
- **Not set**
268+
- **True positive** section:
269+
- **Multi staged attack**
270+
- **Malware**
271+
- **Malicious user activity**
272+
- **Unwanted software**
273+
- **Phishing**
274+
- **Compromised account**
275+
- **Other**
276+
- **Informational, expected activity** section:
277+
- **Security testing**
278+
- **Confirmed activity**
279+
- **Line of business application**
280+
- **Other**
281+
- **False positive** section:
282+
- **Not malicious**
283+
- **Not enough data to validate**
284+
- **Other**
285+
- **Comment**: Enter an optional comment.
285286

286287
When you're finished in the **Manage alert** flyout, select **Save**
287288

@@ -576,7 +577,7 @@ Certain kinds of alerts trigger automated investigation in Microsoft 365. To lea
576577
1. On the **Action center** page, use the **Pending** or **History** tabs to find the action.
577578
1. Select an action from the table by selecting the link in the **Investigation ID** column.
578579

579-
The [investigation details page](#view-investigation-details-from-air-in-defender-for-office-365) opens.
580+
The [investigation details page](#view-investigation-details-from-air-in-defender-for-office-365-plan-2) opens.
580581

581582
## Keep the following points in mind
582583

0 commit comments

Comments
 (0)