Loading...

Microsoft Defender for Office 365: Auto-remediation of malicious similarity clusters in AIR

Microsoft Defender for Office 365: Auto-remediation of malicious similarity clusters in AIR

Microsoft Defender for Office 365 expands AIR auto-remediation to malicious similarity clusters, automating approval of remediation actions without manual intervention. Rolling out worldwide mid to late December 2025, this feature reduces SOC workload and speeds threat response. It’s off by default and can be enabled in the Defender portal. Introduction We are expanding the auto-remediation capabilities in Automated Investigations and Response (AIR) to fully automate the remediation of malicious similarity clusters. Earlier this year, we introduced auto-remediation for malicious URL and file clusters. Building on that foundation, this enhancement enables AIR to automatically approve all pending remediation actions it generates—eliminating the need for manual intervention and streamlining the response process for SOC teams. This advancement significantly reduces response time and operational overhead, allowing security teams to focus on higher-priority threats. This message is associated with Microsoft 365 Roadmap ID 502528. When this will happen General Availability (Worldwide): We will begin rolling out in mid-December 2025 and expect to complete by late December 2025. How this will affect your organization Who is affected: Microsoft Defender for Office 365 Plan 2 and Microsoft Defender for Endpoint E5 customers. What will happen: AIR will automatically approve all pending remediation actions for malicious similarity clusters. This feature extends existing auto-remediation for URL and file clusters to include similarity clusters. This feature is not enabled by default. Admins can turn it on in the Microsoft Defender portal by configuring MDO automation settings. No manual intervention will be required for these remediation actions. Key benefits: Increased post-delivery protection by identifying campaigns and removing malicious messages faster. Reduced SOC workload by eliminating manual cleanup actions. What you need to do to prepare Learn more: No admin action is required before rollout. If you want to enable or verify this feature: In the Defender portal (security.microsoft.com), go to Settings > Email & collaboration > MDO automation settings. Select multiple similar attributes (similar files and similar URLs options were previously available and can also be selected). Select Save to enable auto-remediation. View image in new tab Automated investigation and response (AIR) examples in Microsoft Defender for Office 365 Plan […]

The post Microsoft Defender for Office 365: Auto-remediation of malicious similarity clusters in AIR appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Defender for Office 365: Auto-remediation of malicious similarity clusters in AIR

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft OneDrive and SharePoint: Generate smart tables of contents for PDFs on the web with Copilot

Microsoft 365 Copilot users can generate AI-created, hierarchical, clickable tables of contents for PDFs in OneDrive and SharePoint on the web...

12 hours ago

Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role

Microsoft is updating Microsoft Defender for Office 365’s Unified RBAC mapping for the Microsoft Entra Security Operator role, removing ...

12 hours ago

Microsoft 365 Copilot: new guided Copilot onboarding experience

Microsoft 365 Copilot introduces an optional, admin-enabled guided onboarding experience for Frontier participants starting late October 2026....

12 hours ago

Microsoft Purview |Unified Classification Management Experience

Microsoft Purview is launching a unified Classification Management experience for admins to manage classifiers consistently. Public Preview st...

12 hours ago

Microsoft Purview | Data Loss Prevention: Administrative Units support for DLP policies for Microsoft Copilot

Microsoft Purview extends Microsoft Entra Administrative Units support to Copilot DLP policies, enabling delegated management within units whi...

12 hours ago

Action required: Update Teams devices to a minimum app version ahead of the retirement of Exchange Web Services (EWS)

Update Microsoft Teams Rooms on Android, phones, and panels to the minimum app version released in February 2026 before October 2026 to avoid ...

12 hours ago

Microsoft Power Platform governance and administration – Secure Dataverse record with column-based filtering

We are announcing the ability for admins to use filtered views to select and manage record-level access securely by defining security based on...

12 hours ago

Microsoft Teams: Impersonation Protection for Teams meetings

Impersonation Protection for Teams meetings helps users identify potentially deceptive participants and meeting organizers. When Teams detects...

2 days ago

Microsoft Copilot (Microsoft 365): Use Dataverse Business Skills in Sales Agent

Business Skills are natural language instructions authored and stored in Microsoft Dataverse that teach Sales Agent how work gets done within ...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.