Microsoft Defender (Security)
Defender XDR, Endpoint, Office 365, Identity, and Sentinel. 30 guides in this topic.
- Attack Simulation Training in Defender for Office 365How to run controlled phishing simulations and embedded training to harden users against real attacks.
- Business Email Compromise response playbookHow to respond to a confirmed BEC incident in Microsoft 365 — containment, investigation, remediation, and prevention.
- Defender Attack DisruptionAutomatic Attack Disruption is Defender XDR's ability to contain in-progress attacks automatically — what it does and how.
- Defender External Attack Surface ManagementDefender EASM discovers your organisation's internet-facing assets — including the ones you didn't know about.
- Defender for Endpoint on LinuxDeploying Microsoft Defender for Endpoint on Linux servers and workstations — distributions, packaging, and integration.
- Defender for Endpoint on macOSDeploying and managing Microsoft Defender for Endpoint on Mac fleets via Intune.
- Defender for Office 365 quarantine workflowHow users and admins work with quarantine — release, request, report, and the policy decisions behind it.
- Defender Threat IntelligenceHow Microsoft Defender XDR integrates threat intelligence — built-in feeds, custom IoCs, and Defender TI as a separate product.
- Defender Vulnerability ManagementHow Defender for Endpoint's vulnerability management surfaces CVEs, misconfigurations, and prioritises remediation.
- Defender XDR advanced hunting workshopHow to use Defender XDR advanced hunting effectively — tables, common queries, and threat-hunting patterns.
- Defender XDR and attack-surface managementHow Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.
- KQL primer for Defender XDRA practical introduction to Kusto Query Language for Microsoft Defender XDR and Sentinel hunting.
- Microsoft 365 security and complianceA practical tour of the Microsoft 365 security and compliance stack — Defender, Purview, Entra, and how they fit together.
- Microsoft 365 security baselinesThe minimum security configuration every Microsoft 365 tenant should have — and how to get there.
- Microsoft Defender Antivirus configurationHow to configure Microsoft Defender Antivirus for Windows endpoints — the settings that matter and how to manage them.
- Microsoft Defender Antivirus exclusions designHow to design Defender Antivirus exclusions safely — minimising scope while accommodating legitimate application needs.
- Microsoft Defender for BusinessDefender for Business is the SMB-targeted EDR product bundled with Microsoft 365 Business Premium.
- Microsoft Defender for Cloud Apps explainedDefender for Cloud Apps is Microsoft's CASB — discovering, monitoring, and controlling SaaS app usage.
- Microsoft Defender for Endpoint explainedDefender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.
- Microsoft Defender for Identity explainedDefender for Identity detects identity-based attacks against on-prem Active Directory and Entra ID. Here's how it works.
- Microsoft Defender for Identity sensor deploymentHow to plan and roll out Defender for Identity sensors — DCs, AD FS, Entra Connect, and tuning.
- Microsoft Defender for IoT explainedDefender for IoT secures the devices EDR can't reach — OT, ICS, and IoT. Here's how it works and when it's worth deploying.
- Microsoft Defender for Office 365 explainedWhat Defender for Office 365 adds on top of EOP — Safe Links, Safe Attachments, AIR, attack simulation — plus Plan 1 vs Plan 2 and the settings worth tuning.
- Microsoft Sentinel analytic rulesHow analytic rules work in Sentinel — types, tuning, and writing custom detections.
- Microsoft Sentinel cost optimisationHow to control Microsoft Sentinel costs — ingestion tuning, commitment tiers, retention, and data tiering.
- Microsoft Sentinel for Microsoft 365How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.
- Microsoft Sentinel onboardingHow to onboard Microsoft Sentinel — workspace setup, data connectors, and starting analytic rules.
- Ransomware preparedness for Microsoft 365How to harden a Microsoft 365 tenant against ransomware — prevention, detection, response, and recovery.
- Which Microsoft Defender is whichMicrosoft ships at least ten products called Defender. A field guide to the whole family — Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus, and the rest — what each one actually does, and which licence gets you what.
- Zero trust in Microsoft 365What zero trust actually means in a Microsoft 365 context — and the concrete controls that get you there.
Looking for something else? Browse all guides.