The Email entity page in Defender for Office 365 - Microsoft Defender for Office 365 (original) (raw)

Microsoft 365 organizations that have Microsoft Defender for Office 365 included in their subscription or purchased as an add-on have the Email entity page. The Email entity page in the Microsoft Defender portal contains highly detailed information about an email message and any related entities.

This article explains the information and actions on the Email entity page.

Permissions and licensing for the Email entity page

To use the Email entity page, you need to be assigned permissions. The permissions and licensing are the same as Threat Explorer (Explorer) and Real-time detections. For more information, see Permissions and licensing for Threat Explorer and Real-time detections.

Where to find the Email entity page

There are no direct links to the Email entity page from the top levels of the Defender portal. Instead, the Open email entity action is available at the top of the email details flyout in many Defender for Office 365 features. This email details flyout is known as the Email summary panel, and contains a summarized subset of the information on the Email entity page. The email summary panel is identical across Defender for Office 365 features. For more information, see the The Email summary panel section later in this article.

The Email summary panel with the Open email entity action is available in the following locations:

What's on the Email entity page

Screenshot of the Email entity page showing the available details pane and tabs.

The details pane on the left side of the page contains collapsible sections with details about the message. These sections remain constant as long as you're on the page. The available sections are:

The tabs (views) along the top of the page allows you to investigate email efficiently. These views are described in the following subsections.

Timeline view

The Timeline view shows the delivery and post-delivery events that happened to the message.

The following message event information is available in the view. Select a column header to sort by that column. To add or remove columns, select Customize columns. By default, all available columns are selected.

If nothing happened to the message after delivery, the message is likely to have only one row in the Timeline view with the Event types value Original delivery. For example:

Subsequent actions to the message by users, admins, or Microsoft 365 add more rows to the view. For example:

Use the Search box to find information on the page. Type text in the box and then press the ENTER key.

Use Export to export the data in the view to a CSV file. The default filename is - Microsoft Defender.csv and the default location is the Downloads folder. If a file with that name already exists, the filename is appended with a number (for example, - Microsoft Defender(1).csv).

Screenshot of the Timeline view on the Email entity page.

Analysis view

The Analysis view contains information that helps you analyze the message in depth. The following information is available in this view:

Screenshot of the Analysis view on the Email entity page.

Attachments view

The Attachments view shows information about all file attachments in the message, and the scanning results of those attachments.

The following attachment information is available in this view. Select a column header to sort by that column. To add or remove columns, select Customize columns. By default, all available columns are selected.

Use the Search box to find information on the page. Type text in the box and then press the ENTER key.

Use Export to export the data in the view to a CSV file. The default filename is - Microsoft Defender.csv and the default location is the Downloads folder. If a file with that name already exists, the filename is appended with a number (for example, - Microsoft Defender(1).csv).

Screenshot of the Attachments view on the Email entity page.

Attachment details

If you select an entry in the Attachments view by clicking on the Attachment filename value, a details flyout opens that contains the following information:

When you're finished in the file details flyout, select Close.

Screenshot of the file details flyout from the Attachments view on the Email entity page.

Block attachments from the Attachments view

If you select an entry in the Attachments view by selecting the check box next to the filename, the Block action is available. This action adds the file as a block entry in the Tenant Allow/Block List. Selecting Block starts the Take action wizard:

  1. On the Choose actions page, configure one of following settings in the Block file section:
    When you're finished on the Choose actions page, select Next.
  2. On the Choose target entities page, verify the file that you want to block is selected, and then select Next.
  3. On the Review and submit page, configure the following settings:
    • Remediation name: Enter a unique name to track the status in the Action center.
    • Description: Enter an optional description.
      When you're finished on the Review and submit page, select Submit.

URL view

The URL view shows information about all original or rewritten URLs in the message, along with the scanning results for each URL.

The following attachment information is available in this view. Select a column header to sort by that column. To add or remove columns, select Customize columns. By default, all available columns are selected.

Use the Search box to find information on the page. Type text in the box and then press the ENTER key.

Use Export to export the data in the view to a CSV file. The default filename is - Microsoft Defender.csv and the default location is the Downloads folder. If a file with that name already exists, the filename is appended with a number (for example, - Microsoft Defender(1).csv).

Screenshot of the URL view on the Email entity page.

URL details

If you select an entry in the URL view by clicking on the URL value, a details flyout opens that contains the following information:

When you're finished in the file details flyout, select Close.

Screenshot of the URL details flyout from the URL view on the Email entity page.

Block URLs from the URL view

If you select an entry in the URL view by selecting the check box next to the filename, the Block action is available. This action adds the URL as a block entry in the Tenant Allow/Block List. Selecting Block starts the Take action wizard:

  1. On the Choose actions page, configure one of following settings in the Block URL section:
    When you're finished on the Choose actions page, select Next.
  2. On the Choose target entities page, verify the URL that you want to block is selected, and then select Next.
  3. On the Review and submit page, configure the following settings:
    • Remediation name: Enter a unique name to track the status in the Action center.
    • Description: Enter an optional description.
      When you're finished on the Review and submit page, select Submit.

Similar emails view

The Similar emails view shows other email messages that have the same message body fingerprint as this message. Matching criteria in other messages doesn't apply for this view (for example, file attachment fingerprints).

The following attachment information is available in this view. Select a column header to sort by that column. To add or remove columns, select Customize columns. By default, all available columns are selected.

Use Filter to filter the entries by Start date and End date.

Use the Search box to find information on the page. Type text in the box and then press the ENTER key.

Use Export to export the data in the view to a CSV file. The default filename is - Microsoft Defender.csv and the default location is the Downloads folder. If a file with that name already exists, the filename is appended with a number (for example, - Microsoft Defender(1).csv).

Screenshot of the Similar emails view on the Email entity page.

Actions on the Email entity page

The following actions are available at the top of the Email entity page:

¹ This action requires the Preview role. You can assign this role in the following locations:

² You can preview or download email messages that are available in cloud mailboxes. Examples of when messages are no longer available in mailboxes include:

Screenshot of the available actions at the top of the Email entity page.

The Email summary panel

The Email summary panel is the email details flyout that's available in many features in the built-in security features for all cloud mailboxes and in Defender for Office 365. The Email summary panel contains standardized summary information about the email message taken from the full details that are available on the Email entity page in Defender for Office 365.

Where to find the Email summary panel is described in the Where to find the Email entity page section earlier in this article. The rest of this section describes the information that's available on the Email summary panel across all features.

Tip

The Email summary panel is available from the Action center page at https://security.microsoft.com/action-center/ on the Pending or History tabs. Select an action with the Entity type value Email by clicking anywhere in the row other than the check box or the Investigation ID value. The details flyout that opens is the Email summary panel, but Open email entity isn't available at the top of the flyout.

The following message information is available at the top of the Email summary panel:

Tip

To see details about other messages without leaving the Email summary panel of the current message, use Previous item and Next item at the top of the flyout.

The following sections are available on the Email summary panel for all features (it doesn't matter where you opened the Email summary panel from):

Screenshot of the Email summary panel after selecting an email message in a supported Defender for Office 365 feature.