In an effort to help security experts deal with the critical security alerts they receive every day, Microsoft has enabled its Automated Incident Response in Office 365 Advanced Threat Protection (ATP) for business customers.
The giant's automation feature is designed to help security analysts respond to alerts faster and more systematically.

In a recent post, Microsoft announced that it has two categories of automated incident response for its customers. The first category concerns automated investigations that are triggered in response to new alerts that appear when users report phishing emails, click on a malicious link, or when malicious emails or “phishing” emails are detected in mailboxes.
The second category consists of investigations that are initiated manually and use Microsoft's 'automated playbook' sequences to get to the source of different attack scenarios and types.

Extensive safety manuals
Microsoft automation follows rich security checklists, which are essentially a series of carefully documented steps that security teams can use to thoroughly investigate an alert. They also offer a set of recommended actions to contain and mitigate a risk.
The company's manuals correlate similar emails sent or received within an organization to detect any suspicious actions for users. Microsoft lists some examples of flagged activities on its website, citing mail forwarding, mail spoofing, Office 365 Data Loss Prevention (DLP), and suspicious email sending patterns.
As part of Microsoft Threat Protection, these guides also incorporate signals and detections from Microsoft Cloud App Security and Microsoft Defender ATP.
Organizations with either an Office 365 ATP Plan 2 or an Office 365 Enterprise E5 plan can take advantage of the company's automated response capabilities .
