Microsoft Defender Initial Investigation
A read-only first workflow for triaging Microsoft Defender alerts and affected entities.
Open Runbook entryRunbook category
Microsoft 365 administration, identity, endpoint management, messaging and security investigation references.
Commands and structured workflows for supporting Microsoft 365 services and identities.
The collection covers Exchange Online, mail flow, mailbox permissions, Entra ID, Intune, Microsoft Defender, Microsoft Graph and service-health investigation.
All examples use placeholder users, domains, devices and tenant information.
Technical reference
Commands, checks, troubleshooting procedures and operational references for this subject.
A read-only first workflow for triaging Microsoft Defender alerts and affected entities.
Open Runbook entryReview tenant service health, advisories and workload-specific diagnostics.
Open Runbook entryReview Full Access, Send As, Send on Behalf and shared mailbox delegation.
Open Runbook entryWorkflow for investigating delayed, rejected or missing Exchange Online messages.
Open Runbook entryWorkflow for enrollment, compliance, sync, ownership and managed-device investigation.
Open Runbook entryRead-only checks for mailbox type, aliases, forwarding, permissions and delivery settings.
Open Runbook entryInstall, connect, verify and disconnect Exchange Online PowerShell safely.
Open Runbook entryRead-only Microsoft Graph checks for users, groups, licenses and membership.
Open Runbook entry