Microsoft Defender for Office 365
Email and collaboration

Email Analysis Investigations

In brief

The documentation now explains email clustering for SecOps mailboxes and phishing simulations, how Explorer filter exclusions behave, and how pending actions affect remediation status.

What Defender admins need to know

Administrators can use the clarified guidance when reviewing investigation results and remediation actions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • m365initiative-defender-office365
  • tier3 keywords: automated incident response, investigation, remediation, threat protection description: SeeLearn how email analysis inautomated investigations work in Microsoft Defender for Office 365.365 analyze original and related emails, cluster suspicious messages, and determine threat status for remediation. ms.custom:
  • msecd-doc-authoring-10141016
  • air
  • seo-marvel-mar2020 ms.service: defender-office-365 ms.date: 06/15/07/03/2026 appliesto:

Email clustering analysis via similarity and malicious entity queries ensures that email problems are fully identified and cleaned up, even if only one email from an attack gets identified. You can use links from the email cluster details side panel views to open the queries in Explorer or Advanced Hunting to perform deeper analysis and change the queries if needed. Opening and editing the queries in Explorer or Advanced Hunting enables manual refinement and remediation if you find the email cluster's queries too narrow or too broad (including unrelated email).

Automated investigation emailEmail clustering analysis includes the following additional enhancements.also handles SecOps mailboxes, phishing simulations, pending action updates, and evidence display.

AIR investigation ignores advanced delivery items (SecOps mailboxes and phishing simulation messages)

During email clustering analysis, all clustering queries ignore SecOps mailboxes and phishing simulation URLs that are configured in the Advanced delivery policy (the policy that designates SecOps mailboxes and third-party phishing simulations as trusted). These items aren't shown in the query. This approachExcluding these trusted items keeps the clustering attributes simple and easy to read. Messages sent to SecOps mailboxes are skipped during threat analysis. Messages with phishing simulation URLs are also skipped. None of these excluded messages are removed during remediation.

AIR updates pending email action status

  • When the email cluster data changes, it updates the threat and latest delivery location counts.
  • If email or email cluster with pending actions no longer are in the mailbox, then the pending action is canceled, and the malicious email/cluster considered remediated.
  • Once all the investigation's threats have been remediated or their pending actions have been canceled, the investigation transitions to a remediated state and the original alert is resolved.

The display of incident evidence for email and email clusters

In this example, the email is malicious but not in a mailbox.

Next step