Automated Investigation and Response
Automated investigation and response examines alerts, collects evidence, and can take remediation actions to reduce security operations workload.
capabilitiesCurrent
Relationships
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Gap | No product-specific PowerShell automation surface is recorded for this capability yet. |
| REST API | Supported | Reference |
| Graph | Supported | Reference |
| ARM | Gap | No ARM resource is recorded for this capability. |
| Bicep | Gap | No Bicep resource is recorded for this capability. |
| Terraform | Gap | Automation level and investigation settings are tenant/device-group configuration exposed only via the Defender for Endpoint API and Graph Security API, not ARM/Terraform. Automate with a script step inside the same pipeline that runs Terraform, not Terraform itself. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |