Skip to content

Commit dd5ccdd

Browse files
authored
Revise action instructions and update date
Updated the date and improved clarity in the instructions for submitting to Microsoft and initiating automated investigations.
1 parent 37f5635 commit dd5ccdd

File tree

1 file changed

+6
-6
lines changed

1 file changed

+6
-6
lines changed

defender-xdr/advanced-hunting-take-action.md

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ appliesto:
2121
- Microsoft Defender XDR
2222
- Microsoft Sentinel in the Microsoft Defender portal
2323
ms.topic: how-to
24-
ms.date: 03/28/2025
24+
ms.date: 11/10/2025
2525
---
2626

2727
# Take action on advanced hunting query results
@@ -106,17 +106,17 @@ Apart from device-focused remediation steps, you can also take some actions on e
106106
| project NetworkMessageId,RecipientEmailAddress, EmailDirection, SenderFromAddress, LatestDeliveryAction,LatestDeliveryLocation
107107
```
108108

109-
- `Submit to Microsoft` - select this action to submit False positives or False negative emails to Microsoft. As part of the submission, you can also add URLs, Senders and their domains to Tenant block/allow lists (TABL) to immediatley resolve the issue while Microsoft works on the submission.
109+
- `Submit to Microsoft` - select this action to submit False positives or False negative emails to Microsoft. As part of the submission, you can also add URLs and senders and their domains to the Tenant Allow/Block List to immediatley resolve the issue while Microsoft works on the submission.
110110

111-
TABL for URLs is only supported if the query result has `Url` column by joining with `EmailUrlInfo` table on `NetworkMessageId`.
111+
URL entries in the Tenant Aloow/Block List are supported only if the query result has the `Url` column by joining with `EmailUrlInfo` table on `NetworkMessageId`.
112112

113-
Submit to Microsoft checkbox can be disabled in cases where mandatory columns are missing. To resolve this, click on Show Empty columns and Take actions.
113+
The **Submit to Microsoft** check box might be disabled if mandatory columns are missing. To resolve this issue, select **Show empty columns** and **Take actions**.
114114

115115
:::image type="content" source="media/submit-to-microsoft.png" alt-text="Screenshot of take actions option in the Microsoft Defender portal." lightbox="media/submit-to-microsoft.png":::
116-
116+
117117
- `Initiate automated investigation` - select this action to trigger [Automated investigation](/defender-office-365/air-about) on email, sender, recipient or contact recipients.
118118

119-
Initiate automated investigation checkbox can be disabled in cases where mandatory columns are missing. To resolve this, click on Show Empty columns and Take actions.
119+
The **Initiate automated investigation** check box might be disabled if mandatory columns are missing. To resolve this issue, select **Show empty columns** and **Take actions**.
120120

121121
:::image type="content" source="media/initiate-automated-investigation.png" alt-text="Screenshot of take actions option in the Microsoft Defender portal." lightbox="media/submit-to-microsoft.png":::
122122

0 commit comments

Comments
 (0)