Remediation steps taken against devices, mailboxes and identities, whether triggered by automated investigations, attack disruption or a person, are gathered on this Microsoft Defender portal page. Pending items can be approved or rejected here, and finished ones reversed.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Action center in context, with comparison tables and the common traps.
Terms in this definition
- remediation
Applying updates through vSphere Lifecycle Manager, entering maintenance mode where needed, so that every cluster and host ends up compliant with its image or baselines. Readiness can first be confirmed by a pre-check that changes nothing.
- Microsoft Defender portal
At security.microsoft.com, one place to work with Defender XDR, Microsoft Sentinel, Defender for Cloud Apps and further Microsoft security products.
Related terms
- AIR
Automated investigation and response in Microsoft Defender: alerts are examined without an analyst, each item of evidence gets a verdict, and fixes are carried out or suggested in the Action center. For Office 365 protection it requires Defender for Office 365 Plan 2.
- Contain user
Stops a compromised account's network logons and lateral movement by pushing a policy to every onboarded device. Automatic attack disruption uses this Defender for Endpoint action, which you can reverse from the Action center or from the user's page.