Skip to content

Latest commit

 

History

History
72 lines (55 loc) · 5.16 KB

File metadata and controls

72 lines (55 loc) · 5.16 KB
title Report false positives or false negatives following automated investigation and response
description Was something missed or wrongly detected by AIR in Microsoft Defender for Office 365 Plan 2? Learn how to submit false positives or false negatives to Microsoft for analysis.
search.appverid met150
f1.keywords
NOCSH
author chrisda
ms.author chrisda
manager bagol
ms.service defender-office-365
ms.date 07/10/2024
ms.localizationpriority medium
audience ITPro
ms.collection
m365-security
tier2
ms.topic how-to
ms.custom
autoir
appliesto
✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 2</a>
✅ <a href="https://learn.microsoft.com/defender-xdr/microsoft-365-defender" target="_blank">Microsoft Defender XDR</a>

Report false positives or false negatives in automated investigation and response (AIR)

[!INCLUDE MDO Trial banner]

Automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2 includes powerful capabilities to detect and investigate threats. For more information, see Automated investigation and response.

But what if AIR incorrectly identifies something as a threat (a false positive) or missed something that turned out to be a threat (a false negative)? This article explains the options that are available to security operations (SecOps) personnel to deal with false positives and false negatives from AIR.

Submit false positives or false negatives to Microsoft

To submit or resubmit false positive and false negative email messages, email attachments, and URLs to Microsoft, see Use the Submissions page to submit suspected spam, phish, URLs, legitimate email getting blocked, and email attachments to Microsoft.

Adjust alerts to prevent false positives from recurring

For instructions, see the following articles, based on the available subscriptions in your organization:

  • Defender XDR: Tune an alert
  • Defender for Endpoint: Create Allow actions for files, IP addresses URLs or domains that are misidentified as malware on devices. For instructions, see Create indicators.

Undo remediation actions

Tip

For permission and licensing requirements, see Required permissions and licensing for AIR.

SecOps personnel can often use :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: Take action to undo the remediation action. For example:

For details about the available actions in :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: Take action, see the Take action wizard.

See also