Microsoft Defender for Office 365: Auto-Remediation of Malicious Similarity Clusters in AIR Beta
Data as of 2 hours ago (9 September 2026)
Description
We are expanding the auto-remediation capabilities in Automated Investigations and Response (AIR) to fully automate the remediation of malicious similarity clusters. Earlier this year, we introduced auto-remediation for malicious URL and file clusters. Building on that foundation, this enhancement enables AIR to automatically approve all pending remediation actions it generates—eliminating the need for manual intervention and streamlining the response process for SOC teams. This advancement significantly reduces response time and operational overhead, allowing security teams to focus on higher-priority threats.
Change history
Added to the roadmap 3 September 2025. Tracked here since 1 September 2026. Earliest target we recorded: December 2025 (since tracked — Microsoft may have moved it before we started watching).
Nothing has changed on this item since tracking began on 1 September 2026. Changes appear here as Microsoft updates the feed.