Identity and security

Defender

Microsoft Defender XDR

Microsoft Defender XDR is the unifying layer that sits above Microsoft's individual security products, Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps.

Why Defender matters in a Microsoft estate

Defender matters because identity, access, endpoint, and data controls shape how Microsoft environments are protected. Readers should understand the term and then be able to move into security assessment, conformity, or remediation guidance.

How Defender shows up in practice

It correlates their separate alert streams into a single incident, rather than leaving analysts to manually piece together fragments from four different consoles. The underlying idea behind extended detection and response is that a real attack rarely stays confined to one layer. A phishing email that delivers a malicious attachment, which then runs on an endpoint, which then uses stolen credentials to move laterally through the identity layer, generates alerts in three separate products. Without correlation, those alerts look like three unrelated low-priority events rather than one coherent attack chain. Defender XDR's incident graph automatically links related alerts, affected users, devices, and mailboxes into a single 'attack story' with a unified severity and priority.

Its automated investigation and response capability can, depending on configuration, automatically remediate common patterns such as isolating a compromised device or removing a malicious email from every inbox it reached, without waiting for a human to correlate the same evidence manually. All of this is accessed through the unified Microsoft Defender portal at security.microsoft.com, which has progressively absorbed what used to be separate admin experiences for each Defender product. The same portal also surfaces Microsoft Secure Score, threat analytics, and hunting queries written in the same Kusto-based query language used across the suite. For organisations running a security operations function, Defender XDR data flows into Microsoft Sentinel for longer-term retention, cross-product correlation with non-Microsoft signals, and SIEM-style investigation.

The two products are generally deployed together rather than as alternatives: Defender XDR handles fast, product-native detection and response, while Sentinel adds broader analytics and case management. Licensing is the detail that most often trips organisations up, since full XDR capability, rather than the baseline protection bundled into standard Microsoft 365 plans, generally requires Microsoft 365 E5 or the equivalent standalone add-ons for each underlying Defender product. This means an organisation can appear to have 'Defender' enabled while actually running well below the licence tier needed for automated investigation, advanced hunting, or the full incident correlation the platform is designed around. The resulting alert fatigue from unlinked, per-product alerts is often the first practical symptom of that gap.

Glossary