Browse all topics
Microsoft Defender (Security)

Which Microsoft Defender is which

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

Microsoft ships at least ten products called Defender. A field guide to the whole family — Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus, and the rest — what each one actually does, and which licence gets you what.

Microsoft ships at least ten distinct products under the name Defender. Some are enterprise security platforms, one is a consumer app, one is the antivirus built into every Windows machine, and two have names so similar — Defender for Cloud and Defender for Cloud Apps — that they get confused in vendor meetings weekly. Nobody should feel bad about being lost here; the naming is genuinely bad.

This guide is the map: what each Defender does, how they relate, and which licence gets you which. Bookmark it for the next meeting where someone says "we already have Defender".

The four workload Defenders (the core family)

These four are the enterprise products that detect and respond to threats in a Microsoft 365 tenant. They share the Defender portal (security.microsoft.com) and feed the combined incident queue.

Microsoft Defender for Endpoint. EDR for devices — Windows, macOS, Linux, iOS, Android. Detects malicious behaviour on the machine, isolates compromised devices, supports threat hunting. This is the flagship, and the one people usually mean by "MDE". Details in Microsoft Defender for Endpoint explained. Not the same thing as the antivirus (see below) — Defender for Endpoint is the detection-and-response layer that uses the antivirus as one of its sensors.

Microsoft Defender for Office 365. Email and collaboration protection — Safe Links, Safe Attachments, anti-phishing impersonation protection, automated investigation, attack simulation training. Sits on top of the baseline Exchange Online Protection that every tenant gets. Details in Microsoft Defender for Office 365 explained.

Microsoft Defender for Identity. Watches Active Directory and Entra ID for identity attacks — pass-the-hash, kerberoasting, lateral movement, DCSync. Sensor-based: you install it on domain controllers. Details in Microsoft Defender for Identity explained.

Microsoft Defender for Cloud Apps. The CASB — discovers shadow-IT SaaS usage, applies session controls to cloud apps, scores SaaS security posture, governs OAuth app permissions. Details in Microsoft Defender for Cloud Apps explained.

Defender XDR: the umbrella, not a product you buy

Microsoft Defender XDR (formerly Microsoft 365 Defender) is not a fifth product — it is the layer that correlates signals from the four workload Defenders into single incidents, runs attack disruption, and hosts advanced hunting across all the data. You don't buy Defender XDR; you get it by licensing the underlying products. The more of the four you license, the more the correlation is worth.

This is the most useful mental model in the whole family: four sensors, one brain. Endpoint watches devices, Office 365 watches mail, Identity watches AD, Cloud Apps watches SaaS — and XDR joins the dots into "this one attack touched all four".

The confusing near-namesakes

Microsoft Defender for Cloud is not Defender for Cloud Apps. Defender for Cloud is an Azure product (formerly Azure Security Center) that protects cloud infrastructure — VMs, storage accounts, Kubernetes, SQL — across Azure, AWS, and GCP. It is licensed through Azure consumption, managed by the infrastructure team, and has nothing to do with Microsoft 365 licensing. If your organisation runs workloads in Azure, you likely need both; they are different budgets, different consoles, different teams.

Microsoft Defender Antivirus is the free antivirus engine built into Windows 10 and 11. Every machine has it whether you license anything or not. Defender for Endpoint manages and enriches it, but the antivirus works standalone. Configuration guidance is in Microsoft Defender Antivirus configuration.

Microsoft Defender (the consumer app) is a cross-device security app bundled with Microsoft 365 Personal and Family subscriptions. It has nothing to do with any enterprise product and should never appear in a business architecture diagram.

Microsoft Defender for Business is not a separate technology — it is Defender for Endpoint repackaged for organisations under 300 users, with simplified onboarding and a lower price, bundled into Microsoft 365 Business Premium. Details in Microsoft Defender for Business.

The satellites

Three more products wear the badge:

And adjacent but not named Defender: Microsoft Sentinel is the SIEM/SOAR that can ingest everything above plus third-party sources — see Microsoft Sentinel for Microsoft 365 — and Microsoft Security Copilot is the AI layer over the lot.

Which licence gets you what

The short mapping, for the licences most tenants actually hold:

  • Every tenant, free: Exchange Online Protection, Defender Antivirus on Windows devices.
  • Microsoft 365 Business Premium: Defender for Business (≈ Endpoint for SMB) + Defender for Office 365 Plan 1.
  • Microsoft 365 E3: none of the four workload Defenders. This surprises people constantly — E3 is not a security SKU beyond the basics.
  • Microsoft 365 E5 / E5 Security add-on: all four workload Defenders at their highest plans, and therefore the full Defender XDR experience.
  • Azure subscription: Defender for Cloud, priced per resource, regardless of your Microsoft 365 licensing.

The E3 row is the one to internalise. "We have Microsoft 365, so we have Defender" is true only at E5 or Business Premium level; an E3 tenant claiming Defender coverage usually has only the built-in antivirus. The step-up economics are covered in Microsoft 365 E3 vs E5.

The short version

Four workload products — Endpoint (devices), Office 365 (mail), Identity (AD), Cloud Apps (SaaS) — correlated by Defender XDR, which you get by licensing them, not by buying it. Defender for Business is small-business Endpoint. Defender for Cloud is a different product for Azure infrastructure. Defender Antivirus is the free engine in Windows. The consumer Microsoft Defender app is irrelevant to work.

When someone says "we have Defender", the only correct response is: which one?

Frequently asked questions

What is the difference between Defender for Cloud and Defender for Cloud Apps?
Different products entirely. Defender for Cloud Apps is the CASB for SaaS — shadow-IT discovery, session controls, OAuth governance — licensed through Microsoft 365. Defender for Cloud is an Azure product (formerly Azure Security Center) protecting VMs, storage, Kubernetes, and SQL across Azure, AWS, and GCP, billed through Azure consumption. Different budgets, consoles, and teams.
Is Defender XDR a product I can buy?
No. Defender XDR is the correlation layer you get by licensing the underlying workload products — Endpoint, Office 365, Identity, Cloud Apps. It joins their alerts into single incidents and runs attack disruption and advanced hunting. Four sensors, one brain; the more of the four you license, the more the correlation is worth.
Does Microsoft 365 E3 include Defender?
Only the free baseline: Exchange Online Protection and the built-in Defender Antivirus. E3 includes none of the four workload Defenders — no EDR, no Safe Links, no identity or SaaS threat detection. Full Defender coverage comes with E5, the E5 Security add-on, or (for SMB) Business Premium.
Is Defender for Business the same as Defender for Endpoint?
Essentially yes — Defender for Business is Defender for Endpoint repackaged for organisations under 300 users, with simplified onboarding and a lower price, and it is bundled into Microsoft 365 Business Premium. It is not a separate technology.

Further reading

Spot something wrong or want a topic covered? Send it through the contact form.