Skip to content

Commit d12965e

Browse files
Update defender-for-office-365-whats-new.md
@chrisda this is the Take action we launched in last April and now we are bringing the same to GOV clouds.
1 parent 5413a1f commit d12965e

File tree

1 file changed

+17
-0
lines changed

1 file changed

+17
-0
lines changed

defender-office-365/defender-for-office-365-whats-new.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,23 @@ For more information on what's new with other Microsoft Defender security produc
3838
- [What's new in Microsoft Defender for Endpoint](/defender-endpoint/whats-new-in-microsoft-defender-endpoint)
3939
- [What's new in Microsoft Defender for Identity](/defender-for-identity/whats-new)
4040
- [What's new in Microsoft Defender for Cloud Apps](/cloud-app-security/release-notes)
41+
## May 2025
42+
43+
Customers in government cloud environments are now able to take purge email messages or propose email remediation, Submit messages to Microsoft, Trigger investigations and block entries in the Tenant Allow/Block List together in few clicks.
44+
- :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: **Take action** replaces the **Message actions** drop down list on the **Email** tab (view) of the details area of the **All email**, **Malware**, or **Phish** views in [Threat Explorer (Explorer)](threat-explorer-real-time-detections-about.md):
45+
- SecOps personnel can now create tenant-level block entries on URLs and files via the [Tenant Allow/Block List](tenant-allow-block-list-about.md) directly from Threat Explorer.
46+
- For 100 or fewer messages selected in Threat Explorer, SecOps personnel can take multiple actions on the selected messages from the same page. For example:
47+
- Purge email messages or propose email remediation.
48+
- Submit messages to Microsoft.
49+
- Trigger investigations.
50+
- Block entries in the Tenant Allow/Block List.
51+
- Actions are contextually based on the latest delivery location of the message, but SecOps personnel can use the **Show all response actions** toggle to allow all available actions.
52+
- For 101 or more messages selected, only email purge and propose remediation options are available.
53+
54+
> [!TIP]
55+
> A new panel allows SecOps personnel to look for indicators of compromise at the tenant level, and the block action is readily available.
56+
57+
For more information, see [Threat hunting: Email remediation](threat-explorer-threat-hunting.md#email-remediation) and [Remediate Malicios Email: Email remediation](remediate-malicious-email-delivered-office-365.md#email-remediation).
4158

4259
## March 2025
4360

0 commit comments

Comments
 (0)