diff --git a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md index 81ce65baaa..d6dd2ea36a 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md +++ b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md @@ -82,10 +82,12 @@ The default device group is configured for semi-automatic remediation. This mean When a pending action is approved, the entity is then remediated and this new state is reflected in the **Entities** tab of the investigation. -## Next step +## Next steps - [Learn about the automated investigations dashboard](manage-auto-investigation.md) +- [See the interactive guide: Investigate and remediate threats with Microsoft Defender ATP](https://aka.ms/MDATP-IR-Interactive-Guide)(https://aka.ms/MDATP-IR-Interactive-Guide) + ## Related articles - [Automated investigation and response in Office 365 Advanced Threat Protection](https://docs.microsoft.com/microsoft-365/security/office-365-security/office-365-air)