Home > Blog > Microsoft 365 Administrator > Navigating Threat Analytics and Threat Explorer in MS-102

Navigating Threat Analytics and Threat Explorer in MS-102

Deep Dive Cert Sensei Team 2026-09-02 8 min read

Threat Analytics is an in-product threat intelligence solution from expert Microsoft security researchers, providing detailed reports on active threat campaigns. Threat Explorer is a powerful investigation tool used to analyze and track threats across email and collaboration platforms.

#Threat Analytics #Threat Explorer #MS-102 #Security Management #Cybersecurity

Leveraging Threat Analytics

Threat Analytics provides high-level executive summaries alongside detailed technical information about ongoing cyberattacks worldwide.

Administrators use it to assess their organization's specific exposure to a threat campaign and apply recommended mitigations directly from the portal.

Hunting with Threat Explorer

Threat Explorer (or Real-time detections) allows security teams to investigate email and collaboration threats.

You can search by sender, recipient, subject, or malware family, making it an indispensable tool for tracking phishing campaigns that may have bypassed initial filters.

Remediation Actions from Explorer

Threat Explorer isn't just for visibility; it's an operational tool. From within Explorer, you can trigger remediation actions.

For the MS-102 exam, know how to use Explorer to soft delete malicious emails, trigger automated investigations, or report false positives to Microsoft.

Proactive Security Exam Tips

Microsoft expects modern administrators to be proactive, not just reactive, which is why these tools feature prominently on the exam.

To build muscle memory on when to use Analytics versus Explorer, supplement your Microsoft Learn reading with high-quality practice exams like Cert Sensei.

❓ Frequently Asked Questions

What kind of information does Threat Analytics provide?

It provides executive summaries and technical details about ongoing cyberattacks worldwide, written by Microsoft security researchers.


How is Threat Explorer used in Microsoft 365 Defender?

It is a powerful investigation tool used to analyze and track threats across email and collaboration platforms.


Can I take remediation actions directly from Threat Explorer?

Yes, you can trigger actions like soft deleting malicious emails or reporting false positives directly from the Explorer interface.

More from Microsoft 365 Administrator

🧠

Test Your Knowledge

Ready to practice 365 Administrator? Put what you've learned to the test.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium
📖 Browse the Glossary

Join thousands of certification students

Sign Up Free