Microsoft Defender for Office 365: View approver details for remediation actions in Advanced Hunting

🚨 The Signal: Microsoft Defender XDR Advanced Hunting now includes the approver's UPN for email remediation actions in the EmailPostDeliveryEvents table. This improves incident response efficiency by allowing security analysts to quickly identify who approved a remediation without leaving hunting queries.

The Impact

Security analysts are affected, gaining improved visibility into remediation approvals, which enhances incident response and audit trails.

  • Security analysts: Faster investigation of email remediation actions.
  • Security operations: Improved auditability of who approved security actions.
  • Incident responders: Streamlined workflow for post-delivery email analysis.

The Action

  1. Review existing KQL queries in Microsoft Defender XDR Advanced Hunting that investigate email remediation actions.
  2. Update or create new KQL queries to incorporate the 'ApproverUpn' column for enhanced visibility.
  3. Communicate the availability of the 'ApproverUpn' column to security analysts and incident response teams.

Domain: Defender · Impact: medium · Workload: Microsoft Defender