Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11In Microsoft Defender for Office 365, phishing cleanup is a two-stage process: an investigation identifies related messages and assesses where they were delivered; remediation then moves or deletes selected messages. Automated investigation and response (AIR) usually recommends an action for an analyst to approve. Automatic remediation is available only when configured and only for eligible cases.
What starts a phishing investigation?
In Defender for Office 365 Plan 2, AIR can begin after qualifying alerts, including suspicious email, Zero-hour Auto Purge (ZAP), user submissions, user-click alerts, and suspicious mailbox behavior. An analyst can also start an investigation from supported Defender tools. AIR evaluates the alert, the original message, and surrounding evidence; its scope can expand as it gathers more evidence. Microsoft’s AIR overview describes the supported triggers and workflow.
ZAP and AIR are related but not interchangeable. ZAP is a post-delivery cleanup capability and can trigger an investigation. An AIR investigation assesses the broader scope and may recommend further action; a ZAP event alone does not establish that every related copy has been removed.
How does Defender find related email?
Microsoft groups messages into clusters using sender information and message attributes, including sender IP or domain, subject, and cluster ID. If the investigation identifies a malicious URL or file, AIR can search for other messages containing it. It assesses the cluster’s threats and the messages’ latest delivery locations.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Cluster scope matters: a broad cluster can include messages that should not be remediated, while a narrow one can miss related copies. Investigators can inspect or edit the underlying queries in Threat Explorer or Advanced Hunting when the results need refinement. Microsoft explains email analysis in investigations and investigating delivered malicious email in cloud organizations.
Check exclusions as well as query results. AIR clustering excludes designated SecOps mailboxes and phishing-simulation URLs covered by an Advanced delivery policy. Those messages are excluded from remediation. If an analyst changes Explorer query filters, exclusion filters can disappear from that view, so verify the effective scope before acting.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Why detection does not mean removal
Finding a malicious message and removing it are separate stages. A malicious cluster can receive a pending soft-delete action when messages remain in cloud mailboxes. Messages that are already blocked, quarantined, failed, soft-deleted, or present only on-premises or externally do not receive that same cloud-mailbox removal action.
Microsoft notes that some mailboxes can still contain malicious content even when other copies were detected or removed by ZAP. Mailbox protections and policies vary, so assess the latest delivery location for each relevant message rather than assuming one cleanup event covered the organization.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Who approves removal, and when can it run automatically?
By default, AIR’s recommended actions await approval from SecOps. Administrators can configure automatic remediation for selected eligible cluster types. Microsoft’s automated remediation guidance documents soft delete as the automated action; clusters larger than 10,000 messages remain pending for review. That 10,000-message threshold is a product eligibility rule, not a measure of phishing prevalence or effectiveness.
Review automated outcomes in the Action Center, investigations, and Threat Explorer. Microsoft documents ways to revert an action, subject to available Defender data and mailbox retention. Soft delete is not the same as permanent removal: recovery depends on those conditions. Administrators should account for organizational retention and legal requirements when deciding whether to enable automation or how to handle a message.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How to carry out manual remediation
For a reviewed investigation, an authorized administrator can select messages or query results in Explorer and choose an available action. Microsoft documents moving email to the inbox, junk, or deleted items, as well as soft and hard deletion. The appropriate action depends on the investigation and organizational policy; verify the selection before submitting it.
- Open the investigation or relevant results in the supported Defender tool, such as Threat Explorer, and confirm the cluster and delivery locations.
- Review the messages and query scope, including whether exclusions are present in the current view.
- Select individual messages or query results, then choose the available remediation action. Confirm the target and scope before submitting.
- Check the Action Center, investigation, and action history to confirm the outcome and preserve a traceable record.
These tools and actions are subject to licensing, role permissions, and service limits. Microsoft’s malicious-email remediation guidance documents a maximum of 100 hand-selected emails and query selection up to 200,000 emails. It also documents a limit of 50 active concurrent email remediations and limits when a remediation exceeds one million messages. These are Defender service limits, not general incident-response targets; consult the current Microsoft guidance and tenant configuration before planning a large action.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What to verify before closing the incident
- Scope: Confirm the cluster query captures the related messages without including unrelated mail.
- Delivery location: Check whether each copy is in a cloud mailbox and whether it was already blocked, quarantined, failed, or deleted. On-premises and external copies are outside the same cloud-mailbox removal action.
- Exclusions: Check designated SecOps mailboxes and phishing-simulation URLs, and confirm that query edits have not removed exclusion filters from the view.
- Action state: Distinguish a recommendation awaiting approval from an action completed automatically or manually.
- Access and license: Verify the tenant’s Defender for Office 365 plan and the role required for the specific investigation or remediation action. Microsoft describes AIR and remediation requirements for Plan 2; Threat Explorer is associated with Plan 2, while Plan 1 provides Real-time detections.
- History and recovery: Review the action history and consider retention requirements before relying on recovery or treating a soft delete as permanent removal.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

