Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
02Microsoft Defender for Endpoint9 modules · 60 units · 5 hr 49 min · Deployment, attack surface reduction, investigations, response, automation, detections, and vulnerability management0/60 units complete
Learning path 02 · Microsoft Defender for Endpoint

9 modules · 60 units · 5 hr 49 min · Deployment, attack surface reduction, investigations, response, automation, detections, and vulnerability management

0%

Study focus

Endpoint readiness

Deploy, onboard, configure, and harden devices with Microsoft Defender for Endpoint.

Investigation and response

Investigate devices and evidence, take response actions, automate remediation, and tune detections.

9 modules · 60 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

07

Module 7

Configure and manage automation using Microsoft Defender for Endpoint

Focus: advanced features, sample handling, automated investigation and remediation, and risky-device access control.
0/7
01 / 07Introduction

Automation reduces repetitive analysis while retaining governance through permissions, remediation levels, evidence handling, Action center audit, and approval workflows.

Official moduleAutomation objectives
02 / 07Configure advanced features

Enable integrations and automation-related capabilities under Settings > Endpoints > Advanced features. Examples include automated investigation, Live Response, Intune connection, authenticated telemetry sharing, custom network indicators, and preview capabilities.

Validate licensing, data-sharing implications, RBAC, and endpoint prerequisites before enabling a tenant-wide switch.

Official lessonAutomation-related tenant features
03 / 07Manage automation upload and folder settings

Sample submission allows Microsoft to analyze suspicious files and improve verdicts. Configure whether samples are submitted automatically and define exclusions for sensitive folders or file extensions where justified. Exclusions can reduce investigation quality, so keep them narrow and review them regularly.

Official lessonSample sharing and exclusions
04 / 07Configure automated investigation and remediation capabilities

AIR inspects evidence, assigns verdicts, and applies or proposes remediation. Device-group automation levels determine whether remediation is fully automatic, requires approval, or is limited. Pending actions are reviewed in the Action center.

1 · TriggerAn alert or analyst action starts investigation.
2 · InspectAIR examines devices, files, processes, services, and persistence.
3 · VerdictEvidence is classified malicious, suspicious, or clean.
4 · RemediateActions run automatically or wait for approval.
Official lessonAIR process and remediation levels
05 / 07Block at-risk devices

MDE sends device-risk signals to Microsoft Intune. Intune compliance policy evaluates that risk, and Microsoft Entra Conditional Access can block access to organizational resources until the endpoint is remediated and becomes compliant again.

1 · DetectMDE calculates device risk.
2 · EvaluateIntune marks the device compliant or noncompliant.
3 · EnforceConditional Access allows or blocks access.
4 · RestoreRemediation lowers risk and restores compliance.
Official lessonMDE, Intune, and Conditional Access
06 / 07Module assessment

Differentiate the tenant feature switch, device-group remediation level, Action center approval, sample-upload setting, and Intune/Conditional Access enforcement flow.

Official assessmentAutomation knowledge check
07 / 07Summary and resources

Effective automation combines broad telemetry with least privilege, controlled remediation levels, transparent audit history, and clear approval and exception processes.

Official moduleSummary and resources
End of learning pathMicrosoft Defender for Endpoint