Microsoft Defender XDR: Automated Investigation and Response for Phishing and URL Threats
Microsoft Threat Protection has evolved into Microsoft Defender XDR. In 2026, security teams use the Microsoft Defender portal to correlate phishing reports, malicious URL clicks, endpoint signals, cloud app activity, and identity risk into unified incidents with automated investigation and response.
From Microsoft Threat Protection to Microsoft Defender XDR
The original Microsoft Threat Protection branding is retired. The current integrated security experience is Microsoft Defender XDR, which brings together Microsoft Defender for Office 365, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Entra ID signals in the Microsoft Defender portal at security.microsoft.com. Instead of reviewing isolated email, endpoint, and identity alerts one at a time, SecOps teams work from correlated incidents, alerts, evidence, automated investigations, hunting data, and recommended remediation actions.
User-reported phishing in the Microsoft Defender portal
User-reported messages remain one of the most important phishing signals. Employees can report suspicious email from Outlook by using the Microsoft Report Message or Report Phishing add-ins, and in many tenants through the built-in Report button. Those submissions can be reviewed by security teams in the Microsoft Defender portal and can also be sent to Microsoft for analysis, depending on the organization’s configuration. In modern workflows, a reported message may become part of a broader Defender XDR incident if it matches other malicious indicators, affected users, URLs, files, devices, or sender infrastructure. Security analysts can review the email entity, URL entity, sender details, authentication results, delivery location, click activity, and related alerts before deciding whether to remediate, tune policy, or close the case as benign.
Automated Investigation and Response for phishing
Automated Investigation and Response, or AIR, in Microsoft Defender for Office 365 Plan 2 helps investigate phishing, malware, and related email threats at scale. Instead of requiring analysts to manually inspect every reported message or alert, AIR analyzes the original message, similar messages, recipients, URLs, attachments, sender infrastructure, user activity, and related signals. Investigations can recommend actions such as moving messages to quarantine, deleting messages, blocking malicious URLs or files, disabling compromised users, or triggering additional endpoint investigation when Defender for Endpoint data is available. Depending on the tenant’s automation settings and role assignments, actions may be taken automatically or placed in the Action center for approval.
Clicked URL verdict changed to malicious
A common attack pattern is delayed weaponization: a URL looks harmless at delivery time, then later redirects to credential theft, malware, or another malicious destination. Microsoft Defender for Office 365 Safe Links and post-delivery analysis help detect these changes. When a user clicks a URL whose verdict later changes to malicious, the activity can trigger alerts and contribute to a Defender XDR incident. Analysts can review the timeline, the affected user, the clicked URL, related messages, URL detonation results where available, and any endpoint or identity activity that occurred after the click. If there are signs of credential compromise, the investigation should include Microsoft Entra ID sign-in activity, risk detections, multifactor authentication status, inbox rule changes, OAuth app consent, and any suspicious cloud app activity surfaced through Microsoft Defender for Cloud Apps.
Zero-hour auto purge and post-delivery remediation
Zero-hour auto purge, commonly called ZAP, helps remove or quarantine messages after delivery when Microsoft later determines that they are malicious or unwanted. ZAP is used for malware, phishing, and spam scenarios in Exchange Online Protection and Microsoft Defender for Office 365, with behavior depending on policy, verdict, mailbox state, and service configuration. In Defender Explorer and the email entity experience, analysts can review where messages were delivered, whether they were read or clicked, whether ZAP acted on them, and what remediation actions remain. Where supported and enabled, Teams message protection and remediation can also be part of the broader Defender for Office 365 investigation experience. ZAP should not be treated as a substitute for prevention; it works best together with Safe Links, Safe Attachments, anti-phishing policies, impersonation protection, and strong email authentication.
Cross-domain investigation with Defender XDR
The biggest improvement since the old Microsoft Threat Protection experience is unified incident correlation. A phishing campaign may start with email, but the real impact can involve an endpoint infection, a stolen session, impossible travel sign-ins, risky OAuth consent, suspicious mailbox rules, or data exfiltration from a sanctioned cloud app. Microsoft Defender XDR helps connect these signals into one incident so analysts can move from alert triage to impact assessment. Relevant evidence can include users, devices, files, URLs, mail clusters, cloud apps, identities, and identity-related events from Microsoft Entra ID. For deeper investigation, analysts can use Advanced hunting with Kusto Query Language across Defender data tables, and organizations using Microsoft Sentinel can connect Defender incidents into their SIEM and SOAR processes.
Licensing and role considerations
The most advanced phishing investigation and AIR capabilities generally require Microsoft Defender for Office 365 Plan 2, Microsoft 365 E5, Office 365 E5, or an equivalent security add-on. Defender XDR value increases when it is combined with Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, and Microsoft Entra ID P1 or P2 capabilities. Licensing should be reviewed carefully under the current Microsoft Cloud Solution Provider New Commerce Experience, or NCE, because monthly and annual terms, add-ons, renewal dates, and cancellation windows affect cost and flexibility. Access also depends on Microsoft Defender portal role-based access control and Microsoft Entra roles; analysts should have only the permissions they need to review incidents, approve actions, run hunting queries, and manage security settings.
2026 best practices for phishing response
A modern phishing defense program should combine prevention, detection, automation, and user readiness. Configure SPF, DKIM, and DMARC for trusted domains and monitor alignment failures. Use Microsoft Defender for Office 365 anti-phishing policies, Safe Links, Safe Attachments, impersonation protection, and preset security policies where appropriate. Enable user reporting and define who reviews submissions. Tune AIR automation levels so routine containment can move quickly while high-impact actions still receive the right approval. Review the Action center daily, close the loop on false positives, and use Explorer and Advanced hunting to identify campaign patterns. Run phishing simulation and awareness training to reduce repeat risky behavior. For organizations with mature SecOps requirements, consider Microsoft Sentinel for extended SIEM/SOAR and Microsoft Security Copilot as an optional assistant for summarizing incidents, drafting hunting queries, and accelerating analyst workflows.
Key takeaways
- Microsoft Threat Protection is now Microsoft Defender XDR, with security workflows centered in the Microsoft Defender portal.
- Automated Investigation and Response in Microsoft Defender for Office 365 Plan 2 helps investigate phishing, malicious URLs, user-reported messages, and related evidence at scale.
- ZAP provides post-delivery remediation for malicious or unwanted messages, but it should be paired with strong prevention controls such as Safe Links, Safe Attachments, anti-phishing policies, and email authentication.
- Modern phishing investigations should include email, endpoint, identity, cloud app, and user activity signals rather than treating each alert as a standalone event.
- Licensing, NCE subscription terms, role permissions, and automation approval settings should be reviewed before relying on advanced Defender XDR workflows.
IT Partner can help you assess your current Microsoft Defender configuration, modernize phishing protection, tune AIR and Action center workflows, and align Microsoft 365 security licensing under NCE with your operational needs.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.