Configure automated investigation and remediation capabilities in Microsoft Defender for Endpoint
In brief
The article now links to the current Defender for Endpoint overview, uses clearer wording for remediated threats, and introduces the steps for configuring device groups and automation levels in the Defender portal.
What Defender admins need to know
Administrators have clearer navigation and setup guidance when configuring automated investigation and remediation.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Configure automated investigation and remediation capabilities in Microsoft Defender for Endpoint
If your organization is using Defender for EndpointDefender for Endpoint (or Defender for Business), automated investigation and remediation capabilities can save your security operations team time and effort. As outlined in Enhance your SOC with Microsoft Defender for Endpoint automatic investigation and remediation, these capabilities mimic the ideal steps that a security analyst takes to investigate and remediate threats. For more information, see Automated investigation and remediation.
[!INCLUDE AIR deprecation note]
If you're using Defender for Endpoint, you can specify an automation level so that when a threat is detected on a device, the entitydetected threat can be remediated automatically or only upon approval by your security team. You can configure automated investigation and remediation with device groups.
Set up device groups
To create device groups and configure automation levels in the Microsoft Defender portal, follow these steps:
In the Microsoft Defender portal, on the Settings page, under Permissions, select Device groups.
Select + Add device group.
@@ -12,28 +12,30 @@ ms.collection: - mde-edr ms.topic: how-to ms.reviewer: ramarom, evaldm, isco, mabraitm, chriggs-ms.date: 06/17/2026+ms.date: 07/02/2026 appliesto: - Microsoft Defender for Endpoint Plan 2 ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Configure automated investigation and remediation capabilities in Microsoft Defender for Endpoint -If your organization is using [Defender for Endpoint](/windows/security/threat-protection/) (or [Defender for Business](/defender-business/mdb-overview)), [automated investigation and remediation capabilities](automated-investigations.md) can save your security operations team time and effort. As outlined in [Enhance your SOC with Microsoft Defender for Endpoint automatic investigation and remediation](https://techcommunity.microsoft.com/t5/microsoft-defender-atp/enhance-your-soc-with-microsoft-defender-atp-automatic/ba-p/848946), these capabilities mimic the ideal steps that a security analyst takes to investigate and remediate threats. [Automated investigation and remediation](automated-investigations.md).+If your organization is using [Defender for Endpoint](microsoft-defender-endpoint.md) (or [Defender for Business](/defender-business/mdb-overview)), [automated investigation and remediation capabilities](automated-investigations.md) can save your security operations team time and effort. As outlined in [Enhance your SOC with Microsoft Defender for Endpoint automatic investigation and remediation](https://techcommunity.microsoft.com/t5/microsoft-defender-atp/enhance-your-soc-with-microsoft-defender-atp-automatic/ba-p/848946), these capabilities mimic the ideal steps that a security analyst takes to investigate and remediate threats. For more information, see [Automated investigation and remediation](automated-investigations.md). [!INCLUDE [AIR deprecation note](includes/air-deprecation-note.md)] -If you're using Defender for Endpoint, you can specify an automation level so that when a threat is detected on a device, the entity can be remediated automatically or only upon approval by your security team. You can configure automated investigation and remediation with device groups. +If you're using Defender for Endpoint, you can specify an automation level so that when a threat is detected on a device, the detected threat can be remediated automatically or only upon approval by your security team. You can configure automated investigation and remediation with device groups. > [!NOTE] > In Defender for Business, automated investigation is configured automatically. See [Review settings for advanced features in Defender for Business](/defender-business/mdb-configure-security-settings#review-settings-for-advanced-features). ## Set up device groups +To create device groups and configure automation levels in the Microsoft Defender portal, follow these steps:+ 1. In the [Microsoft Defender portal](https://security.microsoft.com), on the **Settings** page, under **Permissions**, select **Device groups**. 1. Select **+ Add device group**.@@ -59,4 +61,3 @@ If you're using Defender for Endpoint, you can specify an automation level so th - [Address false positives/negatives in Microsoft Defender for Endpoint](defender-endpoint-false-positives-negatives.md) - [Automation levels in automated investigation and remediation](automation-levels.md) - 