Microsoft Defender for Office 365: AIR Investigation Experience Improvements
Microsoft Defender for Office 365’s AIR experience will add a manual refresh button, replacing auto-refresh, and simplify investigation names by removing email subjects and UPNs. These changes improve performance, reduce network activity, and support data minimization. No admin action is required, but SOC workflows and documentation should be updated. What and Why: Microsoft is enhancing the Automated Investigation and Response (AIR) experience in Microsoft Defender for Office 365 by introducing a manual refresh capability and simplifying investigation naming conventions. These changes improve portal performance, reduce unnecessary network activity, and support data minimization principles by removing email subjects and User Principal Names (UPNs) from investigation names. Rollout Schedule: General Availability (Worldwide): Beginning in late July 2026 and expected to complete by late August 2026 Impact on Your Organization: Who is affected: Security Operations Center (SOC) analysts Security administrators Incident responders Organizations using Microsoft Defender for Office 365 Plan 2 / E5 and AIR Platforms/Services: Microsoft Defender portal Microsoft Defender for Office 365 Automated Investigation and Response (AIR) What will happen: Manual refresh replaces auto-refresh: The AIR Investigations page will no longer refresh automatically. A new Refresh button will be available on the Investigations page. Analysts must manually refresh the page to obtain the latest investigation status and details. This change is enabled by default as part of the service update. Improved page responsiveness and reduced background network calls are expected. Simplified investigation names: Investigation names for Manual and User-Reported will no longer include email subject lines Generic investigation names will be displayed instead, such as: Email investigation for ‘Network message Id” User reported message as malicious “Network message Id” Existing investigation history and results remain unchanged. No changes to existing capabilities Investigation triggers remain unchanged. Detection logic remains unchanged. Automated remediation actions remain unchanged. Threat Explorer functionality remains unchanged. Email & Collaboration reports remain unchanged. Historical investigation records remain available. Action Required/Recommendations: No mandatory administrative configuration is required. Recommended actions: Review SOC workflows that rely on automatic refresh behavior. Inform security analysts that investigation status updates now require use of the new Refresh button. Review automation, runbooks, scripts, dashboards, or integrations […]
The post Microsoft Defender for Office 365: AIR Investigation Experience Improvements appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender for Office 365: AIR Investigation Experience Improvements
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft OneDrive and SharePoint: Generate smart tables of contents for PDFs on the web with Copilot
Microsoft 365 Copilot users can generate AI-created, hierarchical, clickable tables of contents for PDFs in OneDrive and SharePoint on the web...
Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role
Microsoft is updating Microsoft Defender for Office 365’s Unified RBAC mapping for the Microsoft Entra Security Operator role, removing ...
Microsoft 365 Copilot: new guided Copilot onboarding experience
Microsoft 365 Copilot introduces an optional, admin-enabled guided onboarding experience for Frontier participants starting late October 2026....
Microsoft Purview |Unified Classification Management Experience
Microsoft Purview is launching a unified Classification Management experience for admins to manage classifiers consistently. Public Preview st...
Microsoft Purview | Data Loss Prevention: Administrative Units support for DLP policies for Microsoft Copilot
Microsoft Purview extends Microsoft Entra Administrative Units support to Copilot DLP policies, enabling delegated management within units whi...
Action required: Update Teams devices to a minimum app version ahead of the retirement of Exchange Web Services (EWS)
Update Microsoft Teams Rooms on Android, phones, and panels to the minimum app version released in February 2026 before October 2026 to avoid ...
Microsoft Power Platform governance and administration – Secure Dataverse record with column-based filtering
We are announcing the ability for admins to use filtered views to select and manage record-level access securely by defining security based on...
Microsoft Teams: Impersonation Protection for Teams meetings
Impersonation Protection for Teams meetings helps users identify potentially deceptive participants and meeting organizers. When Teams detects...
Microsoft Copilot (Microsoft 365): Use Dataverse Business Skills in Sales Agent
Business Skills are natural language instructions authored and stored in Microsoft Dataverse that teach Sales Agent how work gets done within ...