MC1478005 - Microsoft Defender for Office 365: View approver details for remediation actions in Advanced Hunting
Microsoft 365 Message Center announcement MC1478005.
MS Message Center's Summary
Microsoft is rolling out a new ApproverUpn column in the EmailPostDeliveryEvents table within Advanced Hunting for Microsoft Defender XDR. This addition allows security teams to identify who approved remediation actions directly in query results. The feature is available worldwide now by default. Administrators should review existing queries and inform security operations teams about this capability.
- Administrator impact
- No direct administrator action is required.
- End user impact
- No direct end user impact is expected.
- Importance
- 3/10: The update provides a helpful schema enhancement for security investigations without requiring any administrative intervention or causing service disruption.
EmailPostDeliveryEvents table in the advanced hunting schema
Microsoft Summary
Microsoft Defender for Office 365 added an ApproverUpn column to the EmailPostDeliveryEvents table in Advanced Hunting, showing who approved remediation actions. This enables faster investigations without using Action Center. The feature is available worldwide, enabled by default, and requires no action from administrators.
- Message Center ID
- MC1478005
- Category
- plan For Change
- Severity
- normal
- Services
- Microsoft Defender XDR
- Tags
- Feature update, User impact, Admin impact
- Published
- 2026-09-23
- Last updated
- 2026-09-23
- Expires
- 2026-10-21
[What and why] We've added a new ApproverUpn column to the EmailPostDeliveryEvents table in Microsoft Defender XDR Advanced Hunting . This enhancement allows security teams to identify who approved eligible remediation actions directly from Advanced Hunting results. By making approver information available in hunting queries, analysts can investigate remediation activity more efficiently without needing to navigate to Action Center. This improvement supports faster security investigations and operational efficiency. [Rollout schedule] General Availability (Worldwide, GCC, GCC High, DoD): Available now [Impact on your organization] Who is affected Security administrators and security analysts who use Microsoft Defender XDR Advanced Hunting Organizations that investigate email remediation activity using Advanced Hunting Platforms and services Microsoft Defender XDR Advanced Hunting EmailPostDeliveryEvents table What will happen A new ApproverUpn column is added to the EmailPostDeliveryEvents table. The column displays the User Principal Name (UPN) of the user who approved a remediation action. The enhancement applies to manual remediation actions and Automated Investigation and Response (AIR) remediation actions that require approval. Advanced Hunting query results include approver information for eligible remediation actions. Administrators and analysts can identify the approver for eligible remediation actions directly in Advanced Hunting results without navigating to Action Center. The feature is enabled by default and is automatically available in your tenant. There are no changes to: Manual remediation approval workflows Permissions required to approve remediation actions Remediation processing behavior or action status Information available in Action Center Existing columns in the EmailPostDeliveryEvents table [Action required and recommendations] No action is required. After rollout, administrators can begin using the new ApproverUpn column in Advanced Hunting queries and workflows . We recommend that you: Review existing Advanced Hunting queries to determine whether the new ApproverUpn field should be incorporated into investigation, reporting, or automation workflows. Inform security operations teams about the availability of the new column. Validate any investigation workflows, reports, or automation that could benefit from the new ApproverUpn field. Learn more EmailPostDeliveryEvents table in the advanced hunting schema - Microsoft Defender XDR | Microsoft Learn [Compliance considerations] No compliance considerations identified, review as appropriate for your organization.