capability

Automated Investigation and Response

Automated investigation and response examines alerts, collects evidence, and can take remediation actions to reduce security operations workload.

capabilitiesCurrent

Relationships

Configuration Methods

MethodSupportReference or Gap
PortalSupported Reference
PowerShellGapNo product-specific PowerShell automation surface is recorded for this capability yet.
REST APISupported Reference
GraphSupported Reference
ARMGapNo ARM resource is recorded for this capability.
BicepGapNo Bicep resource is recorded for this capability.
TerraformGapAutomation level and investigation settings are tenant/device-group configuration exposed only via the Defender for Endpoint API and Graph Security API, not ARM/Terraform. Automate with a script step inside the same pipeline that runs Terraform, not Terraform itself.
GitHub ActionsSupported Reference
Azure DevOpsSupported Reference