Undo Automatic Investigation Remediations

MVP

According to the documentation, you can undo automatic investigation remediations for things such as Task Scheduler entries and quarantine.  This is particularly useful for getting buy-in to enabling fully automated remediation, rather than approval based.

 

firefox_2021-05-26_08-13-36.png

In my environment, there is no option for undo in the flyout pane for either a single historic action centre entry or multiple.  Specifically, I am trying to undo the removal of a scheduled task. Are there prerequisites for this, or am I missing something else?  Devices are Windows 10 2004, hybrid Azure AD joined, using MDAV as the engine, and still onboarded to MDE.

 

 

 

 

0 Replies