<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>Solving Microsoft 365 — Microsoft Defender (Security)</title>
<link>https://www.solvingmicrosoft365.com/guides/category/security</link>
<description>New and reviewed Microsoft Defender (Security) guides. Defender XDR, Endpoint, Office 365, Identity, and Sentinel.</description>
<language>en</language>
<generator>Solving Microsoft 365</generator>
<atom:link href="https://www.solvingmicrosoft365.com/guides/category/security/feed.xml" rel="self" type="application/rss+xml" />
<lastBuildDate>Sat, 05 Sep 2026 08:00:00 GMT</lastBuildDate>
<item>
<title>Reviewed: Defender External Attack Surface Management</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-external-attack-surface-management</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-external-attack-surface-management#2026-09-05</guid>
<pubDate>Sat, 05 Sep 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Defender EASM discovers your organisation&apos;s internet-facing assets — including the ones you didn&apos;t know about.</description>
</item>
<item>
<title>How to block a compromised account in Microsoft 365</title>
<link>https://www.solvingmicrosoft365.com/guides/how-to-block-a-compromised-account-in-microsoft-365</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/how-to-block-a-compromised-account-in-microsoft-365#2026-09-03</guid>
<pubDate>Thu, 03 Sep 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How to block a compromised Microsoft 365 account in ten minutes: disable sign-in, revoke sessions, reset password and MFA, kill inbox rules and forwarding.</description>
</item>
<item>
<title>Defender for Endpoint vs SentinelOne</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-vs-sentinelone</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-vs-sentinelone#2026-09-03</guid>
<pubDate>Thu, 03 Sep 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Defender for Endpoint vs SentinelOne Singularity: autonomous response and rollback vs Microsoft XDR correlation, platform coverage, MSP fit, and licensing.</description>
</item>
<item>
<title>Defender for Endpoint vs CrowdStrike</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-vs-crowdstrike</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-vs-crowdstrike#2026-09-03</guid>
<pubDate>Thu, 03 Sep 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Defender for Endpoint vs CrowdStrike Falcon: detection quality, platform coverage, the SOC experience, licensing, and what the July 2024 outage changed.</description>
</item>
<item>
<title>Investigating a phishing message that got past defences</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-phishing-message-investigation-runbook</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-phishing-message-investigation-runbook#2026-09-02</guid>
<pubDate>Wed, 02 Sep 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Runbook for a phish that landed: find every copy, purge it from mailboxes, find who clicked, submit it so filters learn, and work out why it got through.</description>
</item>
<item>
<title>Reviewed: Microsoft Defender for Office 365 explained</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-for-office-365-explained</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-for-office-365-explained#2026-08-31</guid>
<pubDate>Mon, 31 Aug 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>What Defender for Office 365 adds on top of EOP — Safe Links, Safe Attachments, AIR, attack simulation — plus Plan 1 vs Plan 2 and the settings worth tuning.</description>
</item>
<item>
<title>Which Microsoft Defender is which</title>
<link>https://www.solvingmicrosoft365.com/guides/microsoft-defender-products-explained</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/microsoft-defender-products-explained#2026-08-30</guid>
<pubDate>Sun, 30 Aug 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Which Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it.</description>
</item>
<item>
<title>Reviewed: Defender XDR and attack-surface management</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-xdr-and-attack-surface</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-xdr-and-attack-surface#2026-08-30</guid>
<pubDate>Sun, 30 Aug 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.</description>
</item>
<item>
<title>Microsoft Defender for IoT explained</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-for-iot-explained</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-for-iot-explained#2026-08-30</guid>
<pubDate>Sun, 30 Aug 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Defender for IoT secures the devices EDR can&apos;t reach — OT, ICS, and IoT. Here&apos;s how it works and when it&apos;s worth deploying.</description>
</item>
<item>
<title>Reviewed: Microsoft Defender for Endpoint explained</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-explained</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-explained#2026-08-30</guid>
<pubDate>Sun, 30 Aug 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Defender for Endpoint is Microsoft&apos;s EDR/XDR platform for laptops, servers, and mobile. Here&apos;s what it does.</description>
</item>
<item>
<title>Zero trust in Microsoft 365</title>
<link>https://www.solvingmicrosoft365.com/guides/zero-trust-in-microsoft-365</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/zero-trust-in-microsoft-365#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>What zero trust actually means in a Microsoft 365 context — and the concrete controls that get you there.</description>
</item>
<item>
<title>Microsoft Sentinel analytic rules</title>
<link>https://www.solvingmicrosoft365.com/guides/sentinel-analytic-rules</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/sentinel-analytic-rules#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How analytic rules work in Sentinel — types, tuning, and writing custom detections.</description>
</item>
<item>
<title>Ransomware preparedness for Microsoft 365</title>
<link>https://www.solvingmicrosoft365.com/guides/ransomware-preparedness-for-microsoft-365</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/ransomware-preparedness-for-microsoft-365#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How to harden a Microsoft 365 tenant against ransomware — prevention, detection, response, and recovery.</description>
</item>
<item>
<title>Microsoft Sentinel onboarding</title>
<link>https://www.solvingmicrosoft365.com/guides/microsoft-sentinel-onboarding</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/microsoft-sentinel-onboarding#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How to onboard Microsoft Sentinel — workspace setup, data connectors, and starting analytic rules.</description>
</item>
<item>
<title>Microsoft Sentinel for Microsoft 365</title>
<link>https://www.solvingmicrosoft365.com/guides/microsoft-sentinel-for-microsoft-365</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/microsoft-sentinel-for-microsoft-365#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.</description>
</item>
<item>
<title>Microsoft Sentinel cost optimisation</title>
<link>https://www.solvingmicrosoft365.com/guides/microsoft-sentinel-cost-optimization</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/microsoft-sentinel-cost-optimization#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How to control Microsoft Sentinel costs — ingestion tuning, commitment tiers, retention, and data tiering.</description>
</item>
<item>
<title>Microsoft Defender for Identity sensor deployment</title>
<link>https://www.solvingmicrosoft365.com/guides/microsoft-defender-for-identity-deployment</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/microsoft-defender-for-identity-deployment#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How to plan and roll out Defender for Identity sensors — DCs, AD FS, Entra Connect, and tuning.</description>
</item>
<item>
<title>Microsoft 365 security baselines</title>
<link>https://www.solvingmicrosoft365.com/guides/microsoft-365-security-baselines</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/microsoft-365-security-baselines#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>The minimum security configuration every Microsoft 365 tenant should have — and how to get there.</description>
</item>
<item>
<title>Microsoft 365 security and compliance</title>
<link>https://www.solvingmicrosoft365.com/guides/microsoft-365-security-and-compliance</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/microsoft-365-security-and-compliance#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>A practical tour of the Microsoft 365 security and compliance stack — Defender, Purview, Entra, and how they fit together.</description>
</item>
<item>
<title>KQL primer for Defender XDR</title>
<link>https://www.solvingmicrosoft365.com/guides/kql-primer-for-defender-xdr</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/kql-primer-for-defender-xdr#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>A practical introduction to Kusto Query Language for Microsoft Defender XDR and Sentinel hunting.</description>
</item>
<item>
<title>Defender XDR advanced hunting workshop</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-xdr-advanced-hunting</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-xdr-advanced-hunting#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How to use Defender XDR advanced hunting effectively — tables, common queries, and threat-hunting patterns.</description>
</item>
<item>
<title>Defender Vulnerability Management</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-vulnerability-management</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-vulnerability-management#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How Defender for Endpoint&apos;s vulnerability management surfaces CVEs, misconfigurations, and prioritises remediation.</description>
</item>
<item>
<title>Defender Threat Intelligence</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-threat-intelligence</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-threat-intelligence#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How Microsoft Defender XDR integrates threat intelligence — built-in feeds, custom IoCs, and Defender TI as a separate product.</description>
</item>
<item>
<title>Defender for Office 365 quarantine workflow</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-quarantine-workflow</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-quarantine-workflow#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How users and admins work with quarantine — release, request, report, and the policy decisions behind it.</description>
</item>
<item>
<title>Microsoft Defender for Identity explained</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-for-identity-explained</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-for-identity-explained#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Defender for Identity detects identity-based attacks against on-prem Active Directory and Entra ID. Here&apos;s how it works.</description>
</item>
<item>
<title>Defender for Endpoint on macOS</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-mac</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-mac#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Deploying and managing Microsoft Defender for Endpoint on Mac fleets via Intune.</description>
</item>
<item>
<title>Defender for Endpoint on Linux</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-linux</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-for-endpoint-linux#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Deploying Microsoft Defender for Endpoint on Linux servers and workstations — distributions, packaging, and integration.</description>
</item>
<item>
<title>Microsoft Defender for Cloud Apps explained</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-for-cloud-apps-explained</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-for-cloud-apps-explained#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Defender for Cloud Apps is Microsoft&apos;s CASB — discovering, monitoring, and controlling SaaS app usage.</description>
</item>
<item>
<title>Microsoft Defender for Business</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-for-business-explained</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-for-business-explained#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Defender for Business is the SMB-targeted EDR product bundled with Microsoft 365 Business Premium.</description>
</item>
<item>
<title>Defender Attack Disruption</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-attack-disruption</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-attack-disruption#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>Automatic Attack Disruption is Defender XDR&apos;s ability to contain in-progress attacks automatically — what it does and how.</description>
</item>
<item>
<title>Microsoft Defender Antivirus exclusions design</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-antivirus-exclusions</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-antivirus-exclusions#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How to design Defender Antivirus exclusions safely — minimising scope while accommodating legitimate application needs.</description>
</item>
<item>
<title>Microsoft Defender Antivirus configuration</title>
<link>https://www.solvingmicrosoft365.com/guides/defender-antivirus-configuration</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/defender-antivirus-configuration#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How to configure Microsoft Defender Antivirus for Windows endpoints — the settings that matter and how to manage them.</description>
</item>
<item>
<title>Business Email Compromise response playbook</title>
<link>https://www.solvingmicrosoft365.com/guides/bec-response-playbook</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/bec-response-playbook#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How to respond to a confirmed BEC incident in Microsoft 365 — containment, investigation, remediation, and prevention.</description>
</item>
<item>
<title>Attack Simulation Training in Defender for Office 365</title>
<link>https://www.solvingmicrosoft365.com/guides/attack-simulation-training</link>
<guid isPermaLink="false">https://www.solvingmicrosoft365.com/guides/attack-simulation-training#2026-05-01</guid>
<pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate>
<dc:creator>Emil Björk</dc:creator>
<category>Microsoft Defender (Security)</category>
<description>How to run controlled phishing simulations and embedded training to harden users against real attacks.</description>
</item>
</channel>
</rss>