Microsoft Defender
What is Defender XDR, licensing, Defender for endpoint, office, Identity, Cloud Apps, RBAC, SOC
What is Defender XDR
- Microsoft Defender XDR is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks.
- Microsoft Defender XDR helps security teams protect their organizations and detect threats by using information from other Microsoft security products, including:
- https://learn.microsoft.com/en-us/defender-xdr/microsoft-365-defender
Microsoft Defender for Endpoint(Computers) - MDE (formerly ATP)
- Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to help enterprises prevent, detect, investigate, and respond to advanced threats on their endpoints. Endpoints include laptops, phones, tablets, PCs, access points, routers, and firewalls.
- https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint
- Defender for Endpoint is part of Microsoft Defender XDR and can be integrated with other Microsoft solutions, including: Intune, MDC, MDCA, MDI, MDO, MDVM, Sentinel
- It is Advanced threat protection (ATP) formerly called Microsoft Defender Adanced Threat Proteciton, now called MDE (Microsoft Defender for Endpoint)
- MDE is available in two plans:

- P1 is available with Microsoft 365 E3 or A3 license
- P2 is available in E5 license.
- Endpoint behavioral sensors are built in windows 10/11, these sensors collect the behavorial signals/data from the O/S and sent it to MDE.
- MDE Capabilities:
- Vulnerability Management (P2 license)
- Attack surface reduction:
- Minimizing potential paths through which attackers exploits vulnerabilities on endpoints.
- Hardware based isolation
- application controls
- Exploit proteciton
- network protection
- controlled folder access
- Device control
- web protection
- Ransomeware protection:
- Next generation protection:
- EDR: Endpoint Deduction and Response
- Automated investigation and Remediation
- Secure scores for devices:
- Threat experts:
Microsoft Defender for Office 365 (emails)- MDO
- The built-in security features for all cloud mailboxes prevent broad, volume-based, known email attacks.
- Defender for Office 365 Plan 1 protects email and collaboration features from zero-day malware, phishing, and business email compromise (BEC).
- Defender for Office 365 Plan 2 adds phishing simulations, post-breach investigation, hunting, and response, and automation.
- https://learn.microsoft.com/en-us/defender-office-365/mdo-about
- code
Microsoft Defender for Identity - MDI
- Microsoft Defender for Identity helps organizations detect, investigate, and respond to identity-based attacks across on-premises, cloud, and hybrid environments. Attackers frequently target identities such as users, applications, and service accounts to gain access, escalate privileges, and maintain persistence.
- https://learn.microsoft.com/en-us/defender-for-identity/what-is
- code
Microsoft Defender for Cloud Apps - MDCA
Microsoft Defender for Cloud - MDC
Microsoft Defender Vulnerability Management
- Defender Vulnerability Management delivers asset visibility, intelligent assessments, and built-in remediation tools for Windows, macOS, Linux, Android, iOS, and network devices. Using Microsoft threat intelligence, breach likelihood predictions, business contexts, and devices assessments, Defender Vulnerability Management rapidly and continuously prioritizes the biggest vulnerabilities on your most critical assets and provides security recommendations to mitigate risk.
- https://learn.microsoft.com/en-us/defender-vulnerability-management/defender-vulnerability-management?tabs=preview-customers
- code
Microsoft Entra ID Protection
Microsoft Data loss Prevention
Microsoft Purview Inisder Risk Management
What is XDR (Extended Detection and Response)
- It is like a centralised location where it integrates and correlates data from different security tools like MDE, MDO, MDI, MDCA and other security sources acroos organization.
- It works beyond EDR (Endpoint detection & response) and NDR (Network detection & response).
- It gives more visibility and control to deal any threats.
- It can automatically detects, stops and remediates affected assests.
- It performs detection, investigation, prevention and response
- Example of phishing attach:

- Imagine that an employee gets a fishing email and it has a malicious attachment. User doesn't and open the mail attachments so there is a malware which gets installed.
It gets the user identity and then the attacker uses that identity to access other devices assets and get more sensitive information they start to exfiltrate.
If there is Defender Suite installed, all the services provided by Defender we that is Defender for Office 365 Defender for Endpoint, Defender for identity and Microsoft Defender for cloud apps.
There is exchange online protection is part of MDO (Microsoft Defender for Office 365) so exchange online protection can detect the fishing email and once it detects the fishing email it uses flow rules these are also called as transport rules, these rules are used to make sure that the fishing email never even goes to the inbox of that employee and then Microsoft Defender for office uses something called as safe attachments in MDO which will test these attachments and determine that it is harmful or not not based on rules has been setup. Then there is MDE (Microsoft Defender for Endpoints) which detects the device and network vulnerabilities, next there is MDI (Microsoft Defender for identity)this gets to know things like privilege escalation or if there is any lateral movement that is happening or any weakness related to user identity, then there is MDCA (Microsoft Defender for cloud apps) this usually notices anomalous behaviour like impossible travel request that means suppose say I am in the US I'm trying to log in maybe within 5 minutes or 10 minutes there is another login with my user ID from different location and so that is an impossible travel so it will alert.
Identify anomalous activities like unusual download you know sharing sensitive files mail forwarding activities all these can be identified using Microsoft Defender for cloud apps so this is how all the services that are provided by Microsoft 365 Defender act when there is an attack.
- Code
Difference between Microsoft 365 Defender suite Vs Microsoft Defender XDR
- Microsoft Defender XDR is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks.
- Microsoft Defender XDR (formerly Microsoft 365 Defender) is the current, unified Extended Detection and Response (XDR) platform that coordinates security across endpoints, identities, apps, and email. While "Microsoft 365 Defender" was the brand name during its rollout, it was rebranded to "Microsoft Defender XDR" to reflect its broadened, native, cross-domain protection
- All the security tools can be viewed in Microsoft Defender admin portal.
- code
Defender admin portal
- Go to security.microsoft.com

- Code
Exposure management
Investigation & Response
Threat intelligence
Assets
- Devices:
- Device Inventory: List of onboard and offboard devices to Defender.

- click onboard device to get more detailsL
- Overview: Device overview

- Incidents and alerts: Incident and reports related to onboarded device.
- configuration management: Applied security policies to device.

- Applications
- Cloud
- AI agents
Microsoft Sentinel
Endpoints
Email & collaboration
Cloud apps
cloud security
SOC Optimization, Reports, Learning hub, Trials, More resources
System
- Audit
- Data management
- Permissions
- Health
- Settings

- Microsoft Defender portal
- Microsoft Defender XDR
Endpoints


- General
- Advanced features: This section provides a set of advanced features you can enable. These features require integration with other products. You need to verify that these settings are enabled to use the features.
- Restrict correlation to within scoped device groups: On/Off
- Allow or block file: On/Off
- Hide potential duplicate device records: On/Off
- Custom network indicators: On/Off
- Tamper protection: On/Off
- Show user details: On/Off
- Skype for business integration: On/Off
- Microsoft Defender for Cloud Apps: On/Off
- Web content filtering: On/Off
- Default to streamlined connectivity when onboarding devices in Defender portal: On/Off
- Apply streamlined connectivity settings to devices managed by Intune and Defender for Cloud: On/Off
- Aggregated Reporting: On/Off
- Isolation Exclusion Rules: On/Off
- Share endpoint alerts with Microsoft Compliance Center: On/Off
- Microsoft Intune connection: On/Off
- Authenticated telemetry: On/Off
- Preview features: On/Off
- Licenses:
- Email notifications:
- Create rules that determine the devices and alert severities to send email notifications for and the notification recipients. For guidance, read Configuring email notifications.
- Permissions
- Roles:
- Device groups:
- Rules
- Alert suppression:
- Indicators:
- Custom Data Collection:
- Isolation exclusion rules:
- Web Content filtering:
- Asset rule management:
- Configuration management
- Enforcement scope:
- Intune Permissions:
- Device Management
Onboarding Devices to MDE (Microsoft Defender for Endpoint)
Windows 10 and 11 with script <10 devices
- Prerequisites:
- Valid License
- All the Microsoft Defender Servcie Endpoint URL must be accessible from the device.
- Process:
- To get the list of onboarding/Not onboarding: Go to Intune admin center/Endpoint security.

- Go to security.microsoft.com/System/Settings/Endpoints/Device management and click onboarding. (Defender admin portal)

- click Download onboard package: Select O/S = Windows 10 and 11, local script. Copy the package in the desired onboarding machine. extract and run.
- Run the script on the devices which needs to be onboard.
- Go to location where it was extrated and run as administrator.

- hostname=STAR-IT01 (Not onboarded)
- If machine is already onboarded then type at command promt C:/sc query sense
- If machine is not already onboarded then type at command promt C:/sc query sense

- check device is onboarded:
- Go to Defender/Assets/Devices/Device Inventory:

- or
- Run a detection test:
- Run powershell script on onboarded machine: copy the below command and run in powershell or ccommand prompt.
- powershell.exe -NoExit -ExecutionPolicy Bypass -WindowStyle Hidden $ErrorActionPreference= 'silentlycontinue';(New-Object System.Net.WebClient).DownloadFile('http://127.0.0.1/1.exe', 'C:\\test-WDATP-test\\invoice.exe');Start-Process 'C:\\test-WDATP-test\\invoice.exe'
- Note: If powershell window/cmd close automatically which indicates device is onboarded successfully.
- Check Alerts:
- Go to Incidents & Alerts and click alerts.
- click related lerts and check details.
- Run the process commands on powershell on both onboarded and not onboarded machines.
- Not onboarded:
- $Process = Get-Process | select Name | Sort-Object -Property Name $services = "MpCmdRun","MpDlpCmd","MsMpEng","ConfigSecurityPolicy","NisSrv","MsSense","SenseCnCProxy","SenseIR","SenseCE","SenseSampleUploader" foreach ($serv in $services) { if($Process.Name -contains $serv) { Write-Host $serv "is running." -ForegroundColor Green } else { Write-Host $serv "is not running" -ForegroundColor Red } }
- MsSense is not running: It should run.
- Code
Windows 10 and 11 with GPO
Windows 10 and 11 With Mobile Device Management / Intune
- Go to security.microsoft.com/settings/Endpoints/Device management/onboarding
- When you have enrolled endpoint devices with intune, it is the easiest method to onboard to MDE.

- click Download onborading package or Auto Deploy
- Onboarding with package:
- Download the zip package.
- copy to endpoint machine and extract all.
- Open command prompt with administrative privilege.
- Run the package.
- Onboarding with Auto deploy:
- Endpoint Detection and response (EDR):
- Go to Intune portal: intune.microsoft.com/Endpoint security/Microsoft Defender for Endpoint
- Connection status = unavailable (some toggles are disabled and acting as "off" because Microsoft Defender for Endpoint is not actively communicating with intune.....
- Switch on Microsoft Intune Connection:
- Go to Microsoft Defender/Systems/Settings/Endpoints/General/Advanced features and switch on Microsoft Intune Connection.

- This connects microsoft Intune to enable sharing of device information and enhanced policy enforcement.
- Go back to Intune portal and check status is Available.
- Scroll down and swith on: Connect Windows devices version 10.0.15063 and above to Microsoft Defender for Endpoint.
- When on, compliance policies using the Device Threat Level rule will evaluate devices including data from this connector.
When off, Intune will not use device risk details sent over this connector during device compliance calculation for policies that have a Device Threat Level configured. Existing devices that are not compliant due to risk levels obtained from this connector will also become compliant.

- Connection status = Enable
- Onboarding the devices automatically:
- Click Endpoint detection and response-->Create policy

- Platform = Windows
- Profile = Endpoint detection and response --> create
- Basics
- Name = star_EDR
- Configuration settings: Auto from connector

- Scope tags:
- Assignments: select group that will receive this profile,
- Review = Create.
- When you deploy this policy to use group then user must sign in to the device so that this policy applies and device can onboard to Defender for Endpoints.
- Device compliance:
- Click Device compliance-->Create policy
- Platform = windows 10 and later
- Profile type = Windows 10/11 compliance policy
- Basics
- Name = compliance_policy1
- Compliance settings: --> Microsoft Defender for Endpoint-->Require the device to be at or under the machine risk score = Clear, Low, Medium, High, Not configured (Select the maximum allowed machine risk score for devices evaluated by Microsoft Defender for Endpoint. Devices which exceed this score get marked as noncompliant)
- Actions for noncompliance:
- Action = send email to enduser, Add device to retire list
- select message templates: If template is not created, go to
- Additional recepients = select
- Assignments = select group
- Review and create.
- Check the onboard devices.

- Conditional Access:
- Create policy --> redirect to Azure Entra Id/Security/Conditional Access policy
Windows Server 2008 R2 SP1 / 2012, 2016, 2019, 2025
macOS
Linux / Linux Server
iOS & Android
- Deployment packages
- Offboarding
- Email & collaboration
- Device Discovery
- Cloud Apps
- Microsoft Sentinel
Integration with Intune
code
code
code
code
code
code
code
TVM - Threat and Vulnerability Management
TVM
- This service is available in P2 license of Microsoft Defender for Endpoint.
- It is one of the service provided by Microsoft Defender for Endpoint, to protect the endpoint by discovering vulenrability and remediate.
- Find out weaknesses and misconfiguration that exists on a specific devices.
- tvm1.jpg
- It captures some data from the device like some softwares, O/S and hardware details. When you onboarding the device then sensor start sending the details to MDE.
- The details which sent to MDE:
- File Data - File name, size and hashes
- System file changes
- Process data
- Registry values and registry changes
- Network connection data
- Device details (name and OS)
- Deep optics of kernel and memory manager
- TVM options:
- Dashboard:
- Recommendations:
- Remediations:
- Software Inventory:
- Weakness:
- Event Timeline
- Code
Security Recommendation:
- Go to Microsoft Defender by security.microsoft.com/Vulnerability management
- code
- code
code
code
code
code
code
Exclusion
code
code
code
code
code
code
code
Tamper Protection
code
code
code
code
code
code
code
Disk Encryption
code
code
code
code
code
code
code
Firewall
Settings: You can set allow/Block the traffic
- Go to Intune Admin Center/Endpoint Security / Firewall
- firewall1.jpg
- Create policy:
- Platform = Windows
- Profile = Windows Firewall
- Basic
- Name = star_firewall1
- Configurtion Settings: The Firewall configuration service provider configures the Windows Defender Firewall global settings, per profile settings, as well as the desired set of custom rules to be enforced on the device. Using the Firewall CSP the IT admin can now manage non-domain devices, and reduce the risk of network security threats across all systems connecting to the corporate network.
- Certificate revocation list verification =
- Disable Stateful Ftp =
- Enable Packet Queue =
- IPsec Exceptions =
- Opportunistically Match Auth Set Per KM =
- Preshared Key Encoding =
- Security association idle time =
- Enable Domain Network Firewall =
- Enable Private Network Firewall =
- Enable Public Network Firewall =
- VM Creator Id
- Target =
- Auditing
- Object Access Audit Filtering Platform Connection =
- Object Access Audit Filtering Platform Packet Drop =
- Network List Manager
- Allowed Tls Authentication Endpoints =
- Configured Tls Authentication Network Name =
- Create policy.
- code
code
code
code
code
code
code
EDR - Endpoint Detection and Response
code
code
code
code
code
code
code
Configuration Profile
Profile Settings
- Go to intune admin center/Devices/Configuration.
- configuration1.jpg
- Create New Policy-->Windows 10 or higer --> Template
- configuration2.jpg
- Basics
- Name = Star_profile1
- Description = profile
- Profile Type = Endpoint Protection
- Configuration settings
- configuration3.jpg
- Base on requirement set the profile.
- Assignments
- Applicability Rules
- Review + create
- code
- code
code
code
code
code
code
code
Firewall
code
code
code
code
code
code
code
Firewall
code
code
code
code
code
code
code
Firewall
code
code
code
code
code
code
code
Firewall
code
code
code
code
code
code
code
Firewall
code
code
code
code
code
code
code
Firewall
code
code
code
code
code
code
code
Firewall
code
code
code
code
code
code
code
Firewall
code
code
code
code
code
code
code
Firewall
code
code
code
code
code
code
code