Incidents

Open Incidents to review security investigations. The list groups incident severity, status, subjects, timestamps, and the reason an item needs attention. Open an incident to review related messages, detections, indicators, attachments, collaboration, analyst feedback, and the AI brief when your role allows it.

Incident detail links contain a tenant-scoped incident identifier. A direct URL never grants access by itself. Incident updates, collaboration, containment, URL analysis, attachment rescans, and AI analysis each use separate action permissions.

Quarantine

Quarantine shows held messages and recommendations. Review the reason and evidence before choosing an action. Depending on the provider and the role, actions can include release, delete, or leaving the message held. EmDash records the requested action and its outcome; Microsoft-managed quarantine remains authoritative for provider-held records.

Security Detections

Security Detections brings supported Defender alerts, incidents, user reports, analyzed email, provider quarantine, and remediation history together. The Microsoft Defender connection is independent from Microsoft 365 mailbox ingestion and requires XDR plus integration access.

Some provider evidence can be unavailable while synchronization is pending or when Microsoft does not expose a supported API for the record type. Use the page’s explanation and the provider portal when it identifies Microsoft as authoritative.

Containment caution: A visible remediation button means the action is available for this record and role, not that the provider has completed it. Check the resulting status and reason.