12.3 Investigating & Responding to Email Threats

Key Takeaways

  • Threat Explorer (Plan 2) and Real-time detections (Plan 1) are the primary investigation surfaces for email threats, with views for Malware, Phish, and Spam and a delivery-action model of Delivered, Junked, Blocked, or Replaced
  • The Email entity page consolidates metadata, URLs, attachments, authentication results (SPF/DKIM/DMARC), and the per-message timeline in one place for a single message
  • Manual remediation in Explorer supports soft delete (move to the Deleted Items folder) and hard delete (permanently remove) for up to 30 days after delivery, launched from the remediation wizard
  • AIR playbooks hunt for related emails, URLs, and mailbox configurations and queue proposed actions in the Action center, where admins approve, reject, or wait for auto-approval in full-automation tenants
  • Campaign Views (Plan 2) group related messages across the tenant into a campaign with a timeline, attack payload, and recipient list, enabling tenant-wide hunting for a single campaign
Last updated: August 2026

Quick Answer: Investigate email threats in Threat Explorer (Plan 2) or Real-time detections (Plan 1) in the Defender portal under Email & collaboration → Explorer. Filter by Malware, Phish, or Spam view, pivot on sender, recipient, subject, URL, or attachment, and read the delivery action (Delivered, Junked, Blocked, Replaced) and delivery location to understand what happened to each message. Respond with manual soft/hard delete, Tenant Allow/Block List blocking, or by triggering an AIR investigation that proposes related actions in the Action center.

Threat Explorer and Real-time Detections

Threat Explorer (Plan 2) is the interactive hunting surface for email. Real-time detections is the Plan 1 equivalent with a shorter lookback and fewer pivots. Both open to a default view of the last 30 days (Explorer) or 24 hours (Real-time detections) of mail that passed through the tenant. The top-level view selector lets you switch between Malware, Phish, and Spam; within each view you can further restrict to All email to see clean mail in the same pivot for comparison.

Delivery Action and Delivery Location

Every message in Explorer is described by two fields:

  • Delivery action — what the filtering stack did: Delivered (in the inbox or a folder), Junked (sent to Junk), Blocked (filtered out before delivery), Replaced (malicious content removed and the message delivered with a warning), or Quarantined.
  • Delivery location — where the message ended up: Inbox/Junk, Quarantine, Failed, Dropped, or, for messages later removed by ZAP or a remediation action, Deleted folder or Hard delete.

Reading these two fields together tells the attack story. A message that shows Delivered → Inbox at 09:00 and Hard delete at 09:30 was ZAP'd or manually purged after delivery — the recipient saw it for 30 minutes.

Pivoting and the Email Entity Page

Explorer lets you pivot on sender, sender domain, recipient, subject, attachment SHA256, URL domain, and URL (click the columns to add or remove). Clicking any row opens the Email entity page, a single-message view that consolidates:

  • Message metadata (sender, recipients, subject, timestamp, SCL/BCL, network message ID)
  • URLs found in the message with their click count and verdict
  • Attachments with SHA256 and file verdict
  • Authentication results — SPF, DKIM, DMARC, and the composite authentication result used by spoof intelligence
  • Detection details — which policy caught the message and what verdict
  • The timeline — every event in the message's life, from receipt through filtering, delivery, any ZAP, and any remediation action

The timeline is the fastest way to explain to a stakeholder why a phishing message reached an executive's inbox and what happened next.

Threat Trackers and Campaign Views (Plan 2)

Threat Trackers are curated lists of notable threats — Noteworthy trackers highlight active campaigns Microsoft is tracking globally, while Trending trackers show the week's top threats. Campaign Views go further: they group related messages across your tenant into a single campaign, show the campaign timeline, the attack payload (URL, attachment, or sender), the list of affected recipients, and the delivery action breakdown. From a Campaign View you can pivot directly into Explorer scoped to that campaign or trigger a tenant-wide remediation.

Responding: Manual Remediation

When an analyst confirms a message is malicious, Defender for Office 365 offers manual remediation actions:

  • Soft delete — moves the message from every recipient's mailbox to the Deleted Items folder, where it is recoverable for the folder's retention period.
  • Hard delete — permanently removes the message from the mailbox; the message is unrecoverable.
  • Block sender / domain / URL / file — adds an entry to the Tenant Allow/Block List so future messages from that indicator are filtered before delivery.
  • Trigger automated investigation — hands the indicator to AIR, which expands the hunt to related messages, URLs, and mailbox configuration (for example, inbox rules the attacker created).

Manual remediation is launched from the remediation wizard in Explorer (select messages → Actions → remediate). The wizard asks for the action, the remediation name, and an optional comment; the resulting job is tracked in the Action center. Soft and hard delete are available for up to 30 days after delivery; messages older than that can only be investigated, not purged.

Responding: AIR and the Action Center

When an AIR playbook runs — either auto-triggered by a high-confidence detection or manually triggered from Explorer — it performs a graph-style hunt for related entities, writes a report to the investigation page, and queues proposed actions in the Action center. The Action center has two tabs: Pending (actions awaiting admin approval, shown when the tenant is in semi-automatic approval mode) and History (completed actions, both approved and auto-approved). Each pending action can be approved, rejected, or opened for review. In full automation mode, AIR auto-approves remediation of verbatim-known-bad entities (for example, a URL already on a Microsoft block list) and still leaves analyst-reviewable evidence in the History tab.

Hunting a Campaign Across the Tenant

A complete tenant-wide hunt for a campaign combines all three tools: start from a Campaign View (or a Threat Tracker) to see the campaign's scope and payload; pivot into Explorer scoped to the campaign to inspect delivery actions and the Email entity timeline for a representative message; then either trigger an AIR investigation to find every related message automatically or run a manual advanced hunting (KQL) query to enumerate every recipient and confirm the remediation count. Finish by confirming the soft/hard delete job in the Action center and adding any new attacker indicators to the Tenant Allow/Block List so the campaign cannot recur.

Investigating Collaborations Threats

The same Explorer and Email entity tooling covers Microsoft Teams and SharePoint/OneDrive collaboration threats: Safe Links for Teams scans URLs in chats and channels, Safe Attachments for SharePoint/OneDrive detonates files stored in document libraries, and the Defender portal surfaces these detections in the same Email & collaboration area. The investigation workflow — delivery action, entity page, remediation, AIR — is identical across email and collaboration surfaces, which is why MS-102 treats them under one skill.

Test Your Knowledge

In Threat Explorer, a message shows a delivery action of Delivered and a delivery location of Inbox at 09:00, then later shows Hard delete at 09:30. What is the most likely explanation?

A
B
C
D
Test Your Knowledge

A Plan 2 tenant analyst wants to hunt every message in a single phishing campaign across the organization, see the attack payload and the full recipient list, and trigger remediation. Which tool is purpose-built for this?

A
B
C
D
Test Your Knowledge

Where does an admin approve or reject remediation actions that a Defender for Office 365 AIR playbook has proposed but not auto-approved?

A
B
C
D