Microsoft Defender: Automated investigation and response (AIR) integrated into antivirus with manual triggering removed
Starting September 1, 2026, Microsoft Defender will remove manual triggering and the standalone experience of automated investigation and response (AIR). AIR’s protection is integrated into always-on antivirus, running automatically. Organizations using AIR in playbooks or scripts must update them before this date; full antivirus scans replace manual AIR investigations. What and Why As of September 1, 2026, automated investigation and response (AIR) will no longer run as a separate investigation experience or be available for manual triggering in Microsoft Defender. The protection capabilities of AIR are already embedded within Microsoft Defender’s always-on antivirus protection stack today. Detection and response run automatically as part of default protection, without requiring a separate investigation workflow. This change is part of our ongoing “shift left” effort to lift the onus of protection from customers by automating detection and response processes, helping ensure consistent outcomes across endpoints without reliance on a separate, manually initiated investigation experience. With this update, the standalone AIR investigation experience is removed. For on-demand investigations, teams can run full antivirus scans as needed. Rollout Schedule Transition (Worldwide, GCC, GCC High, DoD): Beginning and completing in early September 2026 Impact on Your Organization Who is affected Admins and security teams using Microsoft Defender for Endpoint and Microsoft Defender XDR Platforms/Services Microsoft Defender for Endpoint across supported platforms What will happen Manual triggering of automated investigation and response (AIR) will no longer be available. AIR will no longer run as a separate investigation experience. Detection and response will occur automatically as part of always-on antivirus protection. Full antivirus scans replace manual AIR investigations for on-demand analysis. Any playbooks, scripts, or integrations that initiate AIR will stop working after September 1, 2026, and must be updated before that date. Protection remains enabled by default. Action Required / Recommendations If you are not using AIR manually or through automation, no action is required to maintain protection. Action is required for organizations using AIR in playbooks, scripts, or integrations, as these will no longer function after September 1, 2026. Review and update any playbooks, scripts, or integrations that initiate AIR before September 1, 2026. Replace AIR-based workflows […]
The post Microsoft Defender: Automated investigation and response (AIR) integrated into antivirus with manual triggering removed appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender: Automated investigation and response (AIR) integrated into antivirus with manual triggering removed
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Excel: Excel canvas
Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...
Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads
We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...
Microsoft Outlook: Right-click to customize the classic ribbon
Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...
Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs
Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...
Microsoft Entra App Gallery: Self-service onboarding for new applications
Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...
Upgraded call history in Teams Calls app
Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...
Power Automate – Enable Process Intelligence Studio in object-centric process mining
We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...
Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities
We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...
Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center
The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...
Microsoft Teams: Start side conversations during meetings
Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...