← Back
Microsoft Defender: Automated investigation and response (AIR) integrated into antivirus with manual triggering removed
MC1411577 · build prod-20251231-200323
Category
planForChange
Severity
normal
Major change
True
Last modified
2026-08-28 20:55:24
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
2026-09-01 07:00:00
Action by (AI)
Services
Microsoft Defender XDR
Tags
Updated message, User impact, Admin impact, Retirement
Master tags
Admin, Security, Compliance
Roadmap IDs

One-line summary

Standalone AIR investigations in Defender for Endpoint will be removed—AIR will run automatically as part of default antivirus by early September 2026; manual AIR triggers and related integrations must be updated.

Similar updates

More like this

Details

Summary
Microsoft Defender for Endpoint will remove manual triggering and the standalone experience of automated investigation and response (AIR) by early September 2026. AIR functions are integrated into always-on antivirus protection. Organizations using AIR in playbooks or scripts must update them before September 1, 2026.

Body (from Message Center)

Updated August 28, 2026: We have updated the timeline. Thank you for your patience. 

[What and Why]

As first announced on July 1st, automated investigation and response (AIR) for Defender for Endpoint will no longer run as a separate investigation experience or be available for manual triggering in Microsoft Defender.

There is no change to AIR functionality in Microsoft Defender for Office 365.

The protection capabilities of AIR are already embedded within Microsoft Defender’s always-on antivirus protection stack today. Detection and response run automatically as part of default protection, without requiring a separate investigation workflow.

This change is part of our ongoing “shift left” effort to lift the onus of protection from customers by automating detection and response processes, helping ensure consistent outcomes across endpoints without reliance on a separate, manually initiated investigation experience.

With this update, the standalone AIR investigation experience is removed. For on-demand investigations, teams can run full antivirus scans as needed.

[Rollout Schedule]

  • Transition (Worldwide, GCC, GCC High, DoD): Beginning and completing in early September 2026

[Impact on Your Organization]

Who is affected

  • Admins and security teams using Microsoft Defender for Endpoint and Microsoft Defender XDR

Platforms/Services

  • Microsoft Defender for Endpoint across supported platforms

What will happen

  • Manual triggering of automated investigation and response (AIR) will no longer be available.
  • AIR will no longer run as a separate investigation experience.
  • Detection and response will occur automatically as part of always-on antivirus protection.
  • Full antivirus scans replace manual AIR investigations for on-demand analysis.
  • Any playbooks, scripts, or integrations that initiate AIR will stop working after September 1, 2026, and must be updated before that date.
  • Protection remains enabled by default.

[Action Required / Recommendations]

If you are not using AIR manually or through automation, no action is required to maintain protection.

Action is required for organizations using AIR in playbooks, scripts, or integrations, as these will no longer function after September 1, 2026.

  • Review and update any playbooks, scripts, or integrations that initiate AIR before September 1, 2026.
  • Replace AIR-based workflows with full antivirus scan workflows for on-demand investigations.
  • Update internal documentation that references AIR investigations.
  • Inform security and helpdesk teams of this change.

Learn more: 

[Compliance considerations]

QuestionAnswer
Does the change alter how admins can monitor, report on, or demonstrate compliance activities?Yes. AIR will no longer appear as a distinct investigation type, which may affect monitoring and reporting workflows.

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": "2026-09-01T07:00:00Z",
    "ai_action_required_by": null,
    "ai_actions": [
      "Review and update playbooks, scripts, or integrations that use AIR",
      "Replace AIR-based workflows with antivirus scan workflows",
      "Update documentation referencing AIR investigations",
      "Inform security and helpdesk teams of this change"
    ],
    "ai_master_tags": [
      "Admin",
      "Security",
      "Compliance"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Standalone AIR investigations in Defender for Endpoint will be removed\u2014AIR will run automatically as part of default antivirus by early September 2026; manual AIR triggers and related integrations must be updated.",
    "ai_topics": [
      "Defender"
    ],
    "category": "planForChange",
    "details_map": {
      "Summary": "Microsoft Defender for Endpoint will remove manual triggering and the standalone experience of automated investigation and response (AIR) by early September 2026. AIR functions are integrated into always-on antivirus protection. Organizations using AIR in playbooks or scripts must update them before September 1, 2026."
    },
    "id": "MC1411577",
    "importance": 5,
    "is_major_change": true,
    "last_modified": "2026-08-28T20:55:24Z",
    "ms_products": [
      "Defender"
    ],
    "platforms": null,
    "roadmap_ids": [],
    "services": [
      "Microsoft Defender XDR"
    ],
    "severity": "normal",
    "tags": [
      "Updated message",
      "User impact",
      "Admin impact",
      "Retirement"
    ],
    "title": "Microsoft Defender: Automated investigation and response (AIR) integrated into antivirus with manual triggering removed"
  }
}