Microsoft Defender XDR
General

M365d Configure Auto Investigation Response

In brief

The page date and wording were refreshed, and the settings section was renamed to “Change automated investigation settings” with an updated anchor and additional learning link.

What Defender admins need to know

Administrators should use the revised section heading and navigation when referencing automated investigation and response settings.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.topic: how-to ms.service: defender-xdr ms.localizationpriority: medium ms.date: 06/15/07/02/2026 ms.collection:

  • m365-security
  • tier2
  1. Review or change the automation level for device groups.
  2. Review your security and alert policies in Office 365.

Then, after you're all set up,After configuring automated investigation and response, you can view and manage remediation actions in the Action center. And, if necessary, you can and update automated investigation settings. as needed.

  1. Go to System > Settings > Endpoints > Device groups under Permissions.

  2. Review your device group policies. In particular, look at the Remediation level column. We recommend using Full - remediate threats automatically. You might need to create or edit your device groups to get the level of automation you want. To get help with this task,creating or editing device groups, see the following articles:

You can review your alert policies in the Defender portal at https://security.microsoft.com > Policies & rules > Alert policy or directly at https://security.microsoft.com/alertpoliciesv2. Several default alert policies are in the Threat management category. Some of the alert policies in the Threat management category can trigger automated investigation and response. To learn more, see Threat management alert policies.

Need to make changes toChange automated investigation settings?settings

You can choose from several options to change settings for your automated investigation and response capabilities. Some options are listed in the following table:

Next steps

Learn more about automated investigation and response capabilities in Microsoft Defender XDR.

Related content