Intune - How to Enable AIR (Automatic, Investigation and Remediation)

Sokoban 1,061 Reputation points
2023-08-31T08:27:25.55+00:00

Im trying to setup "Security Microsoft Defender for Endpoint - Best Practices" and I have coming to a part of AIR (Automatic, Investigation and Remediation)

I find that ,

  • Create a Role Group in MDE Settings > Permission > Roles (select a group)
  • Create a MDE machine group, set it to all machines, and assign it to Full – Remediate threats automatically
  • Enable Automated Investigation in MDE Settings > Advanced Features
  • Enable all of the MDE Settings > Advanced Features (or as many as you are licensed for, ex: MDI, Intune, MD4CA, etc).

But the problem is I don´t understand how I do that ...

// Sokoban

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Intune | Security
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

Accepted answer
  1. Givary-MSFT 35,626 Reputation points Microsoft Employee Moderator
    2023-08-31T12:24:35.04+00:00

    @Sokoban Thank you for reaching out to us, As I understand you are trying to configure automated investigation and remediation capabilities in Microsoft Defender for Endpoint.

    In the above query, steps which you mentioned are needs to be performed from Microsoft 365 Defender portal (https://security.microsoft.com).

    Detailed steps on how to configure it are documented here - https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-automated-investigations-remediation?view=o365-worldwide

    Couple of videos also available online in how to configure the same have been explained here

    https://www.youtube.com/watch?v=lu5G-VbELyg

    https://www.youtube.com/watch?v=1UJoH-p3Xik

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.