Automated investigation and response in Microsoft Defender: alerts are examined without an analyst, each item of evidence gets a verdict, and fixes are carried out or suggested in the Action center. For Office 365 protection it requires Defender for Office 365 Plan 2.
Also called automated investigation and response.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AIR in context, with comparison tables and the common traps.
Terms in this definition
- Analyst
A reasoning agent built by Microsoft that comes alongside Researcher for people with a Microsoft Copilot licence, and writes and runs code to work through raw data such as multiple spreadsheets. Agent settings don't govern it, because it belongs to the core Copilot Chat experience.
- Action center
Remediation steps taken against devices, mailboxes and identities, whether triggered by automated investigations, attack disruption or a person, are gathered on this Microsoft Defender portal page. Pending items can be approved or rejected here, and finished ones reversed.
- Microsoft 365
Formerly Office 365, Microsoft's software-as-a-service productivity suite. A Microsoft Entra tenant provides its identity, and its data is not governed by Azure RBAC.
- Defender for Office 365 Plan 2
The higher tier of Defender for Office 365: everything Plan 1 offers, plus advanced hunting, AIR, Threat Explorer, Threat Trackers and Attack simulation training. Microsoft 365 E5 bundles it.
Related terms
- Microsoft Defender for Office 365
Microsoft's protection service for email and collaboration tools. Its basic plan covers impersonation, Safe Attachments, Real-time detections and Safe Links; the higher plan layers on Attack simulation training, automated investigation and response, and Threat Explorer.