For 101 or more messages selected, only email purge and propose remediation options are available
May 2025
In government cloud environments, Take action replaces the Message actions drop down list on the Email tab (view) of the details area of the All email, Malware, or Phish views in Threat Explorer (Explorer):
- SecOps personnel can now create tenant-level block entries on URLs and files via the Tenant Allow/Block List directly from Threat Explorer.
- For 100 or fewer messages selected in Threat Explorer, SecOps personnel can take multiple actions on the selected messages from the same page. For example:
- Purge email messages or propose email remediation.
- Submit messages to Microsoft.
- Trigger investigations.
- Crate block entries in the Tenant Allow/Block List.
- Actions are contextually based on the latest delivery location of the message, but SecOps personnel can use the Show all response actions toggle to allow all available actions.
- For 101 or more messages selected, only email purge and propose remediation options are available.