Remediate and reduce human risk: AIR and attack simulation training
You confirm the Woodgrove message is phishing and open the Take action wizard from Threat Explorer. But automated investigation and response (AIR) already found and clustered messages like this one before you ever opened the alert, grouping it with other messages that share the same malicious pattern. That raises a question worth answering before you click anything.
Guiding question: When AIR auto-remediates a cluster of malicious messages like the one you found, does it delete those messages permanently, or something else?
Soft delete: reversible by design
AIR doesn't permanently purge malicious clusters. For malware, malicious URL, and phishing clusters, its configured remediation action is soft delete, which moves the messages to a location you can still recover from rather than erasing them outright. For a malicious URL specifically, AIR pairs that soft delete with a second control: it blocks the URL at time-of-click, so even if a copy of the message somehow reaches an inbox elsewhere, the link itself stops working the moment someone selects it.
That reversibility matters because classifications sometimes need a second look. If your investigation later shows a cluster was flagged in error, soft-deleted messages are still recoverable. A permanent delete wouldn't give you that option.
Who approves the remediation
Soft-deleting the Woodgrove cluster doesn't happen without oversight, at least not by default. Most AIR remediation actions, including soft-deleting messages and turning off external mail forwarding, land as pending actions and wait for a member of your SecOps team to approve them from the Pending actions tab or the unified Action center. That approval step is your check on automation: nothing gets remediated tenant-wide until someone confirms it should be.
There's one exception, and it's the case AIR was built to handle at scale. When a similarity cluster, such as a malicious URL or file cluster, is fully confirmed as malicious, AIR automatically approves its own pending remediation actions for that cluster. No one from SecOps has to click approve. That auto-approval exists specifically to eliminate manual intervention for the clusters AIR is most confident about, so your team spends its approval time on the messages that genuinely need a human judgment call, not on cases already proven malicious.
| AIR aspect | Behavior |
|---|---|
| Remediation action | Soft delete (reversible)—for a malicious URL cluster, also blocks the URL at time-of-click |
| Default approval | Actions land as pending, waiting for SecOps approval in the Pending actions tab or Action center |
| Exception | A fully confirmed malicious cluster auto-approves its own actions—no manual step |
Learn more about remediation actions from AIR and how automated investigation and response decides which actions to auto-approve.
From the message to the person
The Woodgrove cluster is handled. It's soft-deleted, the malicious URL is blocked at time-of-click, and either SecOps approved the action or AIR auto-approved it because the cluster was fully confirmed. But remediating a message doesn't touch the reason it worked in the first place: someone on the finance team almost forwarded a wire-transfer request to an attacker. Technology stopped this message. It doesn't tell you whether the same person clicks the next one.
That's the gap attack simulation training closes. You can launch a realistic phishing simulation targeted at the finance team, styled on the same wire-transfer pretext, and measure who reports it and who doesn't. But a simulation isn't your only option, and it's not always the right one for what just happened.
Assigning training without a simulation
Sometimes you don't need to test the finance team again. You already know they need training, because a real message almost got through. That's what a Training campaign is for: it assigns training modules directly to a targeted group without putting anyone through a simulation first. Instead of waiting to see who clicks a fake phishing email, you go straight to reinforcing the lesson, similar to how you might roll out a monthly cybersecurity awareness module tenant-wide.
For the finance team, right after a real wire-transfer phishing attempt, a Training campaign is the faster path. You skip the simulation step entirely and assign a module on recognizing payment-fraud requests directly to the people who need it most, right when the incident is still fresh.
Setting the training threshold so the lesson actually lands
Here's where a Training campaign can quietly fail without you noticing: the training threshold. By default, Attack simulation training won't reassign a module to a user for 90 days after they've completed it, or after they've been assigned it but haven't finished yet. That default protects people from being buried in repeat assignments, but it also means anyone on the finance team who completed a similar module recently, even a few weeks ago, gets excluded from your new campaign. You'd assign the training, expect full coverage, and end up with a partial rollout instead, missing exactly the people who need reinforcement right now.
You fix that on the Settings tab of the Attack simulation training page. Setting the training threshold to 0 removes the exclusion entirely: everyone in your targeted group gets the training, regardless of whether they've completed or been assigned it within the past 90 days. For a campaign responding to a real incident, that's the setting you want. The finance team gets the module today, not 90 days from now.
Learn more about training campaigns and how to adjust the training threshold and other global settings for Attack simulation training.
You've now defended the workload end to end: policies, protection, alerts, investigation, remediation, and training. But Office 365 is one workload inside a much larger security estate. Where does everything you just did plug in, and what sits alongside it that you coordinate with but don't operate yourself?