Defender XDR guides
Microsoft's unified extended detection and response portal that correlates signals across Defender products. See the glossary entry →
23 guides touch on defender xdr.
- Business Email Compromise response playbook
How to respond to a confirmed BEC incident in Microsoft 365 — containment, investigation, remediation, and prevention.
- Compromised Microsoft 365 account response runbook
Compromised Microsoft 365 account runbook: what to run in the first fifteen minutes, what to check in the first hour, and when it is safe to hand it back.
- Defender Attack Disruption
Automatic Attack Disruption is Defender XDR's ability to contain in-progress attacks automatically — what it does and how.
- Defender for Endpoint on Linux
Deploying Microsoft Defender for Endpoint on Linux servers and workstations — distributions, packaging, and integration.
- Defender for Endpoint on macOS
Deploying and managing Microsoft Defender for Endpoint on Mac fleets via Intune.
- Defender Threat Intelligence
How Microsoft Defender XDR integrates threat intelligence — built-in feeds, custom IoCs, and Defender TI as a separate product.
- Defender XDR advanced hunting workshop
How to use Defender XDR advanced hunting effectively — tables, common queries, and threat-hunting patterns.
- Defender XDR and attack-surface management
How Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.
- Intune Endpoint Privilege Management
EPM lets standard users run specific tasks with elevated privileges without making them local admins.
- KQL primer for Defender XDR
A practical introduction to Kusto Query Language for Microsoft Defender XDR and Sentinel hunting.
- Microsoft 365 governance framework
A practical framework for governing Microsoft 365 — domains, policies, roles, and operating cadence.
- Microsoft 365 incident response runbook
A structured incident response runbook for Microsoft 365 — detection, triage, containment, eradication, recovery, lessons.
- Microsoft 365 monitoring and alerts
How to monitor a Microsoft 365 tenant — service health, audit logs, security alerts, and third-party tooling.
- Microsoft Defender for Endpoint explained
Defender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.
- Microsoft Defender for Identity explained
Defender for Identity detects identity-based attacks against on-prem Active Directory and Entra ID. Here's how it works.
- Microsoft Defender for Identity sensor deployment
How to plan and roll out Defender for Identity sensors — DCs, AD FS, Entra Connect, and tuning.
- Microsoft Defender for IoT explained
Defender for IoT secures the devices EDR can't reach — OT, ICS, and IoT. Here's how it works and when it's worth deploying.
- Microsoft Security Copilot
Microsoft's AI assistant for security analysts — what it does, where it's embedded, and how it's licensed.
- Microsoft Sentinel analytic rules
How analytic rules work in Sentinel — types, tuning, and writing custom detections.
- Microsoft Sentinel for Microsoft 365
How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.
- Microsoft Sentinel onboarding
How to onboard Microsoft Sentinel — workspace setup, data connectors, and starting analytic rules.
- Token protection and token theft in Microsoft 365
Token theft has become a leading attack pattern. Here's how it works and what Microsoft 365 offers to defend against it.
- Which Microsoft Defender is which
Which Microsoft Defender is which: Endpoint, Office 365, Identity, Cloud Apps, Business, XDR, Cloud, Antivirus — what each does and which licence gets it.