Microsoft Defender for O365 now allows triggering new remediation actions—Submit to Microsoft, add to allow/block list, and initiate automated investigation—directly from the Advanced Hunting interface. This feature, rolled out since November 10, 2025, is enabled by default and supports improved threat response without policy changes.
This update introduces new remediation actions in Microsoft Defender for O365 that can be triggered directly from the Advanced Hunting interface. These actions—previously only available in Threat Explorer—include “Submit to Microsoft” and “Initiate automated investigation.” This enhancement enables security teams to respond to threats more efficiently and programmatically using custom queries, aligning with customer feedback to streamline incident response workflows.
When this will happen:General Availability (Worldwide): We began rolling out this feature on November 10, 2025.
How this affects your organization:Who is affected:
What will happen:
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.