Browse all topics▾
Microsoft 365 Copilot
Power Platform
Microsoft Teams
SharePoint & OneDrive
Exchange & Outlook
Microsoft Entra (Identity)
- Adding a named location without breaking Conditional Access
- App consent policies and the admin consent workflow
- Assigning licenses with group-based licensing in Entra ID
- Cleaning up over-consented app permissions
- Cleaning up unused enterprise apps in Entra ID
- Compromised Microsoft 365 account response runbook
- + 52 more →
Microsoft Defender (Security)
Microsoft Purview (Compliance)
Microsoft Intune (Devices)
Viva & Apps
Developer & APIs
Migration & Tenants
Microsoft Defender (Security)
Defender XDR, Endpoint, Office 365, Identity, and Sentinel. 34 guides in this topic.
Recently reviewed
- Attack Simulation Training in Defender for Office 365How to run controlled phishing simulations and embedded training to harden users against real attacks.
- Business Email Compromise response playbookHow to respond to a confirmed BEC incident in Microsoft 365 — containment, investigation, remediation, and prevention.
- Defender Attack DisruptionAutomatic Attack Disruption is Defender XDR's ability to contain in-progress attacks automatically — what it does and how.
- Defender External Attack Surface ManagementReviewed 2026-09-05Defender EASM discovers your organisation's internet-facing assets — including the ones you didn't know about.
- Defender for Endpoint on LinuxDeploying Microsoft Defender for Endpoint on Linux servers and workstations — distributions, packaging, and integration.
- Defender for Endpoint on macOSDeploying and managing Microsoft Defender for Endpoint on Mac fleets via Intune.
- Defender for Endpoint vs CrowdStrikeComparisonDefender for Endpoint vs CrowdStrike Falcon: detection quality, platform coverage, the SOC experience, licensing, and what the July 2024 outage changed.
- Defender for Endpoint vs SentinelOneComparisonDefender for Endpoint vs SentinelOne Singularity: autonomous response and rollback vs Microsoft XDR correlation, platform coverage, MSP fit, and licensing.
- Defender for Office 365 quarantine workflowHow users and admins work with quarantine — release, request, report, and the policy decisions behind it.
- Defender Threat IntelligenceHow Microsoft Defender XDR integrates threat intelligence — built-in feeds, custom IoCs, and Defender TI as a separate product.
- Defender Vulnerability ManagementHow Defender for Endpoint's vulnerability management surfaces CVEs, misconfigurations, and prioritises remediation.
- Defender XDR advanced hunting workshopHow to use Defender XDR advanced hunting effectively — tables, common queries, and threat-hunting patterns.
- Defender XDR and attack-surface managementReviewed 2026-08-30How Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.
- How to block a compromised account in Microsoft 365How-toHow to block a compromised Microsoft 365 account in ten minutes: disable sign-in, revoke sessions, reset password and MFA, kill inbox rules and forwarding.
- Investigating a phishing message that got past defencesRunbook for a phish that landed: find every copy, purge it from mailboxes, find who clicked, submit it so filters learn, and work out why it got through.
- KQL primer for Defender XDRA practical introduction to Kusto Query Language for Microsoft Defender XDR and Sentinel hunting.
- Microsoft 365 security and complianceA practical tour of the Microsoft 365 security and compliance stack — Defender, Purview, Entra, and how they fit together.
- Microsoft 365 security baselinesThe minimum security configuration every Microsoft 365 tenant should have — and how to get there.
- Microsoft Defender Antivirus configurationHow to configure Microsoft Defender Antivirus for Windows endpoints — the settings that matter and how to manage them.
- Microsoft Defender Antivirus exclusions designHow to design Defender Antivirus exclusions safely — minimising scope while accommodating legitimate application needs.
- Microsoft Defender for BusinessDefender for Business is the SMB-targeted EDR product bundled with Microsoft 365 Business Premium.
- Microsoft Defender for Cloud Apps explainedDefender for Cloud Apps is Microsoft's CASB — discovering, monitoring, and controlling SaaS app usage.
- Microsoft Defender for Endpoint explainedReviewed 2026-08-30Defender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.
- Microsoft Defender for Identity explainedDefender for Identity detects identity-based attacks against on-prem Active Directory and Entra ID. Here's how it works.
- Microsoft Defender for Identity sensor deploymentHow to plan and roll out Defender for Identity sensors — DCs, AD FS, Entra Connect, and tuning.
- Microsoft Defender for IoT explainedDefender for IoT secures the devices EDR can't reach — OT, ICS, and IoT. Here's how it works and when it's worth deploying.
- Microsoft Defender for Office 365 explainedReviewed 2026-08-31What Defender for Office 365 adds on top of EOP — Safe Links, Safe Attachments, AIR, attack simulation — plus Plan 1 vs Plan 2 and the settings worth tuning.
- Microsoft Sentinel analytic rulesHow analytic rules work in Sentinel — types, tuning, and writing custom detections.
- Microsoft Sentinel cost optimisationHow to control Microsoft Sentinel costs — ingestion tuning, commitment tiers, retention, and data tiering.
- Microsoft Sentinel for Microsoft 365How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.
- Microsoft Sentinel onboardingHow to onboard Microsoft Sentinel — workspace setup, data connectors, and starting analytic rules.
- Ransomware preparedness for Microsoft 365How to harden a Microsoft 365 tenant against ransomware — prevention, detection, response, and recovery.
- Which Microsoft Defender is whichWhich Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it.
- Zero trust in Microsoft 365What zero trust actually means in a Microsoft 365 context — and the concrete controls that get you there.
Frequently asked
- What is Microsoft Defender XDR?
- Defender XDR is the unified investigation and response experience across Defender for Endpoint, Office 365, Identity, and Cloud Apps. It correlates signals into incidents so an analyst works on one queue instead of four consoles.
- Do I need Microsoft Sentinel if I already have Defender XDR?
- Sentinel adds cloud-native SIEM capabilities (long-term retention, custom analytics, third-party data sources) on top of XDR. Small tenants that only ingest Microsoft signals often run XDR alone; anything with third-party sources or 90+ day investigation needs generally adds Sentinel.
- What licence unlocks Defender for Endpoint?
- Defender for Endpoint Plan 1 is included in Microsoft 365 E3 and Business Premium. Plan 2 (auto-investigation, advanced hunting, EDR block mode) is in Microsoft 365 E5 or purchasable as a standalone add-on.
- Where does Copilot for Security fit?
- Copilot for Security is a separately-licensed capacity SKU that augments XDR and Sentinel workflows: incident summarisation, KQL generation, guided investigation. It is not required for XDR or Sentinel to function.
Looking for something else? Browse all guides.