Threat Explorer, Alerts & Incident Investigation
SC-200 Exam Alignment
SC-200
Investigate and respond to threats using Microsoft 365 Defender: Use Threat Explorer to trace email threats, identify affected users, and take bulk remediation actions. Manage alert policies and triage the unified incident queue.
- Threat Explorer is available with Defender for Office 365 Plan 2 — shows up to 30 days of email threat data with full investigation capabilities
- Real-time Detections is the Plan 1 equivalent — shows near-real-time data but has fewer pivot/investigation options and no remediation actions
- The Email entity page is the single-message deep-dive: shows delivery action, detection technology, URL clicks, attachment verdicts, and all related alerts in one place
- Microsoft 365 Defender correlates alerts from all Defender products into Incidents — an incident groups all related alerts and evidence for a single attack story
🔬 Threat Explorer vs Real-time Detections
| Feature | Threat Explorer (MDO P2) | Real-time Detections (MDO P1) |
|---|---|---|
| Data retention | Up to 30 days of email data | Near real-time, shorter historical window |
| Investigation pivots | Full pivot capabilities — sender, recipient, URL, file, IP, campaign | Limited pivot options |
| Remediation actions | Yes — soft delete, hard delete, move to junk, move to inbox | No bulk remediation from the UI |
| Campaign view | Full campaign intelligence — group related phishing messages | Not available |
| Email entity page | Full entity page with all detection details | Limited view |
| Advanced Hunting | KQL queries across email, identity, device, and cloud app data | Not available |
🔍 Threat Explorer — Email Investigation Workflow
Step 1 — Scope the Campaign
Navigate to Email & collaboration → Explorer. Select view: All email or Phish. Filter by date range, and optionally by subject, sender domain, or URL domain.
Step 2 — Identify Affected Recipients
Group the results by Recipient to see which users received the message. Note the Delivery action column — look for messages with “Delivered” + “Inbox” as these users actively received the threat.
Step 3 — Investigate Individual Messages
Click a specific message to open the Email entity page.
| Email Entity Page Section | What It Shows |
|---|---|
| Summary | Sender, recipient, subject, received time, message ID, delivery action and location |
| Detection details | Which detection technology caught the message; verdict confidence |
| URLs | Every URL in the message — reputation verdict, click data (who clicked and when), whether Safe Links blocked the click |
| Attachments | Every attachment — Safe Attachments detonation verdict, file hash, malware family if detected |
| Related alerts | Any Defender alerts triggered by this message or its contents |
Step 4 — Take Remediation Action
| Action | Effect | When to Use |
|---|---|---|
| Soft delete | Moves messages to the Recoverable Items folder — removed from Inbox but recoverable by admin | Default for most phishing remediations — reversible |
| Hard delete | Permanently deletes the message — not recoverable | Confirmed malware or highly sensitive BEC; irreversible |
| Move to junk | Moves to the user’s Junk Email folder | Low-severity spam |
| Move to inbox | Restores a message from Junk to Inbox | Releasing false positive messages |
🚨 Alert Policies
| Category | Example Built-in Alerts | Severity |
|---|---|---|
| Email & collaboration | User restricted from sending email, Malware campaign detected, Suspicious email forwarding activity | High / Medium |
| Threat management | Phishing email campaign detected, Malware detected in email | High |
| Data loss prevention | DLP policy matched, Sensitive data shared externally | Medium / Low |
| Custom | Any admin-defined condition | Admin-defined |
📋 Incident Queue & Triage
The Microsoft 365 Defender incident queue (Incidents & alerts → Incidents) shows correlated multi-product incidents. Each incident groups related alerts into a single attack story with a unified timeline, entity list, and evidence graph.
- 1️⃣ Assign the incident to a specific analyst — sets ownership and prevents duplicate work
- 2️⃣ Review the incident summary — understand the attack story, affected entities (users, devices, mailboxes), and alert count
- 3️⃣ Investigate the attack graph (Evidence & response tab) — visual graph showing all entities and their relationships
- 4️⃣ Take remediation actions — isolate devices, disable users, delete emails, add IoCs
- 5️⃣ Close and classify the incident — True positive (malicious, benign), False positive, or Informational
💡 Best Practices
- In Threat Explorer, always filter by “Delivery action: Delivered” AND “Delivery location: Inbox” to identify users who actually received the threat
- Use the Email entity page → URLs tab to identify whether any users clicked a malicious link — this determines the scope of potential compromise
- Set the incident queue filter to Severity: High during your morning review — these require investigation within 1 hour
- When closing an incident, always add a classification reason and comment — this data feeds Microsoft’s learning systems
- Use Threat Analytics reports (Threat intelligence → Threat analytics) to understand active campaigns targeting your industry
🎓 Interview Q&A
1. Open Threat Explorer → All email or Phish view. Search by the reported sender, subject, or time window.
2. Filter by Delivery action: Delivered to find all users who received the message in their Inbox.
3. Click the specific message and open the Email entity page → URLs tab to see URL click data — which users clicked, when, and whether Safe Links blocked them.
4. For any users who clicked and were NOT blocked: pivot to their identity risk in Entra ID and check their devices for malware alerts in Defender for Endpoint.
5. Take a Soft delete action on all copies of the phishing message across all recipients.
6. If any users visited the malicious URL, escalate: force password reset, revoke active sessions, and isolate any devices showing suspicious activity.
A security analyst needs to take bulk remediation actions (soft delete) directly from the Threat Explorer interface after identifying phishing emails. Which Defender for Office 365 licence is required?
In Threat Explorer, a phishing email shows Delivery action: “Delivered” and Delivery location: “Inbox.” What does this mean?
What is the Email entity page in Threat Explorer primarily used for?
A compromised account sent 500 phishing emails to external recipients. An automated alert triggers: “User restricted from sending email.” What caused this and what should you do first?
What is the difference between “soft delete” and “hard delete” in Threat Explorer?