FREE STUDY NOTES · SC-200

Automated investigation and response in Defender for Endpoint: automation levels explained

The full and semi-automated remediation levels set per device group, how pending actions expire, and what automation folder exclusions do and don't affect.

From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)

Automated investigation and response (AIR) examines alerts and remediates threats with or without approval, depending on the automation level of each device group. Its standalone experience changed in 2026, so current behaviour matters.

AIR produces a verdict for each piece of evidence (Malicious, Suspicious or No threats found) and identifies remediation actions such as quarantining a file, stopping a process, removing a scheduled task or isolating a device. Alerts that arrive while an investigation runs are added to it, and the scope expands to other devices where the same threat is seen; if expansion finds 10 or more devices, that expansion needs approval. AIR needs Defender Antivirus in active or passive mode.

Current state

As of 1 September 2026, AIR no longer runs as a separate investigation experience and can’t be triggered manually for Defender for Endpoint. Its detection and response capabilities run automatically as part of the default antivirus protection stack; for an on-demand investigation, run a full antivirus scan. AIR for Defender for Office 365 remains available, and even there no remediation is taken automatically for email: all email actions wait for approval in the Action center.

Automation levels

Automation levels are set per device group as the Remediation level.

Level What happens Pending approvals in
Full - remediate threats automatically All remediation on malicious entities is automatic None; actions appear on History
Semi - require approval for all folders Every file remediation needs approval Pending
Semi - require approval for core folders remediation Approval only for core OS folders such as \windows\*; other folders automatic Pending for core folders
Semi - require approval for non-temp folders remediation Automatic in temporary folders (for example \users\*\appdata\local\temp\*, \windows\temp\*, \users\*\downloads\*); approval elsewhere Pending for non-temp folders
No automated response Automated investigation doesn’t run None; not recommended

The unified Action center (Actions & submissions > Action center) lists actions for devices, email and identities. Pending is where you approve or reject; History is the audit log and lets you undo certain actions (for example isolation and restrict code execution). The Action source column distinguishes manual device, manual email, automated device, automated email, advanced hunting, Explorer and live response actions. Approving device remediation needs Response (manage) in unified RBAC, Security Administrator in Entra, or the MDE Active remediation actions role; email remediation also needs the Search and Purge role.

Two rules pages tune AIR:

Common trap: Expecting a semi-automated pending action to wait indefinitely - pending actions expire after seven days and are then treated as rejected.

Common trap: Using an automation folder exclusion to stop antivirus detections in a folder - it affects only automated investigation and remediation; antivirus scanning continues.

Get the whole book

This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-200 terms in the glossary · All SC-200 study notes

More SC-200 study notes