Microsoft Defender XDR
Incidents and response

M365d Action Center

In brief

The page adds introductory steps for opening and using Action center, updates the source-details heading and anchor, reformats the remediation-actions link, and refreshes the publication date.

What Defender admins need to know

Administrators can use the clearer structure and navigation; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.author: guywild author: guywi-ms ms.localizationpriority: medium ms.date: 06/15/07/02/2026 ms.collection:

  • m365-security
  • tier2

Use the Action center

Use the following steps to open and work with the Action center:

  1. Go to Microsoft Defender portal and sign in.

  2. In the navigation pane under Actions and submissions, choose Action center. Or, in the Automated investigation & response card in the homepage, select View pending actions.

In addition to remediation actions that are taken automatically as a result of automated investigations, the Action center also tracks actions your security team has taken to address detected threats, and actions that were taken as a result of threat protection features in Microsoft Defender XDR. For more information about automatic and manual remediation actions, see Remediation actions.

ViewingView action source details

The Action center includes an Action source column that tells you where each action came from. The following table describes possible Action source values:

Next step

For more information, see the following article: