SHD / MC Checker

MC1431377 | (Updated) Microsoft Defender for Office 365: AIR Investigation Experience Improvements



MC1431377 | (Updated) Microsoft Defender for Office 365: AIR Investigation Experience Improvements

Classification stayInformed
Last Updated 08/06/2026 16:32:14
Start Time 07/17/2026 21:38:06
End Time 09/30/2026 07:00:00
Message Content

Updated August 6, 2026: We have updated the timeline. Thank you for your patience. 

[What and Why:]

Microsoft is enhancing the Automated Investigation and Response (AIR) experience in Microsoft Defender for Office 365 by introducing a manual refresh capability and simplifying investigation naming conventions. These changes improve portal performance, reduce unnecessary network activity, and support data minimization principles by removing email subjects and User Principal Names (UPNs) from investigation names.

[Rollout Schedule:]

  • General Availability (Worldwide): Beginning in mid-August 2026 (previously late July) and expected to complete by late August 2026

[Impact on Your Organization:]

Who is affected:

  • Security Operations Center (SOC) analysts
  • Security administrators
  • Incident responders
  • Organizations using Microsoft Defender for Office 365 Plan 2 / E5 and AIR

Platforms/Services:

  • Microsoft Defender portal
  • Microsoft Defender for Office 365
  • Automated Investigation and Response (AIR)

What will happen:

  • Manual refresh replaces auto-refresh:

    • The AIR Investigations page will no longer refresh automatically.
    • A new Refresh button will be available on the Investigations page.
    • Analysts must manually refresh the page to obtain the latest investigation status and details.
    • This change is enabled by default as part of the service update.
    • Improved page responsiveness and reduced background network calls are expected.

  • Simplified investigation names:

    • Investigation names for Manual and User-Reported will no longer include email subject lines
    • Generic investigation names will be displayed instead, such as:

      • Email investigation for ‘Network message Id”
      • User reported message as malicious “Network message Id”

    • Existing investigation history and results remain unchanged.

  • No changes to existing capabilities

    • Investigation triggers remain unchanged.
    • Detection logic remains unchanged.
    • Automated remediation actions remain unchanged.
    • Threat Explorer functionality remains unchanged.
    • Email & Collaboration reports remain unchanged.
    • Historical investigation records remain available.

[Action Required/Recommendations:]

No mandatory administrative configuration is required.

Recommended actions:

  • Review SOC workflows that rely on automatic refresh behavior.
  • Inform security analysts that investigation status updates now require use of the new Refresh button.
  • Review automation, runbooks, scripts, dashboards, or integrations that may parse investigation names.
  • Update internal SOPs, analyst guides, and training materials that reference investigation names containing email subjects.
  • Communicate the naming convention change to help desk and security teams prior to rollout.
  • Validate any custom reporting processes that may depend on previous investigation naming formats.

Learn more: Details and results of AIR in Defender for Office 365 Plan 2 – Microsoft Defender for Office 365 | Microsoft Learn (will be updated before rollout)

[Compliance Considerations:]

Area Explanation
Existing customer data processing/access Investigation names will no longer expose email subjects, supporting data minimization and changing how investigation-related data is presented to administrators.
Admin monitoring and reporting Organizations may need to update reporting, operational procedures, and investigation workflows that reference investigation names.
Machine Translation

2026年8月6日更新:タイムラインを更新しました。ご辛抱いただきありがとうございます。 

[何となぜ:]

MicrosoftはMicrosoft Defender for Office 365自動調査・応答(AIR)体験を強化し、手動リフレッシュ機能を導入し、調査の命名規則を簡素化しています。これらの変更により、ポータルのパフォーマンスが向上し、不要なネットワーク活動を減らし、調査名からメールの件名やユーザープリンシパル名(UPN)を削除することでデータ最小化の原則を支援します。

[展開スケジュール:]

  • 一般稼働(世界展開):2026年8月中旬(以前 は7月 下旬)から始まり、2026年8月下旬までに完了予定です

[組織への影響:]

影響を受ける人物:

  • セキュリティオペレーションセンター(SOC)アナリスト
  • セキュリティ管理者
  • インシデント対応者
  • Microsoft Defender for Office 365 Plan 2 / E5 および AIR を使用している組織

プラットフォーム/サービス:

  • Microsoft Defender ポータル
  • Microsoft Defender for Office 365
  • 自動調査・対応(AIR)

今後の展開:

  • 手動リフレッシュが自動リフレッシュに代わる:

    • AIR調査ページは自動的に更新されなくなります。
    • 新しい リフレッシュ ボタンが調査ページに登場します。
    • 分析官は最新の調査状況や詳細を取得するために手動でページを更新する必要があります。
    • この変更はサービスアップデートの一環としてデフォルトで有効化されます。
    • ページの応答性の向上とバックグラウンドネットワーク通話の減少が期待されています。

  • 簡略化された調査名:

    • ManualおよびUser-Reportedの調査名称には、メールの件名が含まれなくなります
    • 代わりに、以下のような一般的な調査名が表示されます。

      • 「ネットワークメッセージID」に関するメール調査
      • ユーザーが「ネットワークメッセージID」として悪意のあるメッセージを報告しました

    • 既存の調査経歴と結果は変わっていません。

  • 既存の機能に変更はありません

    • 調査のトリガーは変更されていません。
    • 検知ロジックは変更されていません。
    • 自動修復措置は変更されていません。
    • 脅威エクスプローラーの機能は変更されていません。
    • メールおよびコラボレーションレポートは変更されていません。
    • 過去の調査記録は依然として入手可能です。

[必要な行動/推奨事項:]

必須の管理設定は必要ありません。

推奨される行動:

  • 自動リフレッシュ動作に依存するSOCワークフローを見直しましょう。
  • セキュリティアナリストに対し、調査状況の更新には新しい リフレッシュ ボタンの使用が必要になることを知らせてください。
  • 自動化、ランブック、スクリプト、ダッシュボード、または調査名を解析できる統合をレビューしてください。
  • 調査名にメールの件名を記載した社内SOP、アナリストガイド、研修資料を更新してください。
  • 展開前に、命名規則の変更をヘルプデスクやセキュリティチームに伝えてください。
  • 過去の調査命名形式に依存している可能性のあるカスタム報告プロセスの検証。

詳細はこちら:Defender for Office 365プラン2におけるAIRの詳細と結果 – Microsoft Defender for Office 365 |Microsoft Learn(展開前に更新予定)

[コンプライアンス上の考慮事項:]

面積 説明
既存の顧客データ処理/アクセス 調査名はメールの件名を露出させなくなり、データの最小化を支援し、調査関連データの管理者への提示方法を変えます。
管理者の監視と報告 組織は調査名を参照する報告、運用手順、調査ワークフローの更新が必要になる場合があります。