Module 5: Threat Explorer, Alerts & Incident Investigation

🎯 Security Course · Module 5 of 6

Threat Explorer, Alerts & Incident Investigation

SC-200
SC-200 Exam Alignment
SC-200

Investigate and respond to threats using Microsoft 365 Defender: Use Threat Explorer to trace email threats, identify affected users, and take bulk remediation actions. Manage alert policies and triage the unified incident queue.

  • Threat Explorer is available with Defender for Office 365 Plan 2 — shows up to 30 days of email threat data with full investigation capabilities
  • Real-time Detections is the Plan 1 equivalent — shows near-real-time data but has fewer pivot/investigation options and no remediation actions
  • The Email entity page is the single-message deep-dive: shows delivery action, detection technology, URL clicks, attachment verdicts, and all related alerts in one place
  • Microsoft 365 Defender correlates alerts from all Defender products into Incidents — an incident groups all related alerts and evidence for a single attack story
Exam Tip: In SC-200, Threat Explorer questions test your ability to find specific messages and understand what the data shows. Know the key columns: Delivery action (Delivered, Junk, Quarantined, Blocked), Delivery location (Inbox, Junk folder, Quarantine, Dropped), and Detection technology (what caught the threat). Also know that “Delivered” + “Inbox” means the message reached the user and you need to investigate further.
Threat Explorer is the analyst’s primary tool for investigating email threats in Microsoft 365. It provides a pivotable, searchable view of all email data — letting you trace a single phishing email across all recipients, identify users who clicked malicious links, take bulk remediation actions, and correlate email threats with identity and device signals in the Defender incident queue.

🔬 Threat Explorer vs Real-time Detections

Feature Threat Explorer (MDO P2) Real-time Detections (MDO P1)
Data retention Up to 30 days of email data Near real-time, shorter historical window
Investigation pivots Full pivot capabilities — sender, recipient, URL, file, IP, campaign Limited pivot options
Remediation actions Yes — soft delete, hard delete, move to junk, move to inbox No bulk remediation from the UI
Campaign view Full campaign intelligence — group related phishing messages Not available
Email entity page Full entity page with all detection details Limited view
Advanced Hunting KQL queries across email, identity, device, and cloud app data Not available

🔍 Threat Explorer — Email Investigation Workflow

Step 1 — Scope the Campaign

Navigate to Email & collaboration → Explorer. Select view: All email or Phish. Filter by date range, and optionally by subject, sender domain, or URL domain.

Step 2 — Identify Affected Recipients

Group the results by Recipient to see which users received the message. Note the Delivery action column — look for messages with “Delivered” + “Inbox” as these users actively received the threat.

Step 3 — Investigate Individual Messages

Click a specific message to open the Email entity page.

Email Entity Page Section What It Shows
Summary Sender, recipient, subject, received time, message ID, delivery action and location
Detection details Which detection technology caught the message; verdict confidence
URLs Every URL in the message — reputation verdict, click data (who clicked and when), whether Safe Links blocked the click
Attachments Every attachment — Safe Attachments detonation verdict, file hash, malware family if detected
Related alerts Any Defender alerts triggered by this message or its contents

Step 4 — Take Remediation Action

Action Effect When to Use
Soft delete Moves messages to the Recoverable Items folder — removed from Inbox but recoverable by admin Default for most phishing remediations — reversible
Hard delete Permanently deletes the message — not recoverable Confirmed malware or highly sensitive BEC; irreversible
Move to junk Moves to the user’s Junk Email folder Low-severity spam
Move to inbox Restores a message from Junk to Inbox Releasing false positive messages

🚨 Alert Policies

Category Example Built-in Alerts Severity
Email & collaboration User restricted from sending email, Malware campaign detected, Suspicious email forwarding activity High / Medium
Threat management Phishing email campaign detected, Malware detected in email High
Data loss prevention DLP policy matched, Sensitive data shared externally Medium / Low
Custom Any admin-defined condition Admin-defined

📋 Incident Queue & Triage

The Microsoft 365 Defender incident queue (Incidents & alerts → Incidents) shows correlated multi-product incidents. Each incident groups related alerts into a single attack story with a unified timeline, entity list, and evidence graph.

  • 1️⃣ Assign the incident to a specific analyst — sets ownership and prevents duplicate work
  • 2️⃣ Review the incident summary — understand the attack story, affected entities (users, devices, mailboxes), and alert count
  • 3️⃣ Investigate the attack graph (Evidence & response tab) — visual graph showing all entities and their relationships
  • 4️⃣ Take remediation actions — isolate devices, disable users, delete emails, add IoCs
  • 5️⃣ Close and classify the incident — True positive (malicious, benign), False positive, or Informational
PowerShell — Threat Explorer Email Investigation via Graph

💡 Best Practices

  • In Threat Explorer, always filter by “Delivery action: Delivered” AND “Delivery location: Inbox” to identify users who actually received the threat
  • Use the Email entity page → URLs tab to identify whether any users clicked a malicious link — this determines the scope of potential compromise
  • Set the incident queue filter to Severity: High during your morning review — these require investigation within 1 hour
  • When closing an incident, always add a classification reason and comment — this data feeds Microsoft’s learning systems
  • Use Threat Analytics reports (Threat intelligence → Threat analytics) to understand active campaigns targeting your industry

🎓 Interview Q&A

Q: A user reports receiving a suspicious email and clicking a link. Using Threat Explorer, how would you determine the scope of the incident and what remediation steps would you take?
Investigation workflow:

1. Open Threat Explorer → All email or Phish view. Search by the reported sender, subject, or time window.
2. Filter by Delivery action: Delivered to find all users who received the message in their Inbox.
3. Click the specific message and open the Email entity page → URLs tab to see URL click data — which users clicked, when, and whether Safe Links blocked them.
4. For any users who clicked and were NOT blocked: pivot to their identity risk in Entra ID and check their devices for malware alerts in Defender for Endpoint.
5. Take a Soft delete action on all copies of the phishing message across all recipients.
6. If any users visited the malicious URL, escalate: force password reset, revoke active sessions, and isolate any devices showing suspicious activity.

🎯 SC-200 Mock Test
Module 5 — Threat Explorer & Incidents
5 questions · Scenario-based · Pass mark: 70%

Q1 of 5

A security analyst needs to take bulk remediation actions (soft delete) directly from the Threat Explorer interface after identifying phishing emails. Which Defender for Office 365 licence is required?

AExchange Online Protection (EOP) — bulk remediation is a base EOP feature
BDefender for Office 365 Plan 2 — Threat Explorer with full remediation capabilities requires Plan 2
CDefender for Office 365 Plan 1 — Real-time Detections includes bulk remediation
DMicrosoft 365 E3 — remediation actions are included in E3 security features

B. Bulk remediation actions from Threat Explorer require Defender for Office 365 Plan 2. Plan 1 provides “Real-time Detections” which shows threat data but does NOT provide bulk remediation actions from the UI.

Q2 of 5

In Threat Explorer, a phishing email shows Delivery action: “Delivered” and Delivery location: “Inbox.” What does this mean?

AThe message was caught by Safe Attachments and is safe to ignore
BThe message passed all filters and is currently in the user’s Junk folder
CThe message was quarantined before reaching the user
DThe phishing message bypassed all filters and landed in the user’s Inbox — the user was fully exposed; immediate remediation required

D. “Delivered” + “Inbox” means the message passed all EOP and MDO filtering layers and landed directly in the user’s main Inbox — the highest-risk outcome. The user saw the message and could have clicked links or opened attachments. This requires immediate remediation.

Q3 of 5

What is the Email entity page in Threat Explorer primarily used for?

ADeep investigation of a single email message — delivery history, URL verdicts, attachment detonation results, who clicked links, and related alerts
BManaging a user’s mailbox settings and applying send/receive restrictions
CConfiguring email authentication (SPF, DKIM, DMARC) for a specific domain
DCreating custom anti-spam policy rules based on the message properties

A. The Email entity page is a single-message deep-dive view showing everything about one specific email: full headers, delivery action and location, detection technology, every URL with click tracking, every attachment with detonation verdicts, and related Defender alerts.

Q4 of 5

A compromised account sent 500 phishing emails to external recipients. An automated alert triggers: “User restricted from sending email.” What caused this and what should you do first?

AThe user’s mailbox exceeded storage quota — increase the mailbox quota
BThe user violated a DLP policy — review the DLP incident report
CThe outbound spam policy detected bulk sending and restricted the account — investigate for compromise, reset credentials, and revoke active sessions
DA mail flow rule blocked the user — review and update transport rules

C. The “User restricted from sending email” alert is triggered when EOP’s outbound spam protection detects a user sending at a rate exceeding limits — a strong indicator of account compromise. Immediate actions: 1) Reset password; 2) Revoke sessions (Revoke-MgUserSignInSession); 3) Review sent items for suspicious forwarding rules; 4) Check Entra ID sign-in logs; 5) Remove the sending restriction via the Restricted users page once secured.

Q5 of 5

What is the difference between “soft delete” and “hard delete” in Threat Explorer?

ASoft delete removes from Inbox only; hard delete removes from Junk folder too
BSoft delete moves to Recoverable Items (admin recoverable within retention period); hard delete permanently removes it
CSoft delete notifies the user before deleting; hard delete is silent
DSoft delete is for internal messages; hard delete is for external messages

B. Soft delete moves the message to Recoverable Items — disappears from user view but can still be recovered by an admin during the retention period. Hard delete permanently purges the message — bypasses Recoverable Items and cannot be recovered unless there’s a litigation hold. Use hard delete only for confirmed malware or highly sensitive BEC cases.



🔒

Locked — Complete Module 4 first to unlock this module.