Loading...

Microsoft Defender for Office 365: Auto-remediation of malicious similarity clusters in AIR

Microsoft Defender for Office 365: Auto-remediation of malicious similarity clusters in AIR

Microsoft Defender for Office 365 expands AIR auto-remediation to malicious similarity clusters, automating approval of remediation actions without manual intervention. Rolling out worldwide mid to late December 2025, this feature reduces SOC workload and speeds threat response. It’s off by default and can be enabled in the Defender portal. Introduction We are expanding the auto-remediation capabilities in Automated Investigations and Response (AIR) to fully automate the remediation of malicious similarity clusters. Earlier this year, we introduced auto-remediation for malicious URL and file clusters. Building on that foundation, this enhancement enables AIR to automatically approve all pending remediation actions it generates—eliminating the need for manual intervention and streamlining the response process for SOC teams. This advancement significantly reduces response time and operational overhead, allowing security teams to focus on higher-priority threats. This message is associated with Microsoft 365 Roadmap ID 502528. When this will happen General Availability (Worldwide): We will begin rolling out in mid-December 2025 and expect to complete by late December 2025. How this will affect your organization Who is affected: Microsoft Defender for Office 365 Plan 2 and Microsoft Defender for Endpoint E5 customers. What will happen: AIR will automatically approve all pending remediation actions for malicious similarity clusters. This feature extends existing auto-remediation for URL and file clusters to include similarity clusters. This feature is not enabled by default. Admins can turn it on in the Microsoft Defender portal by configuring MDO automation settings. No manual intervention will be required for these remediation actions. Key benefits: Increased post-delivery protection by identifying campaigns and removing malicious messages faster. Reduced SOC workload by eliminating manual cleanup actions. What you need to do to prepare Learn more: No admin action is required before rollout. If you want to enable or verify this feature: In the Defender portal (security.microsoft.com), go to Settings > Email & collaboration > MDO automation settings. Select multiple similar attributes (similar files and similar URLs options were previously available and can also be selected). Select Save to enable auto-remediation. View image in new tab Automated investigation and response (AIR) examples in Microsoft Defender for Office 365 Plan […]

The post Microsoft Defender for Office 365: Auto-remediation of malicious similarity clusters in AIR appeared first on M365 Admin.

Published on:

Learn more
M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

SharePoint site analytics: OneNote usage included in site usage reports

SharePoint site analytics will include OneNote file usage, increasing reported site metrics like unique viewers and visits. Popular content re...

1 day ago

Microsoft Excel: Enabling M365 subscribers to use Copilot Chat in locally stored modern workbooks

Microsoft 365 subscribers will be able to use Copilot Chat in locally stored Excel modern workbooks starting mid-December 2025, with rollout c...

1 day ago

Microsoft Viva – Viva Glint: Export Executive Summary report in Viva Glint to editable PowerPoint slides

Managers can soon export Viva Glint Executive Summary reports as editable PowerPoint slides, enabling easier customization and faster sharing....

1 day ago

Microsoft Teams: Best Practice dashboard to monitor VDI optimization for meetings

A new Best Practice Configurations Monitoring Dashboard will roll out in early 2026 in the Teams admin center, helping admins monitor and reme...

1 day ago

Manage version expiration for audio and video files in SharePoint Online

SharePoint Online will enable admins to set version expiration policies for audio and video files to reduce storage and manage versions. Rolli...

1 day ago

Microsoft 365 & Power Platform Community Call – December 11th, 2025 – Screenshot Summary

Call Highlights   SharePoint Quicklinks: Primary PnP Website: https://aka.ms/m365pnp Documentation & Guidance SharePoint Dev Videos Issues...

1 day ago

Microsoft Teams: Restart Event feature for Town Hall with unrecoverable failures

Microsoft Teams will introduce a Restart Event feature for live events with unrecoverable failures, rolling out worldwide from January to Febr...

2 days ago

Coming soon: IT admins will be able to customize recording and transcription notifications in Teams

Starting January 2026, IT admins can customize Teams recording and transcription notification messages and privacy links per meeting policy, a...

2 days ago

Microsoft 365 Copilot: Declarative agents model upgrade to GPT-5.1

Microsoft 365 Copilot declarative agents will upgrade to the GPT-5.1 model with an auto architecture by mid-January 2026. The upgrade enables ...

2 days ago

Microsoft Teams: Enhancing update efficiency through peer-to-peer (P2P) download

Microsoft Teams will use peer-to-peer update distribution via Delivery Optimization starting December 2025, enabling devices on the same netwo...

2 days ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy