# Verify AIR action outcomes even when an investigation says Remediated

> Does a Remediated investigation status prove that every Office 365 response action succeeded?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:24+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does a Remediated investigation status prove that every Office 365 response action succeeded?

## Potentially affected

Automated investigation and response in Microsoft Defender for Office 365 Plan 2.

## DSE recommendation

Close the response record from action-level outcomes, not the investigation status label alone.

## Article

## Source facts

In Defender for Office 365 Plan 2 AIR, the Remediated investigation label can remain even when approved actions encounter execution errors. Microsoft also says approving or rejecting all pending actions closes the investigation with that label. Conversely, an investigation marked Failed may still have successful previously approved actions. The investigation’s Log tab lists actions and their status; its action-history view provides execution details. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/air-view-investigation-results).

## Applicability

Use this distinction when reconciling an automated email-security investigation with the work actually completed. Confirm access to the relevant investigation and the permissions required for any response decision. Keep analysis state, approval or rejection, and execution outcome as separate entries in the review.

## DSE recommendation

Close the response record from action-level outcomes, not the investigation status label alone. Have the responder inspect each proposed action and document why it was approved or rejected. For an execution error, identify the affected entity and remaining remediation requirement before authorizing another action. Do not repeat every approved operation merely because the overall investigation failed, or assume an explicit rejection removed the threat.

## Verification

Compare the investigation’s Log and action-history details with the intended response. Check execution status, timing and affected entities, then validate remaining exposure through the authorized investigation tools. Record unresolved errors and rejected actions with their owners. Preserve enough sanitized evidence to explain why the overall investigation label and the response outcome differ. Reopen operational follow-up when an action remains unverified even if the investigation itself is already closed.

## Official references

[Microsoft Learn: Details and results of automated investigation and response in Defender for Office 365 Plan 2](https://learn.microsoft.com/en-us/defender-office-365/air-view-investigation-results). Source reviewed September 9, 2026.

## Primary reference

- Name: Details and results of AIR in Defender for Office 365 Plan 2 - Microsoft Defender for Office 365 | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-office-365/air-view-investigation-results
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Verify AIR action outcomes even when an investigation says Remediated,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-512-verify-air-action-outcomes-even-when-an-investigation-says-remediated/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
