

Remediation actions that were taken as a result of automated investigations Serves as an audit log for actions that were taken, such as: Make sure to review and approve (or reject) pending actions as soon as possible so that your automated investigations can complete in a timely manner. You can approve or reject actions one at a time, or select multiple actions if they have the same type of action (such as Quarantine file). The following table summarizes what you'll see on each tab: Tabĭisplays a list of actions that require attention. Use the Pending actions and History tabs. Or, in the Automated investigation & response card, select Approve in Action Center.

In the navigation pane, choose Action center. Go to Microsoft 365 Defender portal and sign in.

You can navigate to the list of actions pending approval in two different ways: You can use the unified Action center if you have appropriate permissions and one or more of the following subscriptions: Your security operations team has a "single pane of glass" experience to view and manage remediation actions. It defines a common language for all remediation actions and provides a unified investigation experience. The unified Action center brings together remediation actions across Defender for Endpoint and Defender for Office 365.
