Blog Post

Microsoft Defender for Endpoint Blog
3 MIN READ

Microsoft Defender for Endpoint: Automation defaults are changing

israelcohen's avatar
israelcohen
Icon for Microsoft rankMicrosoft
Jan 17, 2021

We are excited to announce that we are about to increase our customers’ protection by upgrading the default automation level of our Microsoft Defender for Endpoint customers who have opted into public previews from Semi - require approval for any remediation to Full – remediate threats automatically. 

 

Auto investigation and remediation overview

When an alert is raised in Microsoft Defender for Endpoint, an automated investigation immediately starts running on the machine where the suspicious activity was detected. It begins with an analysis of the malicious entities that are part of the alert and continues with collection and examination of other entities associated with it. The automated investigation inspects files, processes, services, registry keys, and any area that may contain threat-related evidence.

 

The result of an automated investigation started by an alert is a list of related entities found on a device and their verdicts (malicious, suspicious, or clean). For any malicious entity, the investigation will create a remediation action, an action that, when approved, will remove or contain a malicious entity that was found in the investigation. These actions are defined, managed, and executed by Microsoft Defender for Endpoint without the security operations team having to remotely connect to the device.

 

 

Remediation actions are approved or declined according to the device automation level. When it is set to ‘Full’, the remediation action will be approved automatically, without further waiting. When it is set to ‘Semi’, the action will wait for manual approval, which may lead to losing valuable time in which the malware may cause damage and spread to other devices.

 

 

Automated investigation and remediation supports queuing of remediation actions for devices that are not available, so that when they become available, the actions will be triggered immediately. All remediation actions, whether pending, running, or completed, can be viewed in the Action Center. If you’ve determined that a detected device or a file is not actually a threat, you can undo remediation actions that were taken for a specific device or across the entire organization.

 

Empowering defenders with automation by default

When our automated investigation and remediation capabilities were first introduced, the default automation level was set to semi - require approval for any remediation. Since then, we have increased our malware detection accuracy, added the option to undo remediation actions, and improved our automated investigation infrastructure. Throughout this time, we have seen thousands of cases where organizations with fully automated tenants have successfully contained and remediated threats, while other companies, left with the default ‘semi’ level, have remained at high risk due to lengthy pending time for approval of actions.

 

Data collected and analysed over the past year shows that organizations who are using full automation have had 40% more high-confidence malware samples removed than customers using lower levels of automation. Full automation also frees up our customers’ critical security resources so they can focus more on their strategic initiatives.

 

In light of the significant benefits of using automatic approval of remediation actions, and after changing the default automation level for new customers, starting February 16, 2021, tenants who have opted in for public previews in the Microsoft Defender for Endpoint will be automatically upgraded to the new default automation level: Full-remediate threats automatically.

 

The new default automation level can be kept (this is recommended) or changed according to your organizational needs. This change does not impact or override device group definitions that were previously set to control automation level.

 

To get started with Microsoft Defender for Endpoint public preview capabilities, we encourage customers to turn on preview features in Microsoft Defender Security Center.

 

If you’re not yet taking advantage of Microsoft’s industry leading optics and detection capabilities, sign up for a free trial of Microsoft Defender for Endpoint today.

 

Additional resources:

Create and manage device groups

Automation levels in automated investigation and remediation capabilities

Review and approve remediation actions following an automated investigation

Updated Jun 09, 2021
Version 5.0
  • AxelHellstrom's avatar
    AxelHellstrom
    Copper Contributor

    ejbakker - Yes, to onboard for the Security Center you will have to use the Log Analytics Agent (And with server 2016 or 2019 i belive that you also need to onboard into the DATP portal since it's not synced per auto on these OS, but please correct me if im wrong).

    Defender For Identity will use a censor instead of an agent from what i know.

  • ejbakker's avatar
    ejbakker
    Copper Contributor

    I have a short question about the following: 

    Does someone now the Difference between Microsoft Defender for Identiy Sensors and Microsoft Defender Security Center Onboarding. When i have for example a domain controller VM. Do i put the Defender for Identity Sensor on the server and also onboard the server in the MS Defender Security Center?