Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In Microsoft Defender for Office 365 Plan 2, automated investigation and response (AIR) can investigate selected alerts and recommend email remediation. By default, a security operations (SecOps) team reviews the proposal and approves or rejects it; some selected malicious-message clusters can be configured for automatic remediation. That is a documented Microsoft workflow, not a description of every email-security product.

For administrators and incident responders, the practical goal is to investigate suspected phishing, correct mistaken verdicts, remove confirmed threats with an appropriate level of reversibility, and retain enough history to explain each action.

How does phishing response automation investigate a message?

In Defender for Office 365 Plan 2, AIR investigations may be triggered by suspicious email detections, Zero-hour auto purge (ZAP) events, user submissions, user-click alerts, and suspicious mailbox behavior. AIR evaluates the alert, the message involved, and surrounding evidence, then can produce findings and a remediation recommendation for SecOps. The investigation and recommendation are not, by themselves, proof that a message is malicious. Microsoft’s AIR overview describes the product workflow and its licensing context.

Microsoft documents SecOps approval as the default for proposed remediation. It also documents configurable automatic handling for selected malicious clusters. For those clusters, the current documentation describes soft deletion as the automated action and says clusters larger than 10,000 messages remain pending for review rather than being automatically remediated. Check the live product documentation and tenant configuration before relying on these behaviors, which are specific to the documented Microsoft workflow. AIR overview; AIR automated remediation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should happen when a legitimate email is flagged?

Handle a suspected false positive as an investigation, not as a reason to broadly allow a sender or domain. Microsoft supports submitting messages, attachments, and URLs as false positives or false negatives, then reviewing the resulting verdict and tuning alerts when needed to reduce recurrence. Where an AIR action can be undone, administrators can use the documented reversal process. Microsoft’s guidance on false-positive and false-negative handling explains these workflows.

  1. Confirm the message and verdict. Review the message and investigation evidence, then submit the message, attachment, or URL through Microsoft’s supported submission workflow as a false positive if it was incorrectly classified.
  2. Restore access if appropriate. If the message is quarantined, an administrator with the required permissions can release it, subject to the tenant’s quarantine settings. If AIR already took an action, check whether that action is eligible for reversal.
  3. Address recurrence narrowly. Use the submission result to guide an appropriately scoped alert or configuration change. Avoid broad allowlisting as the first response because it can weaken protection beyond the message in question.

CISA’s Microsoft 365 baseline discusses allowing trusted senders and domains in response to false positives, but the baseline’s version and current applicability should be checked before treating that as current guidance. CISA’s Microsoft 365 Minimum Viable Secure Configuration Baseline.

Rank #2
SonicWall TZ370 Network Security Appliance (02-SSC-2825) Bundled with a SonicWall 1 Year 24x7 Support for TZ370 (02-SSC-6517)
  • The latest SonicWall TZ370 series, are the first desktop form factor nextgeneration firewalls (NGFW) with 10 or 5 Gigabit Ethernet interfaces. The series consist of a wide range of products to suit a variety of use cases.
  • Reduce complexity and get the business running without relying on IT personnel with easy onboarding using SonicExpress App and Zero-Touch Deployment, and easy management through a single pane of glass
  • Drive business growth by investing in next-gen appliances with multi-gigabit and advanced security features, to future-proof against the changing network and security landscape.
  • SonicWall 24x7 support provides chat, email, web, and telephone support for technical assistance | Dynamic Support is designed for customers who need continued protection through ongoing firmware updates and advanced technical support
  • Hardware: Operating system: SonicOS 7.0 | Interfaces: 8x1GbE, 2 USB 3.0, 1 Console | Management: Network Security Manager, CLI, SSH, Web UI, GMS, REST APIs | VLAN Interfaces: 128 | Access points supported (maximum): 16

What does “remove” mean for an email?

Removal can describe different actions with different consequences. Microsoft documents moving an email to a mailbox folder, soft deletion, hard deletion, and quarantine-related operations. AIR’s documented automated remediation action is soft delete; Microsoft notes that recovery depends on the mailbox retention policy. Soft deletion should not be described as permanent removal. Microsoft’s delivered email remediation guidance; AIR automated remediation.

Action What it means in the documented workflow Operational consideration
Move to a mailbox folder Moves the message to a specified folder. Check where it was moved and who can access it; this is not the same as deletion.
Quarantine Restricts access to the message under quarantine settings. Release depends on the applicable permissions and quarantine configuration.
Soft delete Deletes the message without describing it as permanently erased. Recovery depends on mailbox retention policy. This is the action Microsoft documents for AIR automated remediation.
Hard delete Uses a stronger deletion action than soft delete. Confirm that the case and applicable retention or legal obligations justify the action before choosing it.

Choose an action based on confidence in the finding, the workflow’s available controls, permissions, and retention or legal obligations. As an operational safeguard, preserve the ability to investigate or restore a legitimate message where the system and policy allow it, and reserve stronger deletion for cases that warrant it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
SonicWall TZ570 Network Security Appliance (02-SSC-2833) Bundled with a SonicWall TZ570 1YR 24x7 Support License (02-SSC-5065)
  • The TZ570 is designed for mid-sized organizations and distributed enterprise with SD-Branch locations, the TZ570 delivers industry-validated security effectiveness with best-in-class price performance. TZ570 NGFWs address the growing trends in web encryption, connected devices and high-speed mobility by delivering a solution that meets the need for automated, realtime breach detection and prevention.
  • Deployment of TZ570 is further simplified by Zero-Touch Deployment, with the ability to simultaneously roll out these devices across multiple locations with minimal IT support.
  • The SonicOS architecture is at the core of TZ NGFWs. TZ570 is powered by the feature rich SonicOS 7.0 operating system with new modern looking UX/UI, advanced security, networking and management capabilities. TZ570 features integrated SD-WAN, TLS 1.3 support, realtime visualization, high-speed virtual private networking (VPN) and other robust security features.
  • SonicWall 24x7 support provides chat, email, web, and telephone support for technical assistance | Dynamic Support is designed for customers who need continued protection through ongoing firmware updates and advanced technical support
  • Hardware: Interfaces: 8x1GbE, 2x5GbE, 2 USB 3.0, 1 Console | VLAN interfaces: 256 | Firewall Inspection Throughput: 4.00 Gbps | Threat Prevention Throughput: 4.00 Gbps | IPS Throughput: 2.5 Gbps | IPSec VPN Throughput: 1.80 Gbps

Should automation remove messages without approval?

For Microsoft Defender for Office 365 Plan 2 AIR, the documented default is to put proposed remediation before SecOps for approval or rejection. Administrators can configure automatic remediation for selected malicious clusters, subject to the product’s documented behavior and limits. That is a product-specific option, not a general recommendation to remove every flagged message automatically.

Before enabling automatic handling, decide how the organization will control the following:

  • Confidence: what evidence is sufficient for an automatic action, and what should remain a recommendation for review?
  • Blast radius: how should a single message be handled differently from a cluster affecting many mailboxes?
  • Exceptions and recovery: how will an administrator identify exceptions and reverse an action when appropriate?
  • Accountability: who can approve, reject, or configure remediation, and when should a case be escalated?

These are implementation considerations for a reviewable process; they are not a Microsoft-prescribed checklist. The product’s documented automated action and large-cluster limit are described in Microsoft’s AIR automated remediation guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can you see who removed a message and why?

Use the action history and related investigation or alert details to reconstruct the event. Microsoft documents action information such as the action name and type, status, source, decision maker or approver, creation information, and links to associated investigations or alerts. The exact details available depend on the action and view.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
SonicWall TZ370 Network Security Appliance (02-SSC-2825) Bundled with a SonicWall 3 Year 8x5 Support for TZ370 (02-SSC-6615)
  • The latest SonicWall TZ370 series, are the first desktop form factor nextgeneration firewalls (NGFW) with 10 or 5 Gigabit Ethernet interfaces. The series consist of a wide range of products to suit a variety of use cases.
  • Reduce complexity and get the business running without relying on IT personnel with easy onboarding using SonicExpress App and Zero-Touch Deployment, and easy management through a single pane of glass
  • Drive business growth by investing in next-gen appliances with multi-gigabit and advanced security features, to future-proof against the changing network and security landscape.
  • SonicWall 8x5 Support provides chat, email, web, and telephone support for technical assistance | Dynamic Support is designed for customers who need continued protection through ongoing firmware updates and advanced technical support
  • Hardware: Operating system: SonicOS 7.0 | Interfaces: 8x1GbE, 2 USB 3.0, 1 Console | Management: Network Security Manager, CLI, SSH, Web UI, GMS, REST APIs | VLAN Interfaces: 128 | Access points supported (maximum): 20
  1. Open the relevant remediation or action history in Microsoft Defender and locate the action associated with the message or investigation.
  2. Review its status, action type, source, and decision or approver details to establish what happened and who took or approved the action.
  3. Open the associated investigation or alert to examine the evidence and recommendation behind the action.
  4. Use the Microsoft 365 unified audit log as an additional record of user and administrative activity, according to your organization’s audit configuration and access.

AIR requires audit logging to be enabled; Microsoft’s AIR overview says it is on by default. CISA describes the Microsoft 365 unified audit log as a source of user activity records used for incident response and threat detection. Microsoft AIR overview; CISA’s February 21, 2024 announcement on federal logging capabilities.

How long are audit and message records retained?

There is no universal retention period established for every Microsoft 365 organization by the cited guidance. CISA’s February 21, 2024 announcement described a 180-day default in the context of the federal Purview Audit rollout. That announcement does not establish the current retention period for every tenant, license, or organization. Check your tenant’s audit and mailbox retention policies, licensing, and legal obligations rather than applying that figure universally. CISA’s announcement; CISA’s Microsoft 365 Defender baseline PDF.

Audit history and mailbox recovery are separate concerns: action records help explain what was done, while mailbox retention policy affects whether a soft-deleted message can be recovered. Verify both settings for the relevant tenant and case.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.