Microsoft Defender for Endpoint
Endpoint protection

Configure automated investigation and remediation capabilities in Microsoft Defender for Endpoint

In brief

The article now links to the current Defender for Endpoint overview, uses clearer wording for remediated threats, and introduces the steps for configuring device groups and automation levels in the Defender portal.

What Defender admins need to know

Administrators have clearer navigation and setup guidance when configuring automated investigation and remediation.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure automated investigation and remediation capabilities in Microsoft Defender for Endpoint

If your organization is using Defender for EndpointDefender for Endpoint (or Defender for Business), automated investigation and remediation capabilities can save your security operations team time and effort. As outlined in Enhance your SOC with Microsoft Defender for Endpoint automatic investigation and remediation, these capabilities mimic the ideal steps that a security analyst takes to investigate and remediate threats. For more information, see Automated investigation and remediation.

[!INCLUDE AIR deprecation note]

If you're using Defender for Endpoint, you can specify an automation level so that when a threat is detected on a device, the entitydetected threat can be remediated automatically or only upon approval by your security team. You can configure automated investigation and remediation with device groups.

Set up device groups

To create device groups and configure automation levels in the Microsoft Defender portal, follow these steps:

  1. In the Microsoft Defender portal, on the Settings page, under Permissions, select Device groups.

  2. Select + Add device group.