Disconnected security signals can make threats harder to understand and slower to contain. This Microsoft Learn tutorial explores how Microsoft Defender XDR coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications--helping security teams connect signals, investigate attacks, and respond more effectively. Read the tutorial to learn how Microsoft Defender XDR can help you build more coordinated, efficient security operations.
What is Microsoft Defender XDR?
Microsoft Defender XDR is a unified, pre- and post-breach enterprise defense suite that helps you protect devices, identities, data, email, and applications in a coordinated way.
Instead of managing separate tools in silos, Defender XDR brings together multiple Microsoft security products, including:
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Microsoft Defender Vulnerability Management
- Microsoft Defender for Cloud
- Microsoft Entra ID Protection
- Microsoft Data Loss Prevention
- App Governance
- Microsoft Purview Insider Risk Management
- Microsoft Security Exposure Management
Defender XDR coordinates detection, prevention, investigation, and response across these services. It correlates signals from the products you’ve licensed and provisioned, so your security team can see:
- How an attack entered the environment
- Which users, devices, mailboxes, and apps are affected
- How the threat is currently impacting the organization
This helps you move from isolated alerts to a connected view of incidents, making it easier to understand and respond to sophisticated attacks.
How does Defender XDR improve detection and response?
Defender XDR is designed to help your team move faster and with more context when dealing with threats. It does this in several ways:
1. Combined incidents and a single pane of glass
All alerts and related evidence from supported Defender products are surfaced in the Microsoft Defender portal as a combined incidents queue. This gives you:
- A single view of detections, impacted assets, and automated actions
- Incidents that already group related alerts, behaviors, and context
- Less time spent correlating alerts across tools
2. Automatic attack disruption
Defender XDR uses high-confidence signals from multiple workloads to automatically contain in-progress attacks and limit lateral movement. For example:
- If a malicious file is detected on an endpoint by Defender for Endpoint, Defender XDR can instruct Defender for Office 365 to scan and remove that file from all email messages.
- The same file is then blocked on sight across the Microsoft 365 security suite.
3. Self-healing of compromised assets
Using AI-powered automatic actions and playbooks, Defender XDR can help self-heal:
- Compromised devices
- User identities
- Mailboxes
It leverages the automatic remediation capabilities of each suite product to bring impacted assets back to a secure state wherever possible.
4. Cross-product threat hunting
Your security team can use Defender XDR to run custom queries over 30 days of historic raw signals and alert data from:
- Defender for Endpoint
- Defender for Office 365
- Defender for Identity
- Defender for Cloud Apps
This lets you proactively hunt for signs of compromise using your own organizational knowledge, instead of waiting for alerts alone.
What components and licensing do we need for Defender XDR?
Microsoft Defender XDR is a cross-product layer that sits on top of several Microsoft security services. It adds coordination, automation, and a unified experience across the tools you already use.
Key components it works with
Defender XDR correlates signals from the Microsoft security products you have licensed and provisioned, such as:
- Endpoints: Microsoft Defender for Endpoint – unified endpoint platform for preventative protection, post-breach detection, automated investigation, and response.
- Vulnerabilities: Microsoft Defender Vulnerability Management – continuous asset visibility, risk-based assessments, and built-in remediation tools to prioritize and address vulnerabilities and misconfigurations.
- Email & collaboration: Microsoft Defender for Office 365 – protection against malicious email messages, URLs, and collaboration threats.
- Identity: Microsoft Defender for Identity and Microsoft Entra ID Protection – detection and investigation of advanced threats, compromised identities, and malicious insider actions using on-premises Active Directory and Microsoft Entra ID signals.
- Cloud apps: Microsoft Defender for Cloud Apps – cross-SaaS visibility, data controls, and threat protection for cloud applications.
- Data & insider risk: Microsoft Data Loss Prevention and Microsoft Purview Insider Risk Management.
- Exposure management & governance: Microsoft Security Exposure Management and App Governance.
Licensing considerations
To use Microsoft Defender XDR, specific licensing requirements must be met before you can enable the service in the Microsoft Defender portal at https://security.microsoft.com. Defender XDR will only correlate signals from the products you have:
- Properly licensed
- Provisioned and configured in your tenant
In practice, this means your first step is to confirm which Defender and related security products your organization already owns, then map those to the Defender XDR requirements. Once licensing is in place, you can turn on Microsoft Defender XDR in the portal and start using the unified incident view, automatic attack disruption, and cross-product threat hunting capabilities.