Automated investigation and response (AIR) is the part of Microsoft Defender for Endpoint that examines the evidence behind an alert and cleans up what it finds, either on its own or after you approve. Whether it acts or waits is decided by the automation level of the device group a device lands in, which is why Intune admins who tag devices end up influencing security operations more than they expect. In this post I'll walk through how AIR works today, how to design device groups and pick a level, and how to approve, reject and undo remediation in the Action center.
Note: Microsoft changed AIR in September 2026. Message center post MC1411577 (published July 2026) and the Learn documentation state that, as of 1 September 2026, AIR no longer runs as a separate investigation experience and can no longer be started manually; its detection and response capabilities run automatically as part of Defender Antivirus always-on protection, and a full antivirus scan replaces a manually initiated investigation. The device group, automation level and Action center documentation described below is still published (last updated July 2026). Re-check the Learn pages before you change anything, because this area is still moving.
How it works#
An automated investigation starts when an alert is raised and an incident is created. Defender collects the evidence on the device (files, processes, services, registry keys, scheduled tasks), reaches a verdict for each item, and proposes remediation. The verdicts are Malicious, Suspicious or No threats found. If the same incriminated entity shows up on other devices, the investigation expands to those devices; an expansion that would pull in 10 or more devices waits for approval.
The remediation actions AIR can take are quarantine a file, remove a registry key, kill a process, stop a service, disable a driver and remove a scheduled task. Every action, pending or completed, is recorded in the Action center of the Microsoft Defender portal. AIR needs Defender for Endpoint Plan 2 (or Defender for Business, where it is preconfigured), and it needs Microsoft Defender Antivirus running in active or passive mode on the device. Automated investigation is on by default; the old on/off switch under advanced features has been removed.
Step-by-step#
1. Design your device groups#
Go to Settings › Endpoints › Permissions › Device groups (security.microsoft.com). A device group has a name, a remediation level, a matching rule and, optionally, Microsoft Entra user groups that may see and act on its devices. The rule matches on device name, domain, tags and OS platform, with up to 10 values per property; a device must satisfy all conditions. A device that matches several groups is placed only in the highest-ranked one (rank 1 is highest), so order your groups from most specific to most general. Anything unmatched falls into Ungrouped devices (default), which you cannot rank or delete, but whose remediation level you can change. You can create up to 2,000 groups, and changes can take minutes to several hours to propagate.
2. Choose the automation level#
The level names in the Learn documentation are:
| Level | What happens |
|---|---|
| Full - remediate threats automatically | Malicious verdicts are remediated without approval. Microsoft's recommended setting, and the default for tenants created on or after 16 August 2020 that have no device groups. |
| Semi - require approval for all folders | Every remediation waits on the Pending tab. Default for older tenants with no device groups. Pending actions expire after seven days and are then treated as rejected. |
| Semi - require approval for core folders remediation | Files in operating system folders such as \windows\* wait for approval; files elsewhere are remediated automatically. |
| Semi - require approval for non-temp folders remediation | Files in temporary locations (user temp, Downloads, Windows temp and similar) are remediated automatically; everything else waits. |
| No automated response | No investigation runs and nothing is logged in the Action center for those devices. Microsoft advises against it. |
The device group wizard may word these slightly differently (for example "Full remediation" and "Semi - Approval required for system folders"), but they map one to one. A sensible starting point is Full for workstations and a Semi level for servers or a pilot ring, then tighten or loosen once you have seen a few weeks of Action center history.
3. Feed the groups from Intune with device tags#
Tags are the easiest way to make device groups follow your Intune structure. For Windows, Microsoft documents two methods: a custom Intune configuration profile with OMA-URI ./Device/Vendor/MSFT/WindowsAdvancedThreatProtection/DeviceTagging/Group (data type String), or the registry value Group (REG_SZ, up to 200 characters) under HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection\DeviceTagging. Client-side tags sync about once a day; a restart forces it. For macOS and Linux you can set the tag in an endpoint detection and response policy or a configuration profile, and for iOS and Android through an Intune app configuration policy. Dynamic tag rules in the Defender portal (Asset rule management) can also assign tags from device properties and refresh roughly hourly.
4. Work the Action center#
Open Action center in the Defender portal. The Pending tab lists actions waiting for a decision: select one, review the evidence, and choose Approve, Reject, Open investigation page or Go hunt. You can do the same from an incident: Incidents & alerts › Incidents, open the incident, then the Evidence and Response tab. The History tab shows everything already done.
5. Undo an action and handle false positives#
If a file or device turns out to be clean, go to Action center › History, select the entry and choose Undo. Microsoft documents undo for these actions: disable a driver, isolate device, quarantine a file, remove a registry key, remove a scheduled task, restrict code execution and stop a service, whether they were taken automatically or manually. You can select several entries of the same action type and undo them together, and for a quarantined file the flyout offers Apply to X more instances of this file to release it everywhere. Undo restores the item but does not stop the next detection; to prevent a repeat, add an allow indicator for the file under Settings › Endpoints › Indicators and submit the sample to Microsoft for analysis.
Verify#
- On a device page in Assets › Devices, confirm the device shows the expected tag and group. New groups can take hours to appear as filters.
- Use Show preview in the group wizard to check that the matching rule returns the devices you intended before you submit it.
- After the next real detection, look at the incident's Evidence and Response tab and the Action center: with Full you should see completed actions in History; with a Semi level you should see them on Pending.
Tips & gotchas#
- Any playbook, script or SOAR integration that started an investigation manually stopped working on 1 September 2026; replace that step with a full antivirus scan.
- Deleting a device group removes it from email notification rules, and a rule that only referenced that group is deleted with it.
- Device groups also scope RBAC. A group with no Entra user group assigned is visible to everyone with portal access.
- Potentially unwanted application (PUA) protection and other antivirus settings influence what is remediated automatically, independent of the automation level.
- Device group creation is available in Plan 1 and Plan 2, but the investigation and remediation itself requires Plan 2.