Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
As threats are detected, remediation actions come into play. Depending on the particular threat and how your security settings are configured, remediation actions might be taken automatically or only upon approval. Examples of remediation actions include stopping a process from running or removing a scheduled task.
All remediation actions are tracked in the Action Center.
This article describes how to use the Action Center to review pending and completed remediation actions in Defender for Business.
How to use the Action Center
Use the following steps to open and review the Action Center.
In the Defender portal at https://security.microsoft.com, go to Actions & submissions > Action Center. Or, to go directly to the Action Center page, use https://security.microsoft.com/action-center.
On the Action Center page, use the available tabs:
- Pending: View and approve (or reject) any pending actions. Actions on the Pending tab can arise from anti-virus protection, anti-malware protection, automated investigations, manual response activities, or live response sessions.
- History: View completed actions.
Remediation actions
Defender for Business includes several remediation actions. These actions include manual response actions, actions following automated investigation, and live response actions.
The following table lists remediation actions that are available.
| Source | Actions |
|---|---|
| Automatic attack disruption |
|
| Automated investigations |
|
| Manual response actions |
|
| Live response |
|
Next steps
Use the following articles to learn more about responding to threats and managing devices: