Microsoft Defender for Endpoint
Endpoint protection

Investigate devices in Microsoft Defender for Endpoint

In brief

The investigation guidance now notes that some response actions may be unavailable or grayed out for high-value assets because permissions are set during onboarding. Firewall audit links were also updated, and the document date was refreshed.

What Defender admins need to know

Administrators should account for onboarding-defined action restrictions when investigating high-value assets and use the updated firewall audit references.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

title: Investigate devices in Microsoft Defender for Endpoint description: Learn how to investigate devices by reviewing alerts, timelines, network connections, and security assessments in Microsoft Defender for Endpoint. keywords: investigate devices, device timeline, event flags, MITRE ATT&CK, internet-facing devices, device investigation, device details, network connections ms.topic: concept-article ms.subservice: edr search.appverid: met150 ms.date: 02/25/07/23/2026 ai-usage: ai-assisted appliesto:

  • Microsoft Defender for Endpoint Plan 2

You can take response actions in the Action center, in a specific device page, or in a specific file page.

For more information on how to take action on a device, see Take response action on a device.

For more information, see Investigate user entities. :::image type="content" source="media/timeline-device.png" alt-text="Screenshot of the device timeline with events." lightbox="media/timeline-device.png":::