Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

(Updated) Microsoft Defender for Office 365: AIR Investigation Experience Improvements

Message ID
MC1431377
View in Message Center
Service
Microsoft Defender XDR
Category
Stay Informed
Tags
Feature updateUser impactAdmin impact
Rollout
August 2026

Summary

Microsoft Defender for Office 365's AIR experience will add a manual refresh button, replacing auto-refresh, and simplify investigation names by removing email subjects and UPNs. These changes improve performance, reduce network activity, and support data minimization. No admin action is required, but workflow updates are recommended.

Details

Updated August 6, 2026: We have updated the timeline. Thank you for your patience. 

[What and Why:]

Microsoft is enhancing the Automated Investigation and Response (AIR) experience in Microsoft Defender for Office 365 by introducing a manual refresh capability and simplifying investigation naming conventions. These changes improve portal performance, reduce unnecessary network activity, and support data minimization principles by removing email subjects and User Principal Names (UPNs) from investigation names.

[Rollout Schedule:]

  • General Availability (Worldwide): Beginning in mid-August 2026 (previously late July) and expected to complete by late August 2026

[Impact on Your Organization:]

Who is affected:

  • Security Operations Center (SOC) analysts
  • Security administrators
  • Incident responders
  • Organizations using Microsoft Defender for Office 365 Plan 2 / E5 and AIR

Platforms/Services:

  • Microsoft Defender portal
  • Microsoft Defender for Office 365
  • Automated Investigation and Response (AIR)

What will happen:

  • Manual refresh replaces auto-refresh:
    • The AIR Investigations page will no longer refresh automatically.
    • A new Refresh button will be available on the Investigations page.
    • Analysts must manually refresh the page to obtain the latest investigation status and details.
    • This change is enabled by default as part of the service update.
    • Improved page responsiveness and reduced background network calls are expected.
  • Simplified investigation names:
    • Investigation names for Manual and User-Reported will no longer include email subject lines
    • Generic investigation names will be displayed instead, such as:
      • Email investigation for 'Network message Id"
      • User reported message as malicious "Network message Id"
    • Existing investigation history and results remain unchanged.
  • No changes to existing capabilities
    • Investigation triggers remain unchanged.
    • Detection logic remains unchanged.
    • Automated remediation actions remain unchanged.
    • Threat Explorer functionality remains unchanged.
    • Email & Collaboration reports remain unchanged.
    • Historical investigation records remain available.

[Action Required/Recommendations:]

No mandatory administrative configuration is required.

Recommended actions:

  • Review SOC workflows that rely on automatic refresh behavior.
  • Inform security analysts that investigation status updates now require use of the new Refresh button.
  • Review automation, runbooks, scripts, dashboards, or integrations that may parse investigation names.
  • Update internal SOPs, analyst guides, and training materials that reference investigation names containing email subjects.
  • Communicate the naming convention change to help desk and security teams prior to rollout.
  • Validate any custom reporting processes that may depend on previous investigation naming formats.

Learn more: Details and results of AIR in Defender for Office 365 Plan 2 - Microsoft Defender for Office 365 | Microsoft Learn (will be updated before rollout)

[Compliance Considerations:]

Area Explanation
Existing customer data processing/access Investigation names will no longer expose email subjects, supporting data minimization and changing how investigation-related data is presented to administrators.
Admin monitoring and reporting Organizations may need to update reporting, operational procedures, and investigation workflows that reference investigation names.

Change History

Show
August 6, 2026 at 10:30 PM Updated
Title
Previous
Microsoft Defender for Office 365: AIR Investigation Experience Improvements
New
(Updated) Microsoft Defender for Office 365: AIR Investigation Experience Improvements
Summary
Previous
Microsoft Defender for Office 365's AIR experience will add a manual refresh button, replacing auto-refresh, and simplify investigation names by removing email subjects and UPNs. These changes improve performance, reduce network activity, and support data minimization. No admin action is required, but SOC workflows and documentation should be updated.
New
Microsoft Defender for Office 365's AIR experience will add a manual refresh button, replacing auto-refresh, and simplify investigation names by removing email subjects and UPNs. These changes improve performance, reduce network activity, and support data minimization. No admin action is required, but workflow updates are recommended.
Last Updated Date
Previous
2026-07-17T21:38:24.920Z
New
2026-08-06T16:32:14.393Z
Tags
Previous
Feature update,User impact,Admin impact
New
Updated message,Feature update,User impact,Admin impact
Body Content
Previous
<p><b>[What and Why:]</b></p> <p>Microsoft is enhancing the <b>Automated Investigation and Response (AIR)</b> experience in <b>Microsoft Defender for Office 365</b> by introducing a manual refresh capability and simplifying investigation naming conventions. These changes improve portal performance, reduce unnecessary network activity, and support data minimization principles by removing email subjects and <b>User Principal Names (UPNs)</b> from investigation names.</p> <p><b>[Rollout Schedule:]</b></p> <ul> <li>General Availability (Worldwide): Beginning in <b>late July 2026</b> and expected to complete by <b>late August 2026</b></li> </ul> <p><b>[Impact on Your Organization:]</b></p> <p><b>Who is affected:</b></p> <ul> <li>Security Operations Center (SOC) analysts</li> <li>Security administrators</li> <li>Incident responders</li> <li>Organizations using <b>Microsoft Defender for Office 365 Plan 2 / E5</b> and AIR</li> </ul> <p><b>Platforms/Services:</b></p> <ul> <li>Microsoft Defender portal</li> <li>Microsoft Defender for Office 365</li> <li>Automated Investigation and Response (AIR)</li> </ul> <p><b>What will happen:</b></p> <ul> <li><b>Manual refresh replaces auto-refresh:</b> <ul> <li>The AIR Investigations page will no longer refresh automatically.</li> <li>A new <b>Refresh</b> button will be available on the Investigations page.</li> <li>Analysts must manually refresh the page to obtain the latest investigation status and details.</li> <li>This change is enabled by default as part of the service update.</li> <li>Improved page responsiveness and reduced background network calls are expected.</li> </ul> </li> <li><b>Simplified investigation names:</b> <ul> <li>Investigation names for Manual and User-Reported will no longer include email subject lines</li> <li>Generic investigation names will be displayed instead, such as: <ul> <li><b>Email investigation for 'Network message Id"</b></li> <li><b>User reported message as malicious "Network message Id"</b></li> </ul> </li> <li>Existing investigation history and results remain unchanged.</li> </ul> </li> <li><b>No changes to existing capabilities</b> <ul> <li>Investigation triggers remain unchanged.</li> <li>Detection logic remains unchanged.</li> <li>Automated remediation actions remain unchanged.</li> <li>Threat Explorer functionality remains unchanged.</li> <li>Email &amp; Collaboration reports remain unchanged.</li> <li>Historical investigation records remain available.</li> </ul> </li> </ul> <p><b>[Action Required/Recommendations:]</b></p> <p><b>No mandatory administrative configuration is required.</b></p> <p>Recommended actions:</p> <ul> <li>Review SOC workflows that rely on automatic refresh behavior.</li> <li>Inform security analysts that investigation status updates now require use of the new <b>Refresh</b> button.</li> <li>Review automation, runbooks, scripts, dashboards, or integrations that may parse investigation names.</li> <li>Update internal SOPs, analyst guides, and training materials that reference investigation names containing email subjects.</li> <li>Communicate the naming convention change to help desk and security teams prior to rollout.</li> <li>Validate any custom reporting processes that may depend on previous investigation naming formats.</li> </ul> <p><b>Learn more:</b> <a href="https://learn.microsoft.com/defender-office-365/air-view-investigation-results#view-investigation-details-from-air-in-defender-for-office-365-plan-2" target="_blank">Details and results of AIR in Defender for Office 365 Plan 2 - Microsoft Defender for Office 365 | Microsoft Learn</a> (will be updated before rollout)</p> <p><b>[Compliance Considerations:]</b></p> <table> <tbody><tr> <td><b>Area</b></td> <td><b>Explanation</b></td> </tr> <tr> <td>Existing customer data processing/access</td> <td>Investigation names will no longer expose email subjects, supporting data minimization and changing how investigation-related data is presented to administrators.</td> </tr> <tr> <td>Admin monitoring and reporting</td> <td>Organizations may need to update reporting, operational procedures, and investigation workflows that reference investigation names.</td> </tr> </tbody></table>
New
<p>Updated August 6, 2026: We have updated the timeline. Thank you for your patience.&nbsp;</p><p><b>[What and Why:]</b></p> <p>Microsoft is enhancing the <b>Automated Investigation and Response (AIR)</b> experience in <b>Microsoft Defender for Office 365</b> by introducing a manual refresh capability and simplifying investigation naming conventions. These changes improve portal performance, reduce unnecessary network activity, and support data minimization principles by removing email subjects and <b>User Principal Names (UPNs)</b> from investigation names.</p> <p><b>[Rollout Schedule:]</b></p> <ul> <li>General Availability (Worldwide): Beginning in <b>mid-August 2026</b> (previously&nbsp;late July)&nbsp;and expected to complete by <b>late August 2026</b></li> </ul> <p><b>[Impact on Your Organization:]</b></p> <p><b>Who is affected:</b></p> <ul> <li>Security Operations Center (SOC) analysts</li> <li>Security administrators</li> <li>Incident responders</li> <li>Organizations using <b>Microsoft Defender for Office 365 Plan 2 / E5</b> and AIR</li> </ul> <p><b>Platforms/Services:</b></p> <ul> <li>Microsoft Defender portal</li> <li>Microsoft Defender for Office 365</li> <li>Automated Investigation and Response (AIR)</li> </ul> <p><b>What will happen:</b></p> <ul> <li><b>Manual refresh replaces auto-refresh:</b> <ul> <li>The AIR Investigations page will no longer refresh automatically.</li> <li>A new <b>Refresh</b> button will be available on the Investigations page.</li> <li>Analysts must manually refresh the page to obtain the latest investigation status and details.</li> <li>This change is enabled by default as part of the service update.</li> <li>Improved page responsiveness and reduced background network calls are expected.</li> </ul> </li> <li><b>Simplified investigation names:</b> <ul> <li>Investigation names for Manual and User-Reported will no longer include email subject lines</li> <li>Generic investigation names will be displayed instead, such as: <ul> <li><b>Email investigation for 'Network message Id"</b></li> <li><b>User reported message as malicious "Network message Id"</b></li> </ul> </li> <li>Existing investigation history and results remain unchanged.</li> </ul> </li> <li><b>No changes to existing capabilities</b> <ul> <li>Investigation triggers remain unchanged.</li> <li>Detection logic remains unchanged.</li> <li>Automated remediation actions remain unchanged.</li> <li>Threat Explorer functionality remains unchanged.</li> <li>Email &amp; Collaboration reports remain unchanged.</li> <li>Historical investigation records remain available.</li> </ul> </li> </ul> <p><b>[Action Required/Recommendations:]</b></p> <p><b>No mandatory administrative configuration is required.</b></p> <p>Recommended actions:</p> <ul> <li>Review SOC workflows that rely on automatic refresh behavior.</li> <li>Inform security analysts that investigation status updates now require use of the new <b>Refresh</b> button.</li> <li>Review automation, runbooks, scripts, dashboards, or integrations that may parse investigation names.</li> <li>Update internal SOPs, analyst guides, and training materials that reference investigation names containing email subjects.</li> <li>Communicate the naming convention change to help desk and security teams prior to rollout.</li> <li>Validate any custom reporting processes that may depend on previous investigation naming formats.</li> </ul> <p><b>Learn more:</b> <a href="https://learn.microsoft.com/defender-office-365/air-view-investigation-results#view-investigation-details-from-air-in-defender-for-office-365-plan-2" target="_blank">Details and results of AIR in Defender for Office 365 Plan 2 - Microsoft Defender for Office 365 | Microsoft Learn</a> (will be updated before rollout)</p> <p><b>[Compliance Considerations:]</b></p> <table> <tbody><tr> <td><b>Area</b></td> <td><b>Explanation</b></td> </tr> <tr> <td>Existing customer data processing/access</td> <td>Investigation names will no longer expose email subjects, supporting data minimization and changing how investigation-related data is presented to administrators.</td> </tr> <tr> <td>Admin monitoring and reporting</td> <td>Organizations may need to update reporting, operational procedures, and investigation workflows that reference investigation names.</td> </tr> </tbody></table>

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.