Update manage-auto-investigation.md

This commit is contained in:
Denise Vangel-MSFT
2020-09-16 09:36:43 -07:00
committed by GitHub
parent 0038b9f7be
commit f122567282

View File

@ -22,10 +22,14 @@ ms.date: 09/15/2020
## Remediation actions
When an [automated investigation](automated-investigations.md) runs, a verdict is generated for each piece of evidence investigated. Verdicts can be *Malicious*, *Suspicious*, or *No threats found*. Depending on
When an [automated investigation](automated-investigations.md) runs, a verdict is generated for each piece of evidence investigated. Verdicts can be *Malicious*, *Suspicious*, or *No threats found*.
Depending on
- the type of threat,
- the resulting verdict, and
- how your organization's [device groups](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/machine-groups) are configured,
remediation actions can occur automatically or only upon approval by your organizations security operations team.
Here are a few examples: