Study guide
Technical reference and lesson notes
Purpose of This Lesson
This lesson explains how the Actions and Submissions area in Microsoft Defender XDR supports security operations workflows. This is important for the SC-200 exam because Microsoft Security Operations Analysts need to understand how suspicious files, emails, Teams messages, URLs, and user-reported content can be submitted for analysis and how resulting actions are reviewed, approved, rejected, or investigated.
In a real SOC, this workflow helps analysts move from suspicion to investigation and response. A user may report a phishing email, an analyst may submit a suspicious file, Microsoft may return a verdict, and Defender XDR may recommend or perform remediation actions such as quarantining a file or isolating a device.
The main exam-relevant idea is that Submissions are used to send suspicious or questionable items to Microsoft for analysis, while the Action Center is used to review response actions that have occurred or are pending approval.
Key Concepts
Microsoft Defender XDR Actions and Submissions Overview
The Actions and Submissions section in Microsoft Defender XDR provides two major SOC functions:
- Submissions
- Used to submit suspicious or incorrectly classified items to Microsoft for analysis.
- Can include emails, Teams messages, files, URLs, attachments, and user-reported items.
- Action Center
- Used to review actions taken by Microsoft Defender XDR, automated investigation and response, Microsoft Defender Antivirus, or manual response actions.
- Shows pending and completed actions.
- Allows analysts to approve, reject, investigate, or undo certain actions when supported.
For the SC-200 exam, remember that this is primarily a Microsoft Defender XDR operational workflow, not a Microsoft Sentinel analytics rule workflow.
Submissions in Microsoft Defender XDR
The Submissions area allows analysts and administrators to send suspicious content to Microsoft for review. Microsoft analyzes the submitted item and returns a verdict.
Common submission types include:
- Emails
- Microsoft Teams messages
- Email attachments
- URLs
- Files
- User-reported items
This is useful when an analyst needs Microsoft to review whether something is malicious, suspicious, clean, or incorrectly classified.
Example Use Case
An analyst receives a suspicious file from an endpoint investigation. The analyst can submit the file to Microsoft and categorize it as possible malware. The submission can include a priority level and notes explaining the context.
The goal is not just to upload a file. The goal is to receive analysis that can support a security decision, such as whether to block, quarantine, create an indicator, or continue investigating.
File Submissions
When submitting a file, Defender XDR allows the analyst to provide information such as:
- The file being submitted
- The suspected classification, such as possible malware
- Priority level, such as low, medium, or high
- Notes or context for Microsoft
- Optional feedback
Important operational details:
- File submissions may have file size limits.
- Files are submitted one at a time.
- The submission does not instantly create a response action.
- Microsoft must analyze the file and return a result.
- Until analysis completes, the submission may remain in a pending state.
For the exam, do not confuse submitting a file for analysis with taking remediation action. Submission is part of investigation and classification. Remediation happens through supported Defender response actions.
User-Reported Messages
Users can report suspicious messages directly from Microsoft 365 apps such as Outlook and Teams. For example, a user may receive a phishing simulation or suspicious email and use the built-in Report option to report it as phishing.
Reported messages eventually appear in the Defender portal under the appropriate user-reported submissions area.
Important points:
- User reports may not appear immediately.
- There can be a delay before the report is visible in Defender XDR.
- User reporting helps the SOC receive phishing and social engineering reports directly from end users.
- These reports can trigger further investigation or automated analysis.
From a SOC perspective, user-reported phishing is valuable because users are often the first people to see suspicious emails, credential harvesting attempts, malicious attachments, or unusual Teams messages.
Action Center
The Action Center is where analysts review actions that have been taken or are pending. These actions may come from different sources, including:
- Automated investigation and response
- Microsoft Defender Antivirus
- Manual response actions taken by an analyst
The Action Center may show actions such as quarantined files, device isolation, or other remediation steps.
A key point for SC-200 is that the Action Center is not where you submit suspicious content. It is where you review and manage actions related to investigation and response.
Pending Actions vs History
The Action Center commonly includes views for reviewing action status.
Pending Actions
Pending actions are actions that may require analyst review or approval before they are completed.
An analyst may need to:
- Review the recommendation
- Confirm the affected entity
- Approve the action
- Reject the action
- Investigate further before making a decision
History
The history view shows actions that have already occurred.
For example, if a file was quarantined on a test endpoint, the Action Center history can show that action. The analyst can open the related investigation page to review additional information, such as alerts, evidence, affected devices, and related entities.
Investigation Page
When an action is associated with an investigation, Defender XDR can provide an investigation page with more detail.
An analyst may review:
- Alerts generated during the investigation
- The affected device
- The suspicious file
- Related evidence
- Investigation status
- Recommended actions
- Completed actions
This supports the SOC workflow of moving from alert triage to evidence review and then to response.
Automated Investigation and Response
Microsoft Defender XDR can perform automated investigation and response actions depending on licensing, configuration, workload, and the type of threat.
Automated investigation can analyze alerts and evidence, then recommend or take response actions.
Examples of supported actions discussed in this lesson include:
- Isolate a device
- Restrict code execution
- Quarantine a file
- Remove a registry key
- Stop a service
- Disable a driver
- Remove a scheduled task
Some actions may be reversible or may allow undo operations, depending on the action type and Defender capabilities.
For the SC-200 exam, remember that automation can assist the analyst, but analysts still need to understand whether an action is appropriate, supported, and safe for the environment.
Microsoft Defender for Endpoint Licensing Consideration
The endpoint-related evaluation, simulation, and response features require appropriate Microsoft Defender for Endpoint licensing.
This matters because some Defender XDR features are tied to specific Defender products. If the scenario involves endpoint response actions such as isolating a device, quarantining a file, or restricting code execution, the relevant product is Microsoft Defender for Endpoint.
On the SC-200 exam, pay attention to the workload involved:
- Endpoint device issue: Defender for Endpoint
- Email or phishing issue: Defender for Office 365
- Identity-based suspicious activity: Defender for Identity or Entra ID Protection
- Cloud resource threat: Defender for Cloud
- Cross-domain incident correlation: Defender XDR
- SIEM/SOAR analytics and custom log correlation: Microsoft Sentinel
Create Indicator Option
After submitting or investigating a suspicious file, Defender may provide options that help create an indicator.
Indicators can be used to allow, block, or alert on specific entities such as files, URLs, IP addresses, or certificates, depending on the Defender product and configuration.
In a SOC workflow, creating an indicator may be appropriate when:
- A file is confirmed malicious.
- A hash needs to be blocked across endpoints.
- A URL is known to be malicious.
- An IP address is associated with attacker infrastructure.
- The organization needs a temporary containment control.
However, analysts should be careful with indicators. Blocking the wrong item can cause business disruption, especially if the indicator applies broadly across the tenant.
Microsoft Security Operations Context
How This Fits into a SOC Workflow
The Actions and Submissions area supports several common SOC activities:
- Suspicious item identified
- A user reports an email.
- An analyst finds a suspicious file.
- Defender generates an alert.
- A simulation file is used for testing.
- Item submitted for analysis
- The analyst submits the email, Teams message, URL, file, or attachment.
- The submission includes classification, priority, and notes.
- Microsoft reviews the submission
- The item may show as pending while analysis is performed.
- The final verdict can help guide response.
- Action is reviewed
- If Defender recommends or performs remediation, the Action Center shows the action.
- The analyst can review pending or completed actions.
- Investigation continues
- The analyst opens the investigation page.
- Alerts, entities, and evidence are reviewed.
- Scope and impact are determined.
- Response is performed
- A file may be quarantined.
- A device may be isolated.
- Code execution may be restricted.
- A malicious artifact may be blocked using an indicator.
- Documentation and improvement
- Findings are documented.
- False positives are tuned.
- Detection logic or user training may be improved.
- Similar threats may be hunted across the environment.
Triage Considerations
When reviewing submissions or Action Center items, an analyst should ask:
- What was submitted?
- Who submitted it: analyst, user, automated system, or Defender?
- Is the item still pending review?
- Did Microsoft return a malicious, suspicious, or clean verdict?
- Was an action already taken?
- Does the action require approval?
- Which device, user, mailbox, file, URL, or process is affected?
- Is the action safe to approve?
- Could the action disrupt production systems?
- Is escalation required?
Entity Review
Depending on the submission or action, the analyst may need to review related entities such as:
- Users
- Mailboxes
- Devices
- Files
- File hashes
- URLs
- IP addresses
- Registry keys
- Services
- Scheduled tasks
- Drivers
- Alerts
- Incidents
The SC-200 exam often tests whether you understand the relationship between alerts, incidents, evidence, and entities.
Exam-Relevant Takeaways
What to Remember for SC-200
- Submissions are used to send suspicious or incorrectly classified items to Microsoft for analysis.
- Action Center is used to review pending and completed response actions.
- A submitted item may stay pending while Microsoft analyzes it.
- User-reported phishing messages may not appear instantly.
- Users can report suspicious content from Microsoft 365 apps such as Outlook and Teams.
- Endpoint response features require appropriate Defender for Endpoint licensing.
- Automated investigation and response can recommend or perform remediation actions.
- Analysts may be able to approve, reject, or undo certain actions.
- Action sources can include automated investigation, Microsoft Defender Antivirus, and manual response actions.
- Supported endpoint response actions can include device isolation, file quarantine, code execution restriction, registry key removal, service stoppage, driver disabling, and scheduled task removal.
- Creating indicators can help block or allow known entities, but broad blocking decisions should be made carefully.
- Microsoft Sentinel is not the primary feature for submitting suspicious files or emails to Microsoft. That is handled in Microsoft Defender XDR.
Tool / Feature Decision Guide
| Scenario | Best Microsoft Security Tool or Feature | Why |
|---|---|---|
| Analyst wants Microsoft to analyze a suspicious file | Microsoft Defender XDR Submissions | Submissions allow files to be sent to Microsoft for analysis and verdict review. |
| User reports a phishing email from Outlook | User-reported submissions in Defender XDR | User reports from Microsoft 365 apps can flow into Defender for analyst review. |
| Analyst needs to review remediation actions that were taken | Action Center | The Action Center tracks pending and completed actions. |
| Defender recommends quarantining a malicious file | Action Center | The analyst can review, approve, reject, or investigate the action depending on configuration. |
| Analyst needs to isolate a compromised endpoint | Microsoft Defender for Endpoint | Device isolation is an endpoint response action. |
| Analyst wants to review alerts related to a quarantined file | Investigation page in Defender XDR | The investigation page provides related alerts, evidence, and entities. |
| Analyst wants to block a confirmed malicious file hash | Defender indicator | Indicators can be used to block known malicious artifacts. |
| Analyst wants to correlate Defender data with firewall logs or custom logs | Microsoft Sentinel | Sentinel is better suited for SIEM-style log correlation across multiple data sources. |
| Analyst wants to create a detection from recurring suspicious activity | Microsoft Sentinel analytics rule or Defender custom detection | Use an analytics rule or custom detection depending on where the relevant data lives. |
| Analyst wants to review actions from automated investigation | Action Center | Automated investigation actions are surfaced in the Action Center. |
KQL Notes
This lesson does not focus on KQL. The workflow is primarily portal-based: submitting suspicious content, reviewing user-reported items, and managing actions in the Action Center.
However, in real investigations, KQL can support follow-up hunting after a suspicious file, URL, or user report is identified.
Optional Reinforcement Example: Hunt for a File Hash in Defender Advanced Hunting
DeviceFileEvents
| where SHA256 == "REPLACE_WITH_FILE_HASH"
| project Timestamp, DeviceName, ActionType, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
What This Query Does
| Query Part | Purpose |
|---|---|
DeviceFileEvents | Searches endpoint file activity events. |
where SHA256 == | Filters results to a specific file hash. |
project | Selects the most useful columns for review. |
order by Timestamp desc | Shows the most recent activity first. |
How This Helps in a Real Investigation
If a submitted file is later determined to be malicious, an analyst may use advanced hunting to determine whether the file appeared on other devices. This helps answer the SOC question: “Is this isolated to one endpoint, or is it broader?”
Exam Reminder
Do not assume KQL is always required. For this topic, the main exam focus is understanding where to submit suspicious items and where to manage response actions.
Common Exam Traps
Confusing Submissions with Action Center
A common misunderstanding is thinking that the Action Center is where suspicious files or emails are submitted. It is not.
- Use Submissions to send suspicious items to Microsoft.
- Use Action Center to review response actions.
Expecting Instant Results
Submissions and user-reported messages may take time to appear or receive a verdict. Do not assume that an item appears immediately after submission.
Thinking a Submission Automatically Means Remediation
Submitting a file does not automatically mean the file is quarantined, blocked, or removed. Submission is for analysis. Remediation is handled through Defender response actions, indicators, automated investigation, or manual analyst action.
Ignoring Licensing Requirements
Endpoint simulation and endpoint response features require Defender for Endpoint licensing. If the scenario involves isolating a device or restricting code execution, the answer usually points toward Defender for Endpoint capabilities.
Choosing Microsoft Sentinel for Defender Submission Workflows
Microsoft Sentinel is powerful for SIEM, SOAR, analytics rules, workbooks, hunting, and cross-source correlation. But submitting suspicious Defender content to Microsoft and reviewing Defender response actions is a Defender XDR workflow.
Approving Actions Without Reviewing Impact
Some actions can affect production systems. For example, isolating a device or stopping a service may disrupt users or business applications. In the real world, analysts should review scope, severity, business impact, and escalation requirements before approving disruptive actions.
Real-World SOC Analyst Notes
Alert Fatigue and User Reports
User-reported phishing can create a high volume of submissions. Some will be true positives, some will be spam, and some will be harmless. A mature SOC needs a triage process so user reports are reviewed consistently without overwhelming analysts.
False Positives
A file or email may look suspicious but turn out to be benign. Submitting items to Microsoft can help resolve classification questions, but analysts should still use internal evidence such as device activity, email headers, sender reputation, URL behavior, and user impact.
Evidence Preservation
Before taking disruptive actions, analysts should preserve relevant evidence when possible. This may include alert details, file hashes, email metadata, affected users, device names, timestamps, and investigation notes.
Escalation Paths
Some actions may require escalation to endpoint, identity, messaging, cloud, or infrastructure teams.
Examples:
- Device isolation may require endpoint or desktop support coordination.
- Mailbox compromise may require Microsoft 365 or identity team involvement.
- Service stoppage may require application owner review.
- Blocking indicators tenant-wide may require change control.
Automation Safety
Automated investigation and response can speed up containment, but automation should be configured carefully. Overly aggressive remediation can disrupt business operations if false positives occur.
Tenant-Wide Impact
Actions such as creating indicators or blocking files can have broad impact. Before blocking a hash, URL, or IP address, confirm that the item is truly malicious and understand where the control will apply.
Documentation
Good SOC documentation should include:
- What was submitted
- Who reported or identified it
- What Microsoft’s verdict was
- Related alerts or incidents
- Affected users or devices
- Actions taken
- Whether actions were approved, rejected, or undone
- Any escalation or follow-up needed
Cost Considerations
This particular workflow is mostly Defender XDR-focused. However, if similar data is ingested into Microsoft Sentinel for long-term hunting, correlation, or reporting, ingestion and retention costs should be considered.
Quick Reference Summary
- Submissions = send suspicious items to Microsoft for analysis.
- Action Center = review pending and completed response actions.
- Users can report phishing or suspicious messages from Outlook and Teams.
- User-reported items may take time to appear.
- File submissions can be marked with classification, priority, and notes.
- A submission may remain pending while Microsoft analyzes it.
- Endpoint response actions require Defender for Endpoint licensing.
- Automated investigation, Defender Antivirus, and manual response actions can appear in Action Center.
- Supported actions may include isolate device, restrict code execution, quarantine file, remove registry key, stop service, disable driver, or remove scheduled task.
- Analysts can investigate actions by opening the related investigation page.
- Some actions may be approved, rejected, or undone.
- Use Defender XDR for submissions and action review.
- Use Sentinel when you need SIEM correlation, analytics rules, workbooks, or custom log-based detection.
Flashcards
Q: What is the purpose of Submissions in Microsoft Defender XDR?
A: Submissions allow analysts or users to send suspicious emails, Teams messages, URLs, attachments, or files to Microsoft for analysis.
Q: What is the purpose of the Action Center?
A: The Action Center is used to review and manage pending or completed response actions from Defender, automated investigations, antivirus actions, or manual response actions.
Q: Does submitting a file automatically quarantine it?
A: No. Submitting a file sends it to Microsoft for analysis. Remediation actions are handled separately.
Q: Where would an analyst review a completed quarantine action?
A: In the Action Center history.
Q: What Defender product is required for endpoint response actions such as isolating a device?
A: Microsoft Defender for Endpoint.
Q: What can users do from Outlook when they receive a suspicious email?
A: They can report the message as phishing or suspicious using the built-in reporting option.
Q: Will a user-reported phishing message always appear immediately in Defender XDR?
A: No. There can be a delay before user-reported items appear.
Q: Name three supported response actions associated with Defender endpoint investigations.
A: Examples include isolate a device, quarantine a file, restrict code execution, stop a service, remove a registry key, disable a driver, or remove a scheduled task.
Q: What is the difference between pending actions and action history?
A: Pending actions may require review or approval, while history shows actions that have already occurred.
Q: What is an indicator used for in Defender?
A: An indicator can be used to allow, block, or alert on specific entities such as files, URLs, IP addresses, or certificates.
Q: When should Microsoft Sentinel be used instead of Defender XDR Submissions?
A: Use Sentinel for SIEM-style log correlation, analytics rules, workbooks, hunting across connected data sources, and automation through playbooks.
Q: What should an analyst review before approving a disruptive response action?
A: The analyst should review affected entities, severity, business impact, evidence, and whether escalation or change control is required.
Practice Questions
Question 1:
A user reports a suspicious email from Outlook using the built-in reporting option. You need to review the reported message after it is processed. Where should you look?
A. Microsoft Sentinel Workbooks
B. Microsoft Defender XDR user-reported submissions
C. Microsoft Entra audit logs
D. Microsoft Defender for Cloud recommendations
Correct Answer:
B. Microsoft Defender XDR user-reported submissions
Explanation:
User-reported phishing or suspicious messages from Outlook and Teams are reviewed in the Defender XDR submissions area. Sentinel workbooks are used for visualization and reporting, not for reviewing Defender user-reported message submissions.
Question 2:
You submit a suspicious file to Microsoft from the Defender portal. After submission, you do not immediately see a remediation action in the Action Center. Why?
A. Submissions never support files
B. Microsoft Sentinel must be enabled first
C. The file must be analyzed before a verdict or related action is available
D. Defender for Identity must approve the submission
Correct Answer:
C. The file must be analyzed before a verdict or related action is available
Explanation:
Submitting a file sends it to Microsoft for analysis. The submission may remain pending until Microsoft completes the review. Submission is not the same thing as immediate remediation.
Question 3:
An automated investigation recommends quarantining a file on an endpoint. You need to review the recommended action before it is completed. Which Defender XDR area should you use?
A. Action Center
B. Secure Score
C. Microsoft Sentinel Data Connectors
D. Microsoft Entra sign-in logs
Correct Answer:
A. Action Center
Explanation:
The Action Center is used to review pending and completed actions from automated investigations, Microsoft Defender Antivirus, and manual response actions.
Question 4:
A device is suspected of being compromised, and you need to prevent it from communicating with other devices while preserving the ability to investigate it. Which action is most appropriate?
A. Delete the user account
B. Isolate the device
C. Disable Microsoft Sentinel
D. Remove all mailbox rules
Correct Answer:
B. Isolate the device
Explanation:
Device isolation is a Microsoft Defender for Endpoint response action used to contain a potentially compromised endpoint while allowing continued security management and investigation.
Question 5:
You want to determine whether a suspicious file has appeared on other endpoints after Microsoft confirms it is malicious. Which approach would help?
A. Create a Microsoft Sentinel workbook only
B. Use Defender Advanced Hunting to search for the file hash
C. Review Microsoft Entra application registrations
D. Disable all user-reported submissions
Correct Answer:
B. Use Defender Advanced Hunting to search for the file hash
Explanation:
Advanced Hunting can be used to search endpoint telemetry for a file hash across devices. This helps determine scope and impact after a suspicious file is identified.