Configure AIR Remediation Level for a Device
You have a Microsoft 365 E5 subscription. You need to configure the automated investigation and response (AIR) remediation level for a device named Device1 to require approval for all folders. What should you create?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Automated investigation and response (AIR) remediation levels are configured at the device group level, meaning you must group devices to apply a specific automation scope.
Configuring the automated investigation and response (AIR) remediation level in Microsoft Defender for Endpoint requires creating a device group. This page establishes that device groups are the boundary used to apply specific automation settings to targeted devices.
Choosing a security group (A) is the most common mistake, as users confuse Entra ID security groups with Defender device groups used for policy scoping.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Microsoft Defender for Endpoint, automated investigation and response (AIR) settings, such as the remediation level, are configured on a per-group basis. To apply a specific remediation level like 'Require approval for all' to a device, you must create a device group, set the desired automation level for that group, and include the target device within it. This allows for granular control over how automated actions are handled across different device populations.Why the Other Options Are Wrong
A security group (A) is an identity and access management object in Microsoft Entra ID and does not dictate Defender endpoint automation levels. An administrative unit (C) is used to restrict administrative scope in Entra ID but has no bearing on Defender endpoint configurations or AIR settings. An action group (D) is an Azure Monitor concept used to trigger notifications or automated workflows (like Logic Apps) when an alert fires, which is unrelated to Defender's built-in AIR remediation configurations.Community Comment Notes
The community strongly agrees that a device group is the correct configuration object, with multiple users providing the exact navigation path in the Microsoft Defender portal. As murcao noted, the path is "Settings > Endpoints > Device groups" where you can select the "Automation level" list to require approval.Official Reference
Exam Strategy
When asked about configuring Microsoft Defender for Endpoint automation or remediation levels, always associate these settings with device groups. Remember that device groups are the primary scoping mechanism for applying Defender-specific policies and automation boundaries.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →