Skip to content
Browse all topics

Microsoft Defender (Security)

Defender XDR, Endpoint, Office 365, Identity, and Sentinel. 34 guides in this topic.

Recently reviewed

Frequently asked

What is Microsoft Defender XDR?
Defender XDR is the unified investigation and response experience across Defender for Endpoint, Office 365, Identity, and Cloud Apps. It correlates signals into incidents so an analyst works on one queue instead of four consoles.
Do I need Microsoft Sentinel if I already have Defender XDR?
Sentinel adds cloud-native SIEM capabilities (long-term retention, custom analytics, third-party data sources) on top of XDR. Small tenants that only ingest Microsoft signals often run XDR alone; anything with third-party sources or 90+ day investigation needs generally adds Sentinel.
What licence unlocks Defender for Endpoint?
Defender for Endpoint Plan 1 is included in Microsoft 365 E3 and Business Premium. Plan 2 (auto-investigation, advanced hunting, EDR block mode) is in Microsoft 365 E5 or purchasable as a standalone add-on.
Where does Copilot for Security fit?
Copilot for Security is a separately-licensed capacity SKU that augments XDR and Sentinel workflows: incident summarisation, KQL generation, guided investigation. It is not required for XDR or Sentinel to function.

Looking for something else? Browse all guides.