Skip to content
Browse all topics
Microsoft Defender (Security)

Microsoft Defender for Endpoint explained

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

Defender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.

6 min read

Share as imagePNG

Microsoft Defender for Endpoint (MDE) is Microsoft's endpoint detection and response (EDR) platform, layered with attack surface reduction, threat and vulnerability management, and (on the right plans) advanced hunting. It runs on Windows, macOS, Linux, iOS, and Android, with a single cloud-managed console.

What MDE does

  • Antivirus and antimalware via Microsoft Defender Antivirus (the built-in Windows AV).
  • Endpoint detection and response — behavioural detections, alerts, automated investigation.
  • Threat and Vulnerability Management (TVM) — software inventory, vulnerability findings (CVE), and recommendations prioritised by exposure.
  • Attack Surface Reduction (ASR) rules — granular policies that block common attack techniques (macro abuse, credential theft, lateral movement scripts).
  • Web protection — URL filtering and Microsoft Defender SmartScreen integration.
  • Network protection — block connections to malicious IPs and domains.
  • Device control — control USB devices and removable media.
  • Tamper protection — prevent attackers from disabling defences.
  • Live Response — remote shell into a compromised endpoint for investigation.

Plans

  • MDE Plan 1 — protection only: antivirus, ASR rules, web/network protection, device control.
  • MDE Plan 2 — adds full EDR, TVM, advanced hunting, Live Response, AIR.
  • MDE for Servers — covers Windows Server and Linux workloads; integrates with Defender for Cloud for Azure-hosted workloads.
  • MDE for Business — the SMB-targeted SKU bundled with Microsoft 365 Business Premium.

Plan 2 is included with Microsoft 365 E5, Microsoft 365 E5 Security, and as a standalone SKU.

Onboarding

Devices are onboarded to MDE through one of several methods:

  • Intune for managed Windows, Mac, iOS, Android.
  • Group Policy or Configuration Manager for traditional Windows fleets.
  • Local script for one-offs.
  • Defender for Cloud auto-provisioning for Azure VMs.

Once onboarded, the device appears in the Defender XDR portal at security.microsoft.com.

Integration with the rest of Defender

MDE's real power emerges when it feeds Microsoft Defender XDR. Alerts from MDE correlate with Defender for Office 365 (phishing detection), Defender for Identity (lateral movement on AD), and Defender for Cloud Apps (anomalous SaaS access) into unified incidents. AIR can automatically isolate a device, soft-delete malicious emails, and disable the compromised user — all from one investigation.

There's one class of device MDE's agent can't reach: OT, ICS, and IoT equipment — controllers, sensors, medical devices, building automation — where installing an agent is impossible or voids support. That's where Microsoft Defender for IoT picks up, with agentless network monitoring that feeds the same Defender XDR incidents. If you have MDE Plan 2, its enterprise IoT security mode also extends discovery to printers, VoIP phones, and smart TVs on the corporate network without any sensor hardware.

What good looks like

  • Every Windows, Mac, Linux endpoint onboarded.
  • ASR rules deployed in audit mode first, then block for confirmed-safe rules.
  • Tamper protection on, with monitoring for any device that turns it off.
  • TVM remediation findings driving the patching backlog.
  • Conditional Access using device compliance to gate cloud apps.

MDE is one of the strongest EDR products on the market and the natural choice for Microsoft 365 customers — no extra agent, integrated identity, unified telemetry.

A worked example: 400 devices, mixed Windows + macOS + Linux servers

A firm with 300 Windows 11 laptops, 60 macOS laptops, and 40 Linux servers. The onboarding sequence that works cleanly:

  • Windows. Onboard via Intune configuration profile — the Defender for Endpoint policy in Endpoint Security. The devices are already Entra-joined and MDM-managed, so it's a policy assignment; the client already ships with the Defender antimalware engine.
  • macOS. Onboard via Intune's macOS Defender for Endpoint deployment (Microsoft's MDM package + onboarding blob). Approve the system extensions in an Endpoint Protection profile and full-disk-access in a Privacy Preferences profile — miss either and Defender runs blind. See Defender for Endpoint on macOS.
  • Linux servers. Package via the client's config-management tool (Ansible/Salt) and the Microsoft-provided script; onboarding blob per-tenant. Only on distributions Microsoft supports (RHEL, Ubuntu LTS, Debian, SLES) — anything else is technically off-list. See Defender for Endpoint on Linux.
  • Tuning window. Two weeks in audit / no-block posture. Feed the exclusions from historical AV back in (antivirus exclusions), tune ASR rules from audit to block one rule at a time (attack disruption).
  • First incident review. Run a controlled EICAR test + a benign-but-suspicious script on one device per platform to confirm end-to-end signal reaches the XDR portal, generates an alert, and rolls up into an incident.

Decision matrix: which Defender for Endpoint plan

| Situation | Buy | | --- | --- | | Included with Microsoft 365 E3 or Business Premium | Plan 1 (attack surface reduction, next-gen antivirus, manual response actions, some device inventory) | | Included with Microsoft 365 E5 | Plan 2 (adds EDR, advanced hunting, auto-investigation & response, threat & vulnerability management) | | SMB (up to 300 users) on Business Premium | Defender for Business — different SKU, similar functionality, simpler console | | Servers | Defender for Servers via Defender for Cloud (P1 or P2) — Endpoint is only for user devices | | Third-party AV incumbent you can't yank yet | EDR in block mode on Plan 2 — Defender runs behind the incumbent and blocks post-breach behaviours only | | Non-standard OS (older Windows Server, unsupported Linux) | Not a fit — accept the coverage gap or use a third-party |

When Defender for Endpoint is the wrong tool

  • You have no plan to review alerts. Defender generates high-quality alerts, but the SOC (or an MSSP) has to work them. Without that, dwell time stays high and Defender's telemetry is receipts nobody reads.
  • You need FIM/DLP-on-endpoint at the level of a full DLP suite. Endpoint DLP in Purview covers a lot; a specialist DLP vendor may still win in regulated verticals — that's a separate procurement.
  • You need coverage on unsupported OS/hardware. OT devices, embedded Windows CE, air-gapped Linux distros not on the support list. Pick a specialist vendor.
  • You need consumer-grade device hygiene without a tenant. Defender for Endpoint requires Entra ID and a licensed device. For personal devices, Microsoft Defender (consumer) is the product.

MSP checklist

  • Baseline profile per platform. Windows, macOS, Linux baselines held as source-controlled Intune configuration profile exports, applied identically across all client tenants of the same tier.
  • ASR rules ladder. Every new tenant starts in audit for all Microsoft-recommended ASR rules; move to block one rule at a time on a two-week cadence, reviewing false-positive rate against exceptions before promotion.
  • Onboarding-drift report. Weekly per-client: devices seen in Entra ID or Intune but not onboarded to Defender for Endpoint. This is the number that grows silently when a new device baseline goes out with the onboarding blob missing.
  • Multi-tenant view. Defender XDR does not have a native cross-tenant single-pane. Use Microsoft 365 Lighthouse for the M365-scope security posture roll-up and Sentinel multi-workspace for pooled hunting.
  • Incident runbook per plan tier. Client without a SOC = MSSP or in-house runbook covering triage, containment, communication. Client with their own SOC = documented handoff.

Frequently asked questions

What does Defender for Endpoint Plan 1 include versus Plan 2?
Plan 1 (in E3): next-generation protection, attack surface reduction rules, device control, manual response actions, and centralised management. Plan 2 (in E5, E5 Security): everything in P1 plus EDR, automated investigation and response, advanced hunting, threat analytics, vulnerability management, and Defender Experts eligibility.
How do I onboard devices to Defender for Endpoint?
Windows via Intune (the endpoint security onboarding policy), Group Policy, Configuration Manager, or a local script; macOS and Linux via an installer package and onboarding profile; mobile via the Defender app with Intune app configuration. Windows Server uses the same onboarding as clients on 2019+ and the unified agent on older versions.
Can Defender for Endpoint run alongside another antivirus?
Yes. When a non-Microsoft antivirus is the primary, Defender Antivirus goes into passive mode and Defender for Endpoint can still run EDR in block mode, providing detection and response behind the other product. Two active antimalware engines are not supported.

Further reading

Was this useful?

Spot something wrong or want a topic covered? Send it through the contact form.