Glossary
Defender
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
Microsoft's family of threat-protection products, unified under Microsoft Defender XDR.
Microsoft Defender is Microsoft's family of threat-protection products, unified under Microsoft Defender XDR. The main components are Defender for Office 365 (safer links and attachments, anti-phishing), Defender for Endpoint (EDR for Windows, macOS, Linux, iOS, and Android), Defender for Identity (detection of identity-based attacks against AD and Entra ID), and Defender for Cloud Apps (CASB for SaaS apps). Signals from each component feed a unified incident view at security.microsoft.com. Some Defender capabilities are included in Microsoft 365 E5 and Business Premium; others are sold as standalone add-ons or part of the broader Microsoft Sentinel/Defender stack.
Worked example
A phishing email slips past initial filtering and a user clicks a malicious link. Safe Links (part of Defender for Office 365) flags the click as risky in real time; Defender for Endpoint on the user's laptop detects the resulting malware trying to run and isolates the device; Defender for Identity notices an unusual authentication pattern from that same user's account shortly after. Rather than three separate, disconnected alerts an analyst has to manually piece together, Defender XDR automatically correlates all three signals into a single incident, showing the whole attack chain — email, device, identity — as one connected story.
Common pitfalls
Buying one Defender component (commonly Defender for Endpoint) and assuming it covers "security" broadly is a common licensing misunderstanding — each component protects a different layer (email, device, identity, SaaS apps), and gaps in coverage are genuine blind spots, not redundant overlap. Treating the individual Defender portals as separate tools to check one at a time, rather than working primarily from the unified Defender XDR incident view, throws away the correlation that's the whole point of the "XDR" in the name. And assuming every Defender capability is already included in a Microsoft 365 E5 licence trips people up at renewal time — some components (certain Defender for Cloud workload types, higher Defender for Endpoint tiers) are separately licensed add-ons even for E5 tenants.