The full and semi-automated remediation levels set per device group, how pending actions expire, and what automation folder exclusions do and don't affect.
From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)
Automated investigation and response (AIR) examines alerts and remediates threats with or without approval, depending on the automation level of each device group. Its standalone experience changed in 2026, so current behaviour matters.
AIR produces a verdict for each piece of evidence (Malicious, Suspicious or No threats found) and identifies remediation actions such as quarantining a file, stopping a process, removing a scheduled task or isolating a device. Alerts that arrive while an investigation runs are added to it, and the scope expands to other devices where the same threat is seen; if expansion finds 10 or more devices, that expansion needs approval. AIR needs Defender Antivirus in active or passive mode.
As of 1 September 2026, AIR no longer runs as a separate investigation experience and can’t be triggered manually for Defender for Endpoint. Its detection and response capabilities run automatically as part of the default antivirus protection stack; for an on-demand investigation, run a full antivirus scan. AIR for Defender for Office 365 remains available, and even there no remediation is taken automatically for email: all email actions wait for approval in the Action center.
Automation levels are set per device group as the Remediation level.
| Level | What happens | Pending approvals in |
|---|---|---|
| Full - remediate threats automatically | All remediation on malicious entities is automatic | None; actions appear on History |
| Semi - require approval for all folders | Every file remediation needs approval | Pending |
| Semi - require approval for core folders remediation | Approval only for core OS folders such as \windows\*; other folders automatic |
Pending for core folders |
| Semi - require approval for non-temp folders remediation | Automatic in temporary folders (for example \users\*\appdata\local\temp\*, \windows\temp\*, \users\*\downloads\*); approval elsewhere |
Pending for non-temp folders |
| No automated response | Automated investigation doesn’t run | None; not recommended |
The unified Action center (Actions & submissions > Action center) lists actions for devices, email and identities. Pending is where you approve or reject; History is the audit log and lets you undo certain actions (for example isolation and restrict code execution). The Action source column distinguishes manual device, manual email, automated device, automated email, advanced hunting, Explorer and live response actions. Approving device remediation needs Response (manage) in unified RBAC, Security Administrator in Entra, or the MDE Active remediation actions role; email remediation also needs the Search and Purge role.
Two rules pages tune AIR:
File is excluded. Managing them needs Core security settings (manage).Common trap: Expecting a semi-automated pending action to wait indefinitely - pending actions expire after seven days and are then treated as rejected.
Common trap: Using an automation folder exclusion to stop antivirus detections in a folder - it affects only automated investigation and remediation; antivirus scanning continues.
This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-200 terms in the glossary · All SC-200 study notes
Which background query tool fits a requirement, compared by data source, joins, schedule, lookback, timeout and result limits.
How Defender XDR custom detections, scheduled, NRT, threat intelligence, Fusion, ML and anomaly rules differ, and the capability gaps that still decide between them.
How the two Azure Monitor Agent connectors differ, how a Linux log forwarder is set up, and how to avoid ingesting the same messages twice.
What ASR rules need to run, the difference between Audit, Warn, Block, Disabled and Not configured, and which deployment methods support per-rule exclusions.
The three advanced feature toggles, basic versus advanced live response permissions, the key commands and the session and file size limits.
Which email protection and investigation tools each plan includes, with the Safe Attachments responses, impersonation settings and zero-hour auto purge actions.
How the two risk types and their detections work, where to see them, and how risk-based Conditional Access now replaces the retired legacy risk policies.