Visit the Action center to see remediation actions
Article
During and after an automated investigation, remediation actions for threat detections are identified. Depending on the particular threat and how automated investigation and remediation capabilities are configured for your organization, some remediation actions are taken automatically, and others require approval. If you're part of your organization's security operations team, you can view pending and completed remediation actions in the Action center.
Recently, the Action center was updated. You now have a unified Action center experience. To access your Action center, go to https://security.microsoft.com/action-center and sign in.
What's changed?
The following table compares the new, unified Action center to the previous Action center.
In the Microsoft Defender portal, choose Automated investigations > Action center.
The unified Action center brings together remediation actions across Defender for Endpoint and Defender for Office 365. It defines a common language for all remediation actions, and provides a unified investigation experience.
You can use the unified Action center if you have appropriate permissions and one or more of the following subscriptions:
Use the Pending actions and History tabs. The following table summarizes what you'll see on each tab:
Tab
Description
Pending
Displays a list of actions that require attention. You can approve or reject actions one at a time, or select multiple actions if they have the same type of action (such as Quarantine file).