Defender guides
Microsoft's family of threat-protection products, unified under Microsoft Defender XDR. See the glossary entry →
67 guides touch on defender.
- Attack Simulation Training in Defender for Office 365
How to run controlled phishing simulations and embedded training to harden users against real attacks.
- Building a Microsoft 365 strategy
A framework for setting Microsoft 365 strategy — vision, principles, roadmap, and operating model.
- Business Email Compromise response playbook
How to respond to a confirmed BEC incident in Microsoft 365 — containment, investigation, remediation, and prevention.
- Business Premium vs Microsoft 365 E3
Business Premium vs Microsoft 365 E3: Premium wins on security for less money, E3 wins on mailboxes, Windows, and scale. How to choose, and how to mix them.
- Compromised Microsoft 365 account response runbook
Compromised Microsoft 365 account runbook: what to run in the first fifteen minutes, what to check in the first hour, and when it is safe to hand it back.
- Defender Attack Disruption
Automatic Attack Disruption is Defender XDR's ability to contain in-progress attacks automatically — what it does and how.
- Defender External Attack Surface Management
Defender EASM discovers your organisation's internet-facing assets — including the ones you didn't know about.
- Defender for Endpoint on Linux
Deploying Microsoft Defender for Endpoint on Linux servers and workstations — distributions, packaging, and integration.
- Defender for Endpoint on macOS
Deploying and managing Microsoft Defender for Endpoint on Mac fleets via Intune.
- Defender for Office 365 quarantine workflow
How users and admins work with quarantine — release, request, report, and the policy decisions behind it.
- Defender Threat Intelligence
How Microsoft Defender XDR integrates threat intelligence — built-in feeds, custom IoCs, and Defender TI as a separate product.
- Defender Vulnerability Management
How Defender for Endpoint's vulnerability management surfaces CVEs, misconfigurations, and prioritises remediation.
- Defender XDR advanced hunting workshop
How to use Defender XDR advanced hunting effectively — tables, common queries, and threat-hunting patterns.
- Defender XDR and attack-surface management
How Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.
- Exchange Online anti-spam and anti-phishing
The layered defences Exchange Online uses against spam, malware, and phishing — and how to tune them.
- Exchange Online Protection transport pipeline
How email flows through EOP — connection filtering, content filtering, transport rules, and the deliverability checks.
- GitHub with Microsoft 365
How GitHub Enterprise integrates with Microsoft 365 — Entra ID SSO, Teams, SharePoint, and developer workflows.
- How to block a compromised account in Microsoft 365
How to block a compromised Microsoft 365 account in ten minutes: disable sign-in, revoke sessions, reset password and MFA, kill inbox rules and forwarding.
- Intune and Android Enterprise
Managing Android devices with Intune through Android Enterprise — work profiles, fully managed, dedicated devices.
- Intune baseline for Cloud PCs
A minimum viable Intune configuration for Windows 365 Cloud PCs: enrolment, compliance, configuration profiles, Autopatch, and the differences from laptops.
- Intune compliance policies and Conditional Access
Combining Intune compliance with Conditional Access gives you device-aware access control — the heart of zero trust.
- Intune Endpoint Privilege Management
EPM lets standard users run specific tasks with elevated privileges without making them local admins.
- Intune macOS management
How Intune manages Mac devices — enrolment via Apple Business Manager, configuration, app deployment, and compliance.
- Investigating a phishing message that got past defences
Runbook for a phish that landed: find every copy, purge it from mailboxes, find who clicked, submit it so filters learn, and work out why it got through.
- KQL primer for Defender XDR
A practical introduction to Kusto Query Language for Microsoft Defender XDR and Sentinel hunting.
- Microsoft 365 Apps for Mac
Deploying and managing Office apps on macOS — installation, updates, Intune management, and Mac-specific features.
- Microsoft 365 Business Premium deep dive
What Microsoft 365 Business Premium actually delivers — and why it's the right answer for most SMBs.
- Microsoft 365 documentation patterns
What to document for a Microsoft 365 tenant, how to structure it, and how to keep it from rotting.
- Microsoft 365 E3 vs E5 — what's worth the upgrade
A practical comparison of Microsoft 365 E3 and E5 plans — what E5 adds, where the value sits, and step-up patterns.
- Microsoft 365 for small business
How to choose, set up, and run Microsoft 365 in a small business — the plan, the basics, and the security baseline.
- Microsoft 365 Government cloud operations
Specific operational differences when running Microsoft 365 in GCC, GCC High, or DoD government clouds.
- Microsoft 365 incident response runbook
A structured incident response runbook for Microsoft 365 — detection, triage, containment, eradication, recovery, lessons.
- Microsoft 365 Lighthouse for MSPs
Microsoft 365 Lighthouse is the multi-tenant management portal for managed service providers running many SMB tenants.
- Microsoft 365 mobile device security
Securing mobile access to Microsoft 365 — MAM, MDM, Conditional Access, and the BYOD vs corporate distinction.
- Microsoft 365 monitoring and alerts
How to monitor a Microsoft 365 tenant — service health, audit logs, security alerts, and third-party tooling.
- Microsoft 365 network connectivity principles
How to architect network traffic for Microsoft 365 — local egress, optimisation, and the network connectivity principles Microsoft publishes.
- Microsoft 365 plans and pricing
Microsoft 365 plans and pricing, made navigable: Business Premium for SMB, E3 plus add-ons for enterprise, E5 when you'll use it — with every comparison.
- Microsoft 365 security and compliance
A practical tour of the Microsoft 365 security and compliance stack — Defender, Purview, Entra, and how they fit together.
- Microsoft 365 security baselines
The minimum security configuration every Microsoft 365 tenant should have — and how to get there.
- Microsoft 365 service principal best practices
How to design, deploy, and operate service principals safely — credentials, permissions, and lifecycle.
- Microsoft Defender Antivirus configuration
How to configure Microsoft Defender Antivirus for Windows endpoints — the settings that matter and how to manage them.
- Microsoft Defender Antivirus exclusions design
How to design Defender Antivirus exclusions safely — minimising scope while accommodating legitimate application needs.
- Microsoft Defender for Business
Defender for Business is the SMB-targeted EDR product bundled with Microsoft 365 Business Premium.
- Microsoft Defender for Cloud Apps explained
Defender for Cloud Apps is Microsoft's CASB — discovering, monitoring, and controlling SaaS app usage.
- Microsoft Defender for Endpoint explained
Defender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.
- Microsoft Defender for Identity explained
Defender for Identity detects identity-based attacks against on-prem Active Directory and Entra ID. Here's how it works.
- Microsoft Defender for Identity sensor deployment
How to plan and roll out Defender for Identity sensors — DCs, AD FS, Entra Connect, and tuning.
- Microsoft Defender for IoT explained
Defender for IoT secures the devices EDR can't reach — OT, ICS, and IoT. Here's how it works and when it's worth deploying.
- Microsoft Defender for Office 365 explained
What Defender for Office 365 adds on top of EOP — Safe Links, Safe Attachments, AIR, attack simulation — plus Plan 1 vs Plan 2 and the settings worth tuning.
- Microsoft Entra Global Secure Access
Microsoft's SSE platform — Internet Access and Private Access for zero-trust network access. Here's what it does.
- Microsoft Intune and device management
Microsoft Intune explained: what it manages, how policies work, how enrollment and compliance fit together, and where it sits in Microsoft 365.
- Microsoft Purview Data Loss Prevention — a deep dive
DLP policies detect and prevent sensitive data from leaving Microsoft 365. Here's the architecture and how to roll them out.
- Microsoft Security Copilot
Microsoft's AI assistant for security analysts — what it does, where it's embedded, and how it's licensed.
- Microsoft Sentinel analytic rules
How analytic rules work in Sentinel — types, tuning, and writing custom detections.
- Microsoft Sentinel cost optimisation
How to control Microsoft Sentinel costs — ingestion tuning, commitment tiers, retention, and data tiering.
- Microsoft Sentinel for Microsoft 365
How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.
- Microsoft Sentinel onboarding
How to onboard Microsoft Sentinel — workspace setup, data connectors, and starting analytic rules.
- Purview Insider Risk Management
Insider Risk Management detects risky internal behaviour — data theft, IP leakage, policy violations — with built-in privacy controls.
- Ransomware preparedness for Microsoft 365
How to harden a Microsoft 365 tenant against ransomware — prevention, detection, response, and recovery.
- Teams app permission policies design
Designing Teams app permission and setup policies — controlling app installation and pinning at scale.
- The Intune Suite explained
Intune Suite explained: Endpoint Privilege Management, Remote Help, Advanced Analytics, Enterprise App Management, Tunnel, Cloud PKI — and when it pays.
- Token protection and token theft in Microsoft 365
Token theft has become a leading attack pattern. Here's how it works and what Microsoft 365 offers to defend against it.
- What is Exchange Online?
What Exchange Online is: Microsoft 365's cloud email and calendaring, how it fits the platform, the security and compliance layers, and running it well.
- What is Microsoft 365?
What Microsoft 365 is: what's in the suite, who each plan is for, how the pieces fit together, and what changed since the Office 365 days.
- Which Microsoft Defender is which
Which Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it.
- Working effectively with Microsoft Support
How to engage Microsoft Support for Microsoft 365 issues — preparing requests, severity, escalation, and what to expect.
- Zero trust in Microsoft 365
What zero trust actually means in a Microsoft 365 context — and the concrete controls that get you there.