{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/",
        "slug": "dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/"
        },
        "title": "Verify AIR action outcomes even when an investigation says Remediated",
        "summary": "Does a Remediated investigation status prove that every Office 365 response action succeeded?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:24+00:00",
        "modified_at": "2026-09-10T02:11:18+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 264,
        "potentially_affected": "Automated investigation and response in Microsoft Defender for Office 365 Plan 2.",
        "dse_recommendation": "Close the response record from action-level outcomes, not the investigation status label alone.",
        "primary_source": {
            "name": "Details and results of AIR in Defender for Office 365 Plan 2 - Microsoft Defender for Office 365 | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-office-365/air-view-investigation-results",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>In Defender for Office 365 Plan 2 AIR, the Remediated investigation label can remain even when approved actions encounter execution errors. Microsoft also says approving or rejecting all pending actions closes the investigation with that label. Conversely, an investigation marked Failed may still have successful previously approved actions. The investigation&#8217;s Log tab lists actions and their status; its action-history view provides execution details. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/air-view-investigation-results\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this distinction when reconciling an automated email-security investigation with the work actually completed. Confirm access to the relevant investigation and the permissions required for any response decision. Keep analysis state, approval or rejection, and execution outcome as separate entries in the review.</p>\n<h2>DSE recommendation</h2>\n<p>Close the response record from action-level outcomes, not the investigation status label alone. Have the responder inspect each proposed action and document why it was approved or rejected. For an execution error, identify the affected entity and remaining remediation requirement before authorizing another action. Do not repeat every approved operation merely because the overall investigation failed, or assume an explicit rejection removed the threat.</p>\n<h2>Verification</h2>\n<p>Compare the investigation&#8217;s Log and action-history details with the intended response. Check execution status, timing and affected entities, then validate remaining exposure through the authorized investigation tools. Record unresolved errors and rejected actions with their owners. Preserve enough sanitized evidence to explain why the overall investigation label and the response outcome differ. Reopen operational follow-up when an action remains unverified even if the investigation itself is already closed.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-office-365/air-view-investigation-results\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Details and results of automated investigation and response in Defender for Office 365 Plan 2</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nIn Defender for Office 365 Plan 2 AIR, the Remediated investigation label can remain even when approved actions encounter execution errors. Microsoft also says approving or rejecting all pending actions closes the investigation with that label. Conversely, an investigation marked Failed may still have successful previously approved actions. The investigation’s Log tab lists actions and their status; its action-history view provides execution details. Microsoft Learn.\nApplicability\nUse this distinction when reconciling an automated email-security investigation with the work actually completed. Confirm access to the relevant investigation and the permissions required for any response decision. Keep analysis state, approval or rejection, and execution outcome as separate entries in the review.\nDSE recommendation\nClose the response record from action-level outcomes, not the investigation status label alone. Have the responder inspect each proposed action and document why it was approved or rejected. For an execution error, identify the affected entity and remaining remediation requirement before authorizing another action. Do not repeat every approved operation merely because the overall investigation failed, or assume an explicit rejection removed the threat.\nVerification\nCompare the investigation’s Log and action-history details with the intended response. Check execution status, timing and affected entities, then validate remaining exposure through the authorized investigation tools. Record unresolved errors and rejected actions with their owners. Preserve enough sanitized evidence to explain why the overall investigation label and the response outcome differ. Reopen operational follow-up when an action remains unverified even if the investigation itself is already closed.\nOfficial references\nMicrosoft Learn: Details and results of automated investigation and response in Defender for Office 365 Plan 2. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nIn Defender for Office 365 Plan 2 AIR, the Remediated investigation label can remain even when approved actions encounter execution errors. Microsoft also says approving or rejecting all pending actions closes the investigation with that label. Conversely, an investigation marked Failed may still have successful previously approved actions. The investigation’s Log tab lists actions and their status; its action-history view provides execution details. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/air-view-investigation-results).\n\n## Applicability\n\nUse this distinction when reconciling an automated email-security investigation with the work actually completed. Confirm access to the relevant investigation and the permissions required for any response decision. Keep analysis state, approval or rejection, and execution outcome as separate entries in the review.\n\n## DSE recommendation\n\nClose the response record from action-level outcomes, not the investigation status label alone. Have the responder inspect each proposed action and document why it was approved or rejected. For an execution error, identify the affected entity and remaining remediation requirement before authorizing another action. Do not repeat every approved operation merely because the overall investigation failed, or assume an explicit rejection removed the threat.\n\n## Verification\n\nCompare the investigation’s Log and action-history details with the intended response. Check execution status, timing and affected entities, then validate remaining exposure through the authorized investigation tools. Record unresolved errors and rejected actions with their owners. Preserve enough sanitized evidence to explain why the overall investigation label and the response outcome differ. Reopen operational follow-up when an action remains unverified even if the investigation itself is already closed.\n\n## Official references\n\n[Microsoft Learn: Details and results of automated investigation and response in Defender for Office 365 Plan 2](https://learn.microsoft.com/en-us/defender-office-365/air-view-investigation-results). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Verify AIR action outcomes even when an investigation says Remediated",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/",
                "headline": "Verify AIR action outcomes even when an investigation says Remediated",
                "description": "Does a Remediated investigation status prove that every Office 365 response action succeeded?",
                "abstract": "Does a Remediated investigation status prove that every Office 365 response action succeeded?",
                "articleBody": "Source facts\nIn Defender for Office 365 Plan 2 AIR, the Remediated investigation label can remain even when approved actions encounter execution errors. Microsoft also says approving or rejecting all pending actions closes the investigation with that label. Conversely, an investigation marked Failed may still have successful previously approved actions. The investigation’s Log tab lists actions and their status; its action-history view provides execution details. Microsoft Learn.\nApplicability\nUse this distinction when reconciling an automated email-security investigation with the work actually completed. Confirm access to the relevant investigation and the permissions required for any response decision. Keep analysis state, approval or rejection, and execution outcome as separate entries in the review.\nDSE recommendation\nClose the response record from action-level outcomes, not the investigation status label alone. Have the responder inspect each proposed action and document why it was approved or rejected. For an execution error, identify the affected entity and remaining remediation requirement before authorizing another action. Do not repeat every approved operation merely because the overall investigation failed, or assume an explicit rejection removed the threat.\nVerification\nCompare the investigation’s Log and action-history details with the intended response. Check execution status, timing and affected entities, then validate remaining exposure through the authorized investigation tools. Record unresolved errors and rejected actions with their owners. Preserve enough sanitized evidence to explain why the overall investigation label and the response outcome differ. Reopen operational follow-up when an action remains unverified even if the investigation itself is already closed.\nOfficial references\nMicrosoft Learn: Details and results of automated investigation and response in Defender for Office 365 Plan 2. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:23:24+00:00",
                "dateModified": "2026-09-10T02:11:18+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Verify AIR action outcomes even when an investigation says Remediated"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 264,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Details and results of AIR in Defender for Office 365 Plan 2 - Microsoft Defender for Office 365 | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-office-365/air-view-investigation-results"
                }
            }
        ]
    }
}