Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
As of September 1, 2026, automated Investigation and Response (AIR) will no longer run as a separate investigation experience or be available for manual triggering in Microsoft Defender for Endpoint alerts and remediations.
- AIR detection and response capabilities for Defender for Endpoint are already included in Microsoft Defender for Endpoint's default antivirus protection stack and run automatically. For on-demand investigations, run a full antivirus scan as needed.
- This change applies only to Microsoft Defender for Endpoint. AIR capabilities for Defender for Office 365 remain available.
Threat protection features in Microsoft Defender XDR can result in certain remediation actions. Here are some examples:
- Automated investigations can result in remediation actions that are taken automatically or await your approval.
- Antivirus, anti-malware, and other threat protection features can result in remediation actions, such as blocking a file, URL, or process, or sending an artifact to quarantine.
- Your security operations team can take remediation actions manually, such as during advanced hunting or while investigating alerts or incidents.
Note
You must have required permissions for Action center tasks to approve or reject remediation actions. For more information, see the prerequisites for automated investigation and response.
To navigate to the Action center, take one of the following steps:
- Go to the Microsoft Defender Action center; or
- In the Microsoft Defender portal, in the Automated investigation & response card, select Approve in Action Center.
Review pending actions in the Action center
It's important to approve (or reject) pending actions as soon as possible so that your automated investigations can proceed and complete in a timely manner.
Go to Microsoft Defender portal and sign in.
In the navigation pane under Actions and submissions, choose Action center.
In the Action center, on the Pending tab, select an item in the list. The item's flyout pane opens. Here's an example.
Review the information in the flyout pane, and then take one of the following steps:
- Select Open investigation page to view more details about the investigation.
- Select Approve to initiate a pending action.
- Select Reject to prevent a pending action from being taken.
- Select Go hunt to go into Advanced hunting.
Tip
You now have more options to review and approve/reject a remediation action. In addition to using the Action center, you can also approve or reject a remediation action while reviewing an incident. For more information, see Approve or reject remediation actions.
Undo completed actions
If you determine that a device or a file isn't a threat, you can undo the remediation actions that were taken. You can undo actions whether they were taken automatically or manually. In the Action center, on the History tab, you can undo any of the following actions:
| Action source | Supported Actions |
|---|---|
| - Automated investigation - Microsoft Defender Antivirus - Manual response actions |
- Isolate device - Contain device - Contain user - Restrict code execution - Quarantine a file - Remove a registry key - Stop a service - Disable a driver - Remove a scheduled task |
Note
Only Security Administrators and higher are allowed access to undo operations such as File Quarantine.
Undo one remediation action
To undo a single remediation action:
Go to the Microsoft Defender Action center and sign in.
On the History tab, select an action that you want to undo.
In the pane on the right side of the screen, select Undo.
Undo multiple remediation actions
To undo multiple remediation actions at once:
Go to the Microsoft Defender Action center and sign in.
On the History tab, select the actions that you want to undo. Make sure to select items that have the same Action type. A flyout pane opens.
In the flyout pane, select Undo.
Remove a file from quarantine across multiple devices
To remove a quarantined file from multiple devices at once, perform the following steps:
Go to the Action center (https://security.microsoft.com/action-center) and sign in.
On the History tab, select a file that has a Quarantine file Action type.
In the pane on the right side of the screen, select Apply to X more instances of the selected quarantined file, and then select Undo.
Next steps
- View the details and results of an automated investigation
- Address false positives or false negatives
Tip
Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender XDR Tech Community.