Identity and security
Defender for Endpoint
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is Microsoft's endpoint protection platform and EDR product, combining preventative antivirus and attack surface reduction with continuous behavioural monitoring and investigation capability under a single lightweight sensor built into modern Windows and available as an installable agent for macOS, Linux, iOS, and Android.
Why Defender for Endpoint matters in a Microsoft estate
Defender for Endpoint matters because identity, access, endpoint, and data controls shape how Microsoft environments are protected. Readers should understand the term and then be able to move into security assessment, conformity, or remediation guidance.
How Defender for Endpoint shows up in practice
That gives organisations one console covering their genuinely mixed-OS device estate rather than a separate tool per platform. It is licensed in two meaningfully different tiers: Plan 1 covers next-generation antivirus, attack surface reduction rules that block specific behavioural patterns commonly abused for exploitation, such as Office applications spawning child processes, and basic manual response actions, while Plan 2 adds the full EDR capability the product is best known for, behavioural sensors that reconstruct an attack timeline across process, file, network, and registry activity, automated investigation and remediation that can act on common patterns without waiting for analyst intervention, threat and vulnerability management that continuously inventories software and known CVEs across the device estate, and live response, a direct remote investigation and remediation session on an affected device.
Device onboarding is where deployments most often develop silent coverage gaps: devices enrolled through Intune, Group Policy, a manual onboarding script, or a third-party RMM integration get the sensor and appear in the device inventory, but any device missed by whichever onboarding mechanism an organisation relies on sits completely outside visibility, generates no alert to flag its own absence, and can go unnoticed for months. That is precisely the kind of gap that gets discovered only during an actual incident when a compromised device turns out never to have been reporting in the first place.
Tamper protection locks core security settings against being disabled locally, including by a user with local administrative rights, which matters directly against ransomware and other malware families that routinely attempt to disable endpoint defences as one of their first actions after gaining a foothold. Defender for Endpoint integrates closely with device compliance policies in Intune, so a device's real-time risk level as assessed by Defender for Endpoint can feed directly into Conditional Access decisions. A device that develops active malware detections can be automatically marked non-compliant and lose access to corporate resources without requiring a manual response step, and it forms the endpoint pillar of Defender XDR, contributing telemetry and alerts that get automatically correlated with identity, email, and cloud app signals into unified incidents rather than sitting in an isolated endpoint-only view.