Automation Levels
In brief
The table entry describing the No automated response (no automation) level was revised.
What Defender admins need to know
Review the updated guidance when administering automation levels; no action is specified.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
|Semi - require approval for all folders
(also referred to as semi-automation)|With this level of semi-automation, approval is required for remediation actions on all files. Such pending actions can be viewed and approved in the Action Center, on the Pending tab. Pending actions time out after seven days. If an action times out, the behavior is the same as if the action is rejected.
This level of semi-automation is selected by default for tenants that were created before August 16, 2020 with Microsoft Defender for Endpoint, with no device groups defined.|
|Semi - require approval for core folders remediation
(also a type of semi-automation)|With this level of semi-automation, approval is required for any remediation actions needed on files or executables that are in core folders. Core folders include operating system directories, such as the Windows (\windows\*).
Remediation actions can be taken automatically on files or executables that are in other (noncore) folders.
Pending actions for files or executables in core folders can be viewed and approved in the Action Center, on the Pending tab.
Actions that were taken on files or executables in other folders can be viewed in the Action Center, on the History tab.|
|Semi - require approval for non-temp folders remediation
(also a type of semi-automation)|With this level of semi-automation, approval is required for any remediation actions needed on files or executables that aren't* in temporary folders.
Temporary folders can include the following examples:
\users\*\appdata\local\temp\*\documents and settings\*\local settings\temp\*\documents and settings\*\local settings\temporary\*\windows\temp\*\users\*\downloads\*\program files\\program files (x86)\*\documents and settings\*\users\*
Remediation actions can be taken automatically on files or executables that are in temporary folders.
Pending actions for files or executables that aren't in temporary folders can be viewed and approved in the Action Center, on the Pending tab.
Actions that were taken on files or executables in temporary folders can be viewed and approved in the Action Center, on the History tab.|
|No automated response
(also referred to as no automation)|With no automation, automated investigation doesn't run on your organization's devices. As a result, no remediation actions are taken or pending as a result of automated investigation. However, other threat protection features, such as protection from potentially unwanted applicationsprotection from potentially unwanted applications, can be in effect, depending on how your antivirus and next-generation protection features are configured.
*Using the no automation option is not recommended, because it reduces the security posture of your organization's devices. Consider setting up your automation level to full automation (or at least semi-automation).|
Important points about automation levels
@@ -44,7 +44,7 @@ Automated investigation and remediation (AIR) capabilities in Microsoft Defender |**Semi - require approval for all folders** <br> (also referred to as *semi-automation*)|With this level of semi-automation, approval is required for remediation actions on all files. Such pending actions can be viewed and approved in the [Action Center](auto-investigation-action-center.md), on the **Pending** tab. Pending actions time out after seven days. If an action times out, the behavior is the same as if the action is rejected. <p> *This level of semi-automation is selected by default for tenants that were created before August 16, 2020 with Microsoft Defender for Endpoint, with no device groups defined.*| |**Semi - require approval for core folders remediation** <br> (also a type of *semi-automation*)|With this level of semi-automation, approval is required for any remediation actions needed on files or executables that are in core folders. Core folders include operating system directories, such as the **Windows** (`\windows\*`). <p> Remediation actions can be taken automatically on files or executables that are in other (noncore) folders. <p> Pending actions for files or executables in core folders can be viewed and approved in the [Action Center](auto-investigation-action-center.md), on the **Pending** tab. <p> Actions that were taken on files or executables in other folders can be viewed in the [Action Center](auto-investigation-action-center.md), on the **History** tab.| |**Semi - require approval for non-temp folders remediation** <br> (also a type of *semi-automation*)|With this level of semi-automation, approval is required for any remediation actions needed on files or executables that aren't* in temporary folders. <p> Temporary folders can include the following examples: <ul><li>`\users\*\appdata\local\temp\*`</li><li>`\documents and settings\*\local settings\temp\*`</li><li>`\documents and settings\*\local settings\temporary\*`</li><li>`\windows\temp\*`</li><li>`\users\*\downloads\*`</li><li>`\program files\`</li><li>`\program files (x86)\*`</li><li>`\documents and settings\*\users\*`</li></ul> <p> Remediation actions can be taken automatically on files or executables that are in temporary folders. <p> Pending actions for files or executables that aren't in temporary folders can be viewed and approved in the [Action Center](auto-investigation-action-center.md), on the **Pending** tab. <p> Actions that were taken on files or executables in temporary folders can be viewed and approved in the [Action Center](auto-investigation-action-center.md), on the **History** tab.|-|**No automated response** <br> (also referred to as *no automation*)|With no automation, automated investigation doesn't run on your organization's devices. As a result, no remediation actions are taken or pending as a result of automated investigation. However, other threat protection features, such as [protection from potentially unwanted applications](/windows/security/threat-protection/microsoft-defender-antivirus/detect-block-potentially-unwanted-apps-microsoft-defender-antivirus), can be in effect, depending on how your antivirus and next-generation protection features are configured. <p> ***Using the *no automation* option is not recommended**, because it reduces the security posture of your organization's devices. [Consider setting up your automation level to full automation (or at least semi-automation)](machine-groups.md).|+|**No automated response** <br> (also referred to as *no automation*)|With no automation, automated investigation doesn't run on your organization's devices. As a result, no remediation actions are taken or pending as a result of automated investigation. However, other threat protection features, such as [protection from potentially unwanted applications](detect-block-potentially-unwanted-apps-microsoft-defender-antivirus.md), can be in effect, depending on how your antivirus and next-generation protection features are configured. <p> ***Using the *no automation* option is not recommended**, because it reduces the security posture of your organization's devices. [Consider setting up your automation level to full automation (or at least semi-automation)](machine-groups.md).| ## Important points about automation levels @@ -66,4 +66,3 @@ Automated investigation and remediation (AIR) capabilities in Microsoft Defender - [Configure automated investigation and remediation capabilities in Defender for Endpoint](configure-automated-investigations-remediation.md) - [Visit the Action Center](auto-investigation-action-center.md#the-unified-action-center) - 