Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A Microsoft 365 administrator is investigating a report of a user receiving an email with a malicious attachment that bypassed initial filters. The administrator needs to identify if other users in the organization also received this specific email and, if so, remove it from their mailboxes. Which Microsoft Defender for Office 365 feature is best suited for this task?
- AAnti-spam policies
- BSafe Attachments
- CAnti-phishing policies
- DThreat Explorer
Show answer & explanationAnswer & explanation
Correct answer: D. Threat Explorer
Threat Explorer in Microsoft Defender for Office 365 allows administrators to investigate email-based threats, search for specific emails across the organization, and initiate remediation actions like deleting emails from mailboxes.
Why the other options are wrong
- A. Anti-spam policies are for prevention of unsolicited bulk email, not for specific threat hunting and remediation of malicious emails.
- B. Safe Attachments is a preventative feature that detonates attachments in a sandbox, not for post-delivery investigation and removal.
- C. Anti-phishing policies are for prevention, not for searching and removing already delivered emails.
Threat Explorer (MDO)
A powerful reporting tool in Microsoft Defender for Office 365 that allows security teams to investigate and remediate email-borne threats.
- Provides granular search capabilities for email flow.
- Identifies malicious emails that bypassed filters.
- Enables remediation actions like soft delete or hard delete from mailboxes.
Memory trick: Explorer's Scope Finds Every Email Trail.