Skip to content

Commit d0dee94

Browse files
Merge pull request #3411 from MicrosoftDocs/main
Publish main to live, 04/08, 11:00 AM IST
2 parents 74a45a5 + c5695a8 commit d0dee94

9 files changed

+142
-2
lines changed

defender-office-365/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -460,6 +460,8 @@
460460
href: air-remediation-actions.md
461461
- name: Review and approve (or reject) pending actions
462462
href: air-review-approve-pending-completed-actions.md
463+
- name: Automated remediation in AIR
464+
href: air-auto-remediation.md
463465
- name: Detect and address compromised user accounts in AIR
464466
href: address-compromised-users-quickly.md
465467
- name: Integrate AIR with a custom solution or third-party solution
Lines changed: 138 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,138 @@
1+
---
2+
title: Automated remediation in AIR
3+
f1.keywords:
4+
- NOCSH
5+
author: chrisda
6+
ms.author: chrisda
7+
manager: deniseb
8+
audience: ITPro
9+
ms.topic: conceptual
10+
ms.localizationpriority: medium
11+
search.appverid:
12+
- MET150
13+
- MOE150
14+
ms.collection:
15+
- m365-security
16+
- tier2
17+
description: "Learn about automated remediation in automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2."
18+
ms.date: 04/07/2025
19+
ms.custom:
20+
- air
21+
ms.service: defender-office-365
22+
appliesto:
23+
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 2</a>
24+
- ✅ <a href="https://learn.microsoft.com/defender-xdr/microsoft-365-defender" target="_blank">Microsoft Defender XDR</a>
25+
---
26+
27+
# Automated remediation in Automated investigation and response (AIR)
28+
29+
[!INCLUDE [MDO Trial banner](../includes/mdo-trial-banner.md)]
30+
31+
> [!TIP]
32+
> The features described in this article are currently in Private Preview, aren't available in all organization, and are subject to change.
33+
34+
By default, remediation actions identified by automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2 require approval by security operations (SecOps) teams. For more information about AIR, see [Automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2](air-about.md)
35+
36+
Now, admins can also designate certain actions to automatically remediate. Automatically remediating messages identified as malicious in AIR investigations has the following benefits:
37+
38+
- Increases customer protection by expediting remediation of more threats.
39+
40+
- Saves time for SecOps teams by reducing the need for approval.
41+
42+
The rest of this article describes how to configure automated remediation in AIR and how to identify messages that were automatically remediated.
43+
44+
## Configure automated remediation
45+
46+
AIR creates a cluster around a detected malicious file or URL, and then the automated investigation checks the location of messages within the cluster. If the messages are in mailboxes, AIR produces a remediation action.
47+
48+
After you select the cluster types to automatically remediate, the selected remediation action occurs without the need for SecOps approval.
49+
50+
> [!TIP]
51+
> Clusters produced by AIR that don't automatically remediate still show as **Pending action** as they do today.
52+
>
53+
> Clusters larger than 10,000 messages don't automatically remediate and show as **Pending action** for review.
54+
55+
Use the following steps to select the cluster types to automatically remediate:
56+
57+
In the Microsoft Defender portal at <https://security.microsoft.com>, go to **Settings** \> **Email & collaboration** \> **MDO automation settings**.
58+
59+
The following settings are available on the **Automation settings** page:
60+
61+
- **Message clusters** section: Specifies the types of message clusters that are automatically remediated. Choose one or more of the following options:
62+
- **Similar files:** When the automated investigation recognizes a malicious file, it creates a cluster around the malicious file. The cluster groups all messages that contain the file into the cluster. Selecting this setting opts the organization in to automated remediation for these malicious file clusters.
63+
- **Similar URLs:** When the automated investigation recognizes a malicious URL, it creates a cluster around the malicious URL. The cluster groups all messages that contain the URL into the cluster. Selecting this setting opts the organization in to automated remediation for these malicious URL clusters.
64+
65+
> [!TIP]
66+
> Follow the roadmap to stay informed on when more message clusters are available for automated remediation.
67+
68+
- **Remediation action** section: Specifies the action to take on message cluster types specified in the **Message clusters** section.
69+
70+
Currently, **Soft delete** is the only available action. For more information about soft deleted messages, see [Recoverable Items folder in Exchange Online](/exchange/security-and-compliance/recoverable-items-folder/recoverable-items-folder).
71+
72+
> [!IMPORTANT]
73+
> The ability to recover soft deleted messages depends on the retention policy for soft deleted messages in each mailbox. Verify your legal obligations for email retention, including messages marked as malicious. For more information on the retention of soft deleted messages, see [Change how long permanently deleted items are kept for an Exchange Online mailbox in Exchange Online](/exchange/recipients-in-exchange-online/manage-user-mailboxes/change-deleted-item-retention).
74+
75+
When you're finished on the **Automation settings** page, select **Save**.
76+
77+
:::image type="content" source="media/auto-air-mdo-automation-settings.png" alt-text="Screenshot of automated remediation of malicious entity clusters configuration in the Defender portal at Settings \> Email & collaboration \> MDO automation settings." lightbox="media/auto-air-mdo-automation-settings.png":::
78+
79+
## Review automatically remediated messages
80+
81+
The following subsection shows how to use the Defender portal to review automated remediation actions.
82+
83+
### Automated remediation results in the Action center
84+
85+
In the Action center at <https://security.microsoft.com/action-center/>, automatically remediated clusters appear on the **History** tab. Use the **Decided by** filter with the value **Automation** to return clusters that were automatically remediated.
86+
87+
For more information about the Action center, see [The Action center](/defender-xdr/m365d-action-center).
88+
89+
:::image type="content" source="media/auto-air-mdo-action-center.png" alt-text="Screenshot of the History tab in the Action center with automatically remediated clusters filtered by the Decided by value Automation and the Action source value Automated email action." lightbox="media/auto-air-mdo-action-center.png":::
90+
91+
### Automated remediation results in investigations
92+
93+
Within an investigation in AIR, automatically remediated clusters appear on the **Pending action history** tab of the investigation with the **Handled by** value **Automation**.
94+
95+
For more information about AIR investigation results, see [Details and results of automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2](air-view-investigation-results.md).
96+
97+
:::image type="content" source="media/auto-air-mdo-investigations.png" alt-text="Screenshot of the Pending actions history tab of an investigation with automatically remediated clusters with the Handled by value Automation." lightbox="media/auto-air-mdo-investigations.png":::
98+
99+
### Automated remediation results in Threat Explorer
100+
101+
In Threat Explorer (Explorer), automatically remediated messages have the **Additional action** value **Automated remediation:automated**.
102+
103+
For more information about Threat Explorer, see [About Threat Explorer and Real-time detections in Microsoft Defender for Office 365](threat-explorer-real-time-detections-about.md).
104+
105+
:::image type="content" source="media/auto-air-mdo-threat-explorer.png" alt-text="Screenshot of Threat Explorer showing messages that automated remediation deleted from the mailbox by automated remediation (filtered by the Additional action value Automated remediation)." lightbox="media/auto-air-mdo-threat-explorer.png":::
106+
107+
### Automated remediation results in Advanced hunting
108+
109+
In Advanced hunting, automatically remediated messages are in the `EmailPostDeliveryEvents` table with both of the following property values:
110+
111+
- `ActionType` equals **Automated Remediation**
112+
- `ActionTrigger` equals **Automation**.
113+
114+
For more information about Advanced hunting, see [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview).
115+
116+
:::image type="content" source="media/auto-air-mdo-advanced-hunting.png" alt-text="Screenshot of Advanced hunting for messages removed from mailboxes by automated remediation (EmailPostDeliveryEvents table where the ActionType value is Automated Remediation and the ActionTrigger value is Automation.)" lightbox="media/auto-air-mdo-advanced-hunting.png":::
117+
118+
## Revert automated remediation actions on messages
119+
120+
> [!NOTE]
121+
> The ability to recover messages depends on the data still being available in Defender and the mailbox retention settings for soft deleted messages. For more information, see the following articles:
122+
>
123+
> - [Data retention information for Microsoft Defender for Office 365](/defender-office-365/mdo-data-retention)
124+
> - [Recoverable Items folder in Exchange Online](/exchange/security-and-compliance/recoverable-items-folder/recoverable-items-folder)
125+
> - [Change how long permanently deleted items are kept for an Exchange Online mailbox in Exchange Online](/exchange/recipients-in-exchange-online/manage-user-mailboxes/change-deleted-item-retention)
126+
127+
The following methods are available to revert automated remediation actions and restore messages to mailboxes:
128+
129+
- :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: **Take action** on the message in Threat Explorer or Advanced Hunting. For information about the **Take action** wizard, see [The Take action wizard](threat-explorer-threat-hunting.md#the-take-action-wizard).
130+
- The **Move to Inbox** or :::image type="icon" source="media/m365-cc-sc-more-actions-icon.png" border="false"::: \> **Move to Junk** actions in the cluster property details flyout on **History** tab of the Action center as shown in the following screenshot:
131+
132+
:::image type="content" source="media/auto-air-mdo-action-center-cluster-details.png" alt-text="Screenshot of the details flyout of an automatically remediated email cluster showing the available Move to Inbox action to undo the automated remediation action and restore messages to mailboxes." lightbox="media/auto-air-mdo-action-center-cluster-details.png":::
133+
134+
## See also
135+
136+
- [AIR in Defender for Office 365 Plan 2](air-about.md)
137+
- [Review and manage remediation actions in AIR in Defender for Office 365 Plan 2](air-review-approve-pending-completed-actions.md)
138+
- [Remediate malicious email delivered in Office 365](remediate-malicious-email-delivered-office-365.md)
75.3 KB
Loading
51.3 KB
Loading
112 KB
Loading
30.2 KB
Loading
89.5 KB
Loading
82.2 KB
Loading

defender-xdr/before-you-begin-xdr.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 04/07/2025
20+
ms.date: 04/08/2025
2121
---
2222

2323
# Before you begin
@@ -77,7 +77,7 @@ The following sections enumerate additional information about the service's data
7777

7878
All data used for hunting from existing Defender services will continue to reside in the customer's original Microsoft Defender XDR service storage location. [Learn more](/microsoft-365/enterprise/o365-data-locations).
7979

80-
Defender Experts for XDR operational data, such as case tickets and analyst notes, are generated and stored in a Microsoft data center in the US region for US customers and in the European Union for EU customers for the length of the service, irrespective of the Microsoft Defender XDR service storage location. Data generated for the reporting dashboard is stored in customer's Microsoft Defender XDR service storage location. Reporting data and operational data will be retained for a grace period of no more than 90 days after a customer's subscription expires. If the customer terminates their subscription, data will be deleted within 30 days.
80+
Defender Experts for XDR operational data, such as case tickets and analyst notes, are generated and stored in a Microsoft data center in the European Union region for customers whose Defender XDR data is in scope of EU data boundary and in the US region for other customers, irrespective of the Microsoft Defender XDR service storage location. Data generated for the reporting dashboard is stored in customer's Microsoft Defender XDR service storage location. Reporting data and operational data will be retained for a grace period of no more than 90 days after a customer's subscription expires. If the customer terminates their subscription, data will be deleted within 30 days.
8181

8282
Microsoft experts hunt over [advanced hunting logs](advanced-hunting-schema-tables.md) in Microsoft Defender XDR advanced hunting tables. The data in these tables depend on the set of Defender services the customer is enabled for (for example, Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, and Microsoft Entra ID). Experts also use a large set of internal threat intelligence data to inform their hunting and automation.
8383

0 commit comments

Comments
 (0)