diff --git a/defender-xdr/m365d-autoir-actions.md b/defender-xdr/m365d-autoir-actions.md index b4d2f6771b..36ff9b60d2 100644 --- a/defender-xdr/m365d-autoir-actions.md +++ b/defender-xdr/m365d-autoir-actions.md @@ -69,6 +69,9 @@ If you've determined that a device or a file is not a threat, you can undo remed |:---|:---| | - Automated investigation
- Microsoft Defender Antivirus
- Manual response actions | - Isolate device
- Contain device
- Contain user
- Restrict code execution
- Quarantine a file
- Remove a registry key
- Stop a service
- Disable a driver
- Remove a scheduled task | +> [!NOTE] +> Only Security Administrators and Global Administrators are allowed access to undo operations such as File Quarantine. + ### Undo one remediation action 1. Go to the Action center ([https://security.microsoft.com/action-center](https://security.microsoft.com/action-center)) and sign in.