A SOC analyst receives a phishing alert in Microsoft Defender for Office 365. The analyst needs to quickly determine if any users clicked the malicious link. Which action should the analyst take first?
The email entity page is the correct destination because it consolidates the full message record from Microsoft Defender for Office 365, including delivery status, threat name, detection technology, and the recipient-specific URL click verdict. Its Click details section explicitly indicates whether each intended recipient clicked the link, whether the click was allowed or blocked, and the time of the click, which is exactly the evidence needed to assess the impact of a phishing alert. This page is purpose-built for single-message triage and provides near-instant visibility without requiring a custom query or cross-referencing multiple data sources.
Why this answer
The email entity page in Microsoft Defender for Office 365 provides detailed information about a specific email, including click verdicts for any URLs contained within. This allows the analyst to quickly see if any users clicked the malicious link. Option A (Threat Explorer) can also be used, but it requires more steps to filter for the specific email and then view click details.
Option B (user entity page) shows user-specific activities and alerts, but not email-specific click details. Option D (hunting query in Microsoft Sentinel) is effective but slower than directly viewing the email entity page in Defender for Office 365.