Loading...

Microsoft Defender for Office 365: AIR Investigation Experience Improvements

Microsoft Defender for Office 365: AIR Investigation Experience Improvements

Microsoft Defender for Office 365’s AIR experience will add a manual refresh button, replacing auto-refresh, and simplify investigation names by removing email subjects and UPNs. These changes improve performance, reduce network activity, and support data minimization. No admin action is required, but SOC workflows and documentation should be updated. What and Why: Microsoft is enhancing the Automated Investigation and Response (AIR) experience in Microsoft Defender for Office 365 by introducing a manual refresh capability and simplifying investigation naming conventions. These changes improve portal performance, reduce unnecessary network activity, and support data minimization principles by removing email subjects and User Principal Names (UPNs) from investigation names. Rollout Schedule: General Availability (Worldwide): Beginning in late July 2026 and expected to complete by late August 2026 Impact on Your Organization: Who is affected: Security Operations Center (SOC) analysts Security administrators Incident responders Organizations using Microsoft Defender for Office 365 Plan 2 / E5 and AIR Platforms/Services: Microsoft Defender portal Microsoft Defender for Office 365 Automated Investigation and Response (AIR) What will happen: Manual refresh replaces auto-refresh: The AIR Investigations page will no longer refresh automatically. A new Refresh button will be available on the Investigations page. Analysts must manually refresh the page to obtain the latest investigation status and details. This change is enabled by default as part of the service update. Improved page responsiveness and reduced background network calls are expected. Simplified investigation names: Investigation names for Manual and User-Reported will no longer include email subject lines Generic investigation names will be displayed instead, such as: Email investigation for ‘Network message Id” User reported message as malicious “Network message Id” Existing investigation history and results remain unchanged. No changes to existing capabilities Investigation triggers remain unchanged. Detection logic remains unchanged. Automated remediation actions remain unchanged. Threat Explorer functionality remains unchanged. Email & Collaboration reports remain unchanged. Historical investigation records remain available. Action Required/Recommendations: No mandatory administrative configuration is required. Recommended actions: Review SOC workflows that rely on automatic refresh behavior. Inform security analysts that investigation status updates now require use of the new Refresh button. Review automation, runbooks, scripts, dashboards, or integrations […]

The post Microsoft Defender for Office 365: AIR Investigation Experience Improvements appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Defender for Office 365: AIR Investigation Experience Improvements

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Dynamics 365 Contact Center – Manage overnight shifts as a single continuous schedule

We are announcing the ability to manage overnight shifts as a single continuous schedule in Dynamics 365 Contact Center. This feature will rea...

12 hours ago

Manage who can upload advanced agents and plugins

Starting September 25, Microsoft 365 admins can control who uploads advanced Copilot agents and plugins, limiting access to specific users or ...

12 hours ago

Microsoft 365 Copilot: Insights Copilot Analytics cowork adoption impact

Microsoft 365 Copilot now includes Cowork adoption and impact insights in the Consumption dashboard and Viva Insights Advanced Insights. Avail...

12 hours ago

Writing Blocks in M365 Copilot

Microsoft 365 Copilot will introduce Writing blocks by mid-September 2026, enabling users to create and refine longer-form content like emails...

12 hours ago

Outlook: Change the organizer of meetings

Microsoft is introducing a feature to change the organizer of eligible Outlook meetings, allowing transfer of meeting ownership within an orga...

12 hours ago

Code Blocks in M365 Copilot

Microsoft 365 Copilot will support inline previews of code blocks, charts, and diagrams within conversations, eliminating the need for a separ...

12 hours ago

Microsoft SharePoint: PowerShell support for brand fonts deletion

Microsoft SharePoint will introduce the Remove-SPOFontFile PowerShell cmdlet by mid-October 2026, allowing admins to delete brand fonts across...

12 hours ago

[Outlook Mobile] Purview Data Loss Prevention support for Calendar Events

Outlook for iOS and Android will support Microsoft Purview Data Loss Prevention for calendar events, helping prevent sensitive data sharing in...

12 hours ago

[Outlook Mac] Purview Data Loss Prevention support for Calendar Events

Outlook for Mac will support Microsoft Purview Data Loss Prevention for calendar events, detecting sensitive info in meeting details to preven...

12 hours ago

[Outlook Mobile] Purview DLP Wait-on-Send Support

Outlook for iOS and Android will support Microsoft Purview DLP wait-on-send policies, allowing organizations to require and configure a wait t...

12 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.