This repository was archived by the owner on Sep 8, 2026. It is now read-only.
Update air-about.md automatic remediation - #397
Merged
Chris Davis (chrisda) merged 4 commits intoFeb 23, 2026
Conversation
Old version indicated that Tip"No remediation actions happen automatically. Remediation actions require manual approval by SecOps personnel. " however as per our road map 502528 "We are expanding the auto-remediation capabilities in Automated Investigations and Response (AIR) to fully automate the remediation of malicious similarity clusters. Earlier this year, we introduced auto-remediation for malicious URL and file clusters. Building on that foundation, this enhancement enables AIR to automatically approve all pending remediation actions it generates—eliminating the need for manual intervention and streamlining the response process for SOC teams." So the tip should be changed
Contributor
|
Learn Build status updates of commit 6e7aaa2: ✅ Validation status: passed
For more details, please refer to the build report. |
Tami Fosmark (tfosmark)
requested review from
a team,
AbbyMSFT,
Devorah Cohen (DeCohen),
Deborah Langer (DebLanger),
Ed Baynash (EdB-MSFT),
Elazar Krieger (ElazarK),
Batami Gold (batamig),
Chris Davis (chrisda),
Guy Wild (guywi-ms),
Janet Jose (janetjo2510),
Limor Wainstein (limwainstein),
Mona Berdugo (mberdugo),
joey caparas (mjcaparas),
orspod,
Paul Inbar (paulinbar),
Paul Oliveria (poliveria),
Sarabeth Reingold (sbreingold-ms) and
Sophia Nikolayev (snicklezzz)
as code owners
February 13, 2026 00:18
Contributor
|
ahmedfarag2026 : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change. |
Contributor
|
Learn Build status updates of commit 68dd3de: ✅ Validation status: passed
For more details, please refer to the build report. |
Chris Davis (chrisda)
approved these changes
Feb 23, 2026
Contributor
|
Learn Build status updates of commit 85ce0fd: ✅ Validation status: passed
For more details, please refer to the build report. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Old version indicated that Tip"No remediation actions happen automatically. Remediation actions require manual approval by SecOps personnel. " however as per our road map 502528 "We are expanding the auto-remediation capabilities in Automated Investigations and Response (AIR) to fully automate the remediation of malicious similarity clusters. Earlier this year, we introduced auto-remediation for malicious URL and file clusters. Building on that foundation, this enhancement enables AIR to automatically approve all pending remediation actions it generates—eliminating the need for manual intervention and streamlining the response process for SOC teams." So the tip should be changed