Configure advanced features in Microsoft Defender for Endpoint
In brief
The article now lists key advanced features, adds clearer enable/disable instructions, and refines guidance for EDR in block mode, file blocking, and duplicate device records. Metadata was also updated.
What Defender admins need to know
Admins have clearer configuration guidance and explicitly stated EDR in block mode prerequisites: active Microsoft Defender Antivirus and cloud-based protection.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Configure advanced features in Defender for Endpoint
DependingYou can configure the following Defender for Endpoint advanced features depending on the Microsoft security products that you use, you can integrate Defender for Endpoint with the advanced features described in this article.your environment.
Enable advanced features
To enable or disable an advanced feature in the Microsoft Defender portal:
Go to the Microsoft Defender portal and sign in.
In the navigation pane, select Settings > Endpoints > Advanced features.
Restrict correlation to within scoped device groups
The scoped device group correlation setting can be used for scenarios where local SOC operations would like to limit alert correlations only to device groups that they can access. When thisthe scoped device group correlation setting is turned on, an incident composed of alerts that cross-device groups areis no longer considered a single incident. The local SOC can then take action on the incident because they have access to one of the device groups involved. However, global SOC sees several different incidents by device group instead of one incident. We don't recommend turning on this setting unless doing so outweighs the benefits of incident correlation across the entire organization.
Enable EDR in block mode
Endpoint detection and response (EDR) in block mode provides protection from malicious artifacts, even when Microsoft Defender Antivirus is running in passive mode. When EDR in block mode is turned on, it blocks malicious artifacts or behaviors that are detected on a device. EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post breach.
Automatically resolve alerts
Turn on the auto-resolve alerts setting to automatically resolve alerts where no threats were found or where detected threats were remediated. If you don't want to have alerts auto resolved, you'll need to manually turn off the feature.
Configure allow or block file settings
Blocking is only available ifTo use this feature, your organization fulfillsmust meet these requirements:
UsesMicrosoft Defender Antivirusasis the active antimalwaresolution and,solution.The cloud-Cloud-based protectionfeatureisenabledenabled.
The allow orThis feature lets you block file feature enables you to block potentially maliciousharmful files in your network. BlockingWhen you block a file will prevent it from being read, written, or executed onfile, devices in your organization.organization can't read, write, or run it.
To turn on Allow or block files on:files:
In the Microsoft Defender portal,
in the navigation pane,select Settings > Endpoints > General > Advanced features > Allow or block file.Toggle the setting between On and Off.
a. :::image type="content" source="/defender/media/alloworblockfile.png" alt-text="The Endpoints screen" lightbox="/defender/media/alloworblockfile.png":::
Select Save preferences at the bottom of the page.
After
turningyou turn on this feature, you can block filesviafrom the Add Indicator tab on a file's profile page.
Hide potential duplicate device records
By enabling theTurn on this feature to hide potential duplicate device records feature,so you can ensure that you're seeingsee only the most accurate information about your devices by hiding potential duplicatedata for each device. Duplicates can happen for many reasons. For example, device records. There are different reasons duplicate device records might occur, for example, the device discovery capability in Microsoft Defender for Endpoint might scan your network and discoverfind a device that's is already onboarded or haswas recently been offboarded.
The hide potential duplicate device recordsThis feature identifies potential duplicate devices based on theirmatches duplicates by hostname and last seen time. The duplicate devices will be hiddenIt hides them from multiple experiences in the portal, such as, the Device Inventory, Microsoft Defender Vulnerability Management pages, and Public APIs for machine data, leaving thedata. The most accurate device record stays visible. However, the duplicates willDuplicates still be visibleappear in global search, advanced hunting, alerts, and incidents pages.
The hide potential duplicate device recordsThis setting is turned on by default and is appliedapplies tenant wide. If you don't want to hide potentialTo show duplicate device records, you'll need to manually turn off the feature.feature manually.
Configure custom network indicators
Turning on custom network indicators allows you to create indicators for IP addresses, domains, or URLs, which determine whether they'll be allowed or blocked based on your custom indicator list.
To use this feature, devices must be running Windows 10 version 1709 or later, or Windows 11.
For more information, see Overview of indicators.
Enable tamper protection
During some kinds of cyber attacks, bad actorsattackers might try to disableturn off security features, such asfeatures like antivirus protection,protection on your machines. Bad actors likedevices. They do this to disableaccess your security features to get easier access to your data, to install malware, or to otherwise exploit your data, identity,identity and devices. Tamper protection essentially locks Microsoft Defender Antivirus and preventsstops your security settings from being changed throughby apps andor other methods.
For more information, including how to configure tamper protection, see Protect security settings with tamper protection.
Configure Skype for Business integration
Enabling the Skype for Business integration gives you the ability to communicate with users using Skype for Business, email, or phone. This activationThe Skype for Business integration can be handy when you need to communicate with the user and mitigate risks.
Configure Microsoft Defender for Cloud Apps integration
Enabling this settingthe Microsoft Defender for Cloud Apps integration forwards Defender for Endpoint signals to Microsoft Defender for Cloud Apps to provide deeper visibility into cloud application usage. Forwarded data is stored and processed in the same location as your Defender for Cloud Apps data.
For more information, see Microsoft Defender for Cloud Apps overview.
Configure web content filtering
Block access to websites containing unwanted content and track web activity across all domains. Before you deploy the Microsoft Defender for Endpoint security baseline, ensure network protection is in block mode. To specify the web content categories you want to block, create a web content filtering policy. Ensure you've network protection in block mode when deploying the Microsoft Defender for Endpoint security baseline.
Enable the unified audit log
Download quarantined files
Backup quarantined files in a secure and compliant location so they can be downloaded directly from quarantine. The Download file button willis always be available in the file page. ThisThe download quarantined files setting is turned on by default. Requirements for downloading quarantined files
Default to streamlined connectivity when onboarding devices in the Defender portal
The streamlined connectivityThis setting will setmakes streamlined connectivity the default onboarding package to streamlined connectivity for applicablesupported operating systems. You can still have the option to use the standard onboarding package withinpackage, but you need to select it from the drop-down on the onboarding page, but you must specifically select it in the drop-down.page.
Enable live response
Turn on this feature so that users with the appropriate permissions can start a live response session on devices.
For more information about role assignments,To assign roles for live response, see Create and manage roles.
Enable live response for servers
Enabling this feature allows you to run unsigned scripts in a live response session.
AutomaticConfigure automatic attack disruption
Automatic attack disruption disruptsstops attacks by automatically containing compromised assets that the attacker is using.controls. It limits lateral movement early on, thereby reducingearly, which reduces the overall impact ofcost and productivity loss from an attack, both on the associated costs and on loss of productivity. At the same time, it leaves securityattack. Security operations teams in completekeep full control of investigating, remediating,to investigate, fix issues, and bringingbring assets back online. For more information, see Automatic attack disruption in Microsoft Defender.
Share endpoint alerts with Microsoft Compliance Center
ThisThe endpoint alert sharing setting forwardssends endpoint security alerts and their triage status to the Microsoft Purview portal, allowing youportal. You can use these alerts to enhanceimprove insider risk management policies with alerts and remediateaddress internal risks before they cause harm. Forwarded data is processed and stored in the same location as your Office 365 data.
After configuringyou set up the Security policy violation indicatorspolicy indicators in the insider risk management settings, Defender for Endpoint shares alerts will be shared with insider risk management for applicable users.
Configure the Microsoft Intune connection
You can integrate Defender for Endpoint can be integrated with Microsoft Intune to enable device risk-based conditional access. When you configure Conditional Access, you'll be able to share Defender for Endpoint shares device informationdata with Intune, enhancing policy enforcement.Intune to help enforce policies.
This feature is only available if you'verequires the following prerequisites:following:
- A licensed tenant for Enterprise Mobility + Security E3, and Windows E5 (or Microsoft 365 Enterprise E5)
- An active Microsoft Intune environment, with Intune-managed Windows devices Microsoft Entra joined.
Enable preview features
Learn about new features in the Defender for Endpoint preview release.
Try upcoming features by turning on the preview experience. You'll have access to upcoming features, which you can provide feedback on to help improve the overall experience before features are generally available.
If you already have preview features turned on, manage your settings from the main Defender XDR settings.
For more information, see Microsoft Defender XDR preview features
Configure Endpoint Attack Notifications
Endpoint Attack Notifications enablelet Microsoft to actively hunt for critical threats to be prioritized based on urgency and impact overin your endpoint data. Threats are ranked by urgency and impact.
For proactive hunting across the full scope of Microsoft Defender XDR, including threats that span email, collaboration, identity, cloud applications,apps, and endpoints, get started with Microsoft Defender Experts about Microsoft Defender Experts..
Related content
@@ -1,31 +1,33 @@ --- title: Configure advanced features in Microsoft Defender for Endpoint-description: Learn how to enable and manage advanced Microsoft Defender for Endpoint features and integrations available in the Microsoft Defender portal.+description: Configure advanced Defender for Endpoint features such as EDR in block mode, tamper protection, live response, attack disruption, custom network indicators, and integrations with Intune, Defender for Cloud Apps, and Microsoft Purview. ms.service: defender-endpoint ms.author: painbar author: paulinbar ms.reviewer: yongrhee ms.localizationpriority: medium-ms.collection: +ms.collection: - m365-security - tier2 ms.topic: how-to ms.subservice: onboard-ms.date: 06/17/2026+ms.date: 07/02/2026 appliesto: - Microsoft Defender for Endpoint Plan 2 ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 ----# Configure advanced features in Defender for Endpoint +# Configure advanced features in Defender for Endpoint -Depending on the Microsoft security products that you use, you can integrate Defender for Endpoint with the advanced features described in this article.+You can configure the following Defender for Endpoint advanced features depending on the Microsoft security products in your environment. ## Enable advanced features -1. Go to the [Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2077139) and sign in. +To enable or disable an advanced feature in the Microsoft Defender portal:++1. Go to the [Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2077139) and sign in. 1. In the navigation pane, select **Settings** \> **Endpoints** \> **Advanced features**. @@ -37,61 +39,62 @@ Use the following advanced features to get better protected from potentially mal ## Restrict correlation to within scoped device groups -The scoped device group correlation setting can be used for scenarios where local SOC operations would like to limit alert correlations only to device groups that they can access. When this setting is turned on, an incident composed of alerts that cross-device groups are no longer considered a single incident. The local SOC can then take action on the incident because they have access to one of the device groups involved. However, global SOC sees several different incidents by device group instead of one incident. We don't recommend turning on this setting unless doing so outweighs the benefits of incident correlation across the entire organization.+The scoped device group correlation setting can be used for scenarios where local SOC operations would like to limit alert correlations only to device groups that they can access. When the scoped device group correlation setting is turned on, an incident composed of alerts that cross-device groups is no longer considered a single incident. The local SOC can then take action on the incident because they have access to one of the device groups involved. However, global SOC sees several different incidents by device group instead of one incident. We don't recommend turning on this setting unless doing so outweighs the benefits of incident correlation across the entire organization. > [!NOTE]-> - Changing this setting impacts future alert correlations only. >+> - Changing this setting impacts future alert correlations only. > - Device group creation is supported in Defender for Endpoint Plan 1 and Plan 2. ## Enable EDR in block mode -Endpoint detection and response (EDR) in block mode provides protection from malicious artifacts, even when Microsoft Defender Antivirus is running in passive mode. When turned on, EDR in block mode blocks malicious artifacts or behaviors that are detected on a device. EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post breach.+Endpoint detection and response (EDR) in block mode provides protection from malicious artifacts, even when Microsoft Defender Antivirus is running in passive mode. When EDR in block mode is turned on, it blocks malicious artifacts or behaviors that are detected on a device. EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post breach. ## Automatically resolve alerts Turn on the auto-resolve alerts setting to automatically resolve alerts where no threats were found or where detected threats were remediated. If you don't want to have alerts auto resolved, you'll need to manually turn off the feature. > [!NOTE]+> > - The result of the auto-resolve action may influence the Device risk level calculation which is based on the active alerts found on a device. > - If a security operations analyst manually sets the status of an alert to "In progress" or "Resolved" the auto-resolve capability will not overwrite it. <a name="allow-or-block-file"></a> ## Configure allow or block file settings -Blocking is only available if your organization fulfills these requirements:+To use this feature, your organization must meet these requirements: -- Uses Microsoft Defender Antivirus as the active antimalware solution and,-- The cloud-based protection feature is enabled+- Microsoft Defender Antivirus is the active antimalware solution.+- Cloud-based protection is enabled. -The allow or block file feature enables you to block potentially malicious files in your network. Blocking a file will prevent it from being read, written, or executed on devices in your organization.+This feature lets you block harmful files in your network. When you block a file, devices in your organization can't read, write, or run it. -To turn **Allow or block** files on:+To turn on **Allow or block** files: -1. In the Microsoft Defender portal, in the navigation pane, select **Settings** \> **Endpoints** \> **General** \> **Advanced features** \> **Allow or block file**.+1. In the Microsoft Defender portal, select **Settings** \> **Endpoints** \> **General** \> **Advanced features** \> **Allow or block file**. 1. Toggle the setting between **On** and **Off**.- + a. :::image type="content" source="/defender/media/alloworblockfile.png" alt-text="The Endpoints screen" lightbox="/defender/media/alloworblockfile.png"::: 1. Select **Save preferences** at the bottom of the page. -1. After turning on this feature, you can [block files](respond-file-alerts.md#allow-or-block-file) via the **Add Indicator** tab on a file's profile page.+1. After you turn on this feature, you can [block files](respond-file-alerts.md#allow-or-block-file) from the **Add Indicator** tab on a file's profile page. ## Hide potential duplicate device records -By enabling the hide potential duplicate device records feature, you can ensure that you're seeing the most accurate information about your devices by hiding potential duplicate device records. There are different reasons duplicate device records might occur, for example, the device discovery capability in Microsoft Defender for Endpoint might scan your network and discover a device that's already onboarded or has recently been offboarded.+Turn on this feature to hide duplicate device records so you see only the most accurate data for each device. Duplicates can happen for many reasons. For example, device discovery might scan your network and find a device that is already onboarded or was recently offboarded. -The hide potential duplicate device records feature identifies potential duplicate devices based on their hostname and last seen time. The duplicate devices will be hidden from multiple experiences in the portal, such as, the Device Inventory, Microsoft Defender Vulnerability Management pages, and Public APIs for machine data, leaving the most accurate device record visible. However, the duplicates will still be visible in global search, advanced hunting, alerts, and incidents pages.+This feature matches duplicates by hostname and last seen time. It hides them from the Device Inventory, Microsoft Defender Vulnerability Management pages, and Public APIs for machine data. The most accurate record stays visible. Duplicates still appear in global search, advanced hunting, alerts, and incidents pages. -The hide potential duplicate device records setting is turned on by default and is applied tenant wide. If you don't want to hide potential duplicate device records, you'll need to manually turn off the feature.+This setting is on by default and applies tenant wide. To show duplicate records, turn off the feature manually. <a name="custom-network-indicators"></a> ## Configure custom network indicators Turning on custom network indicators allows you to create indicators for IP addresses, domains, or URLs, which determine whether they'll be allowed or blocked based on your custom indicator list. -To use this feature, devices must be running Windows 10 version 1709 or later, or Windows 11. +To use this feature, devices must be running Windows 10 version 1709 or later, or Windows 11. For more information, see [Overview of indicators](indicators-overview.md). @@ -101,7 +104,7 @@ For more information, see [Overview of indicators](indicators-overview.md). <a name="tamper-protection"></a> ## Enable tamper protection -During some kinds of cyber attacks, bad actors try to disable security features, such as antivirus protection, on your machines. Bad actors like to disable your security features to get easier access to your data, to install malware, or to otherwise exploit your data, identity, and devices. Tamper protection essentially locks Microsoft Defender Antivirus and prevents your security settings from being changed through apps and methods.+During cyber attacks, attackers might try to turn off security features like antivirus protection on your devices. They do this to access your data, install malware, or exploit your identity and devices. Tamper protection locks Microsoft Defender Antivirus and stops your security settings from being changed by apps or other methods. For more information, including how to configure tamper protection, see [Protect security settings with tamper protection](prevent-changes-to-security-settings-with-tamper-protection.md). @@ -118,22 +121,22 @@ For more information, see [Investigate a user account](investigate-user.md). <a name="skype-for-business-integration"></a> ## Configure Skype for Business integration -Enabling the Skype for Business integration gives you the ability to communicate with users using Skype for Business, email, or phone. This activation can be handy when you need to communicate with the user and mitigate risks.+Enabling the Skype for Business integration gives you the ability to communicate with users using Skype for Business, email, or phone. The Skype for Business integration can be handy when you need to communicate with the user and mitigate risks. > [!NOTE]-> When a device is being isolated from the network, there's a pop-up where you can choose to enable Outlook and Skype communications which allows communications to the user while they are disconnected from the network. This setting applies to Skype and Outlook communication when devices are in isolation mode.+> When a device is being isolated from the network, there's a pop-up where you can choose to enable Outlook and Skype communications which allows communications to the user while they are disconnected from the network. The Outlook and Skype communications option applies only when devices are in isolation mode. <a name="microsoft-defender-for-cloud-apps"></a> ## Configure Microsoft Defender for Cloud Apps integration -Enabling this setting forwards Defender for Endpoint signals to Microsoft Defender for Cloud Apps to provide deeper visibility into cloud application usage. Forwarded data is stored and processed in the same location as your Defender for Cloud Apps data.+Enabling the Microsoft Defender for Cloud Apps integration forwards Defender for Endpoint signals to Microsoft Defender for Cloud Apps to provide deeper visibility into cloud application usage. Forwarded data is stored and processed in the same location as your Defender for Cloud Apps data. For more information, see [Microsoft Defender for Cloud Apps overview](/defender-cloud-apps/what-is-defender-for-cloud-apps). <a name="web-content-filtering"></a> ## Configure web content filtering -Block access to websites containing unwanted content and track web activity across all domains. To specify the web content categories you want to block, create a [web content filtering policy](https://security.microsoft.com/preferences2/web_content_filtering_policy). Ensure you've network protection in block mode when deploying the [Microsoft Defender for Endpoint security baseline](https://devicemanagement.microsoft.com/#blade/Microsoft_Intune_Workflows/SecurityBaselineSummaryMenu/overview/templateType/2).+Block access to websites containing unwanted content and track web activity across all domains. Before you deploy the [Microsoft Defender for Endpoint security baseline](https://devicemanagement.microsoft.com/#blade/Microsoft_Intune_Workflows/SecurityBaselineSummaryMenu/overview/templateType/2), ensure network protection is in block mode. To specify the web content categories you want to block, create a [web content filtering policy](https://security.microsoft.com/preferences2/web_content_filtering_policy). <a name="unified-audit-log"></a> ## Enable the unified audit log@@ -150,19 +153,18 @@ Helps you find unmanaged devices connected to your corporate network without the ## Download quarantined files -Backup quarantined files in a secure and compliant location so they can be downloaded directly from quarantine. The **Download file** button will always be available in the file page. This setting is turned on by default. [Learn more about requirements](respond-file-alerts.md#download-quarantined-files)+Backup quarantined files in a secure and compliant location so they can be downloaded directly from quarantine. The **Download file** button is always available in the file page. The download quarantined files setting is turned on by default. [Requirements for downloading quarantined files](respond-file-alerts.md#download-quarantined-files) ## Default to streamlined connectivity when onboarding devices in the Defender portal -The streamlined connectivity setting will set the default onboarding package to [streamlined connectivity](configure-device-connectivity.md) for applicable operating systems. You still have the option to use the standard onboarding package within the onboarding page, but you must specifically select it in the drop-down.-+This setting makes [streamlined connectivity](configure-device-connectivity.md) the default onboarding package for supported operating systems. You can still use the standard package, but you need to select it from the drop-down on the onboarding page. <a name="live-response"></a> ## Enable live response Turn on this feature so that users with the appropriate permissions can start a live response session on devices. -For more information about role assignments, see [Create and manage roles](user-roles.md).+To assign roles for live response, see [Create and manage roles](user-roles.md). <a name="live-response-for-servers"></a> ## Enable live response for servers@@ -176,24 +178,26 @@ For more information about role assignments, see [Create and manage roles](user- Enabling this feature allows you to run unsigned scripts in a live response session. -## Automatic attack disruption+<a name="automatic-attack-disruption"></a>+## Configure automatic attack disruption -Automatic attack disruption disrupts attacks by automatically containing compromised assets that the attacker is using. It limits lateral movement early on, thereby reducing the overall impact of an attack, both on the associated costs and on loss of productivity. At the same time, it leaves security operations teams in complete control of investigating, remediating, and bringing assets back online. For more information, see [Automatic attack disruption in Microsoft Defender](/defender-xdr/automatic-attack-disruption).+Automatic attack disruption stops attacks by containing compromised assets that the attacker controls. It limits lateral movement early, which reduces the cost and productivity loss from an attack. Security operations teams keep full control to investigate, fix issues, and bring assets back online. For more information, see [Automatic attack disruption in Microsoft Defender](/defender-xdr/automatic-attack-disruption). ## Share endpoint alerts with Microsoft Compliance Center -This setting forwards endpoint security alerts and their triage status to Microsoft Purview portal, allowing you to enhance insider risk management policies with alerts and remediate internal risks before they cause harm. Forwarded data is processed and stored in the same location as your Office 365 data.+The endpoint alert sharing setting sends endpoint security alerts and their triage status to the Microsoft Purview portal. You can use these alerts to improve insider risk management policies and address internal risks before they cause harm. Forwarded data is stored in the same location as your Office 365 data. -After configuring the [Security policy violation indicators](/microsoft-365/compliance/insider-risk-management-settings#indicators) in the insider risk management settings, Defender for Endpoint alerts will be shared with insider risk management for applicable users.+After you set up the [policy indicators](/purview/insider-risk-management-settings-policy-indicators) in insider risk management settings, Defender for Endpoint shares alerts with insider risk management for applicable users. -## Microsoft Intune connection+<a name="microsoft-intune-connection"></a>+## Configure the Microsoft Intune connection -Defender for Endpoint can be integrated with [Microsoft Intune](/intune/intune-service/fundamentals/what-is-intune) to [enable device risk-based conditional access](/intune/intune-service/protect/advanced-threat-protection). When you [turn on this feature](configure-conditional-access.md), you'll be able to share Defender for Endpoint device information with Intune, enhancing policy enforcement.+You can integrate Defender for Endpoint with [Microsoft Intune](/intune/intune-service/fundamentals/what-is-intune) to [enable device risk-based conditional access](/intune/intune-service/protect/advanced-threat-protection). When you [configure Conditional Access](configure-conditional-access.md), Defender for Endpoint shares device data with Intune to help enforce policies. > [!IMPORTANT]-> You'll need to enable the integration on both Intune and Defender for Endpoint to use this feature. For more information on specific steps, see [Configure Conditional Access in Defender for Endpoint](configure-conditional-access.md).+> You must enable this integration in both Intune and Defender for Endpoint. For detailed steps, see [Configure Conditional Access in Defender for Endpoint](configure-conditional-access.md). -This feature is only available if you've the following prerequisites:+This feature requires the following: - A licensed tenant for Enterprise Mobility + Security E3, and Windows E5 (or Microsoft 365 Enterprise E5) - An active Microsoft Intune environment, with Intune-managed Windows devices [Microsoft Entra joined](/azure/active-directory/devices/concept-azure-ad-join/).@@ -206,25 +210,23 @@ You can **Turn on** Authenticated telemetry to prevent spoofing telemetry into y <a name="preview-features"></a> ## Enable preview features -Learn about new features in the Defender for Endpoint preview release. +Learn about new features in the Defender for Endpoint preview release. Try upcoming features by turning on the preview experience. You'll have access to upcoming features, which you can provide feedback on to help improve the overall experience before features are generally available. -If you already have preview features turned on, manage your settings from the main Defender XDR settings. +If you already have preview features turned on, manage your settings from the main Defender XDR settings. For more information, see [Microsoft Defender XDR preview features](/defender-xdr/preview) <a name="endpoint-attack-notifications"></a> ## Configure Endpoint Attack Notifications -[Endpoint Attack Notifications](endpoint-attack-notifications.md) enable Microsoft to actively hunt for critical threats to be prioritized based on urgency and impact over your endpoint data. +[Endpoint Attack Notifications](endpoint-attack-notifications.md) let Microsoft hunt for critical threats in your endpoint data. Threats are ranked by urgency and impact. -For proactive hunting across the full scope of Microsoft Defender XDR, including threats that span email, collaboration, identity, cloud applications, and endpoints, [learn more](https://aka.ms/DefenderExpertsForHuntingGetStarted) about Microsoft Defender Experts.+For proactive hunting across Microsoft Defender XDR, including threats that span email, collaboration, identity, cloud apps, and endpoints, [get started with Microsoft Defender Experts](https://aka.ms/DefenderExpertsForHuntingGetStarted). <a name="related-topics"></a> ## Related content - [Update data retention settings](preferences-setup.md) - [Configure alert notifications](/defender-xdr/configure-email-notifications)-- 