Microsoft Unified SecOps Platform
General

Defender Portal

In brief

The overview now refers to Microsoft Threat Intelligence and describes capabilities in Microsoft Defender XDR and Microsoft Sentinel that aggregate and enrich threat data from multiple sources.

What Defender admins need to know

Administrators should use the updated terminology when referencing threat-intelligence capabilities.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

--- | --- Microsoft Defender XDR

Detect and respond to cybersecurity threats. | Defender XDR includes a suite of services that come together in the Defender portal to provide unified threat protection across the enterprise.

Defender XDR services collect, correlate, and analyze threat data and signals across endpoints and devices, identities, email, apps, and OT/IoT assets. In the portal you can review, investigate, and respond to security alerts and incidents, automatically disrupt attacks, and proactively hunt for threats.

Learn more about Defender XDR in the Defender portal. Microsoft Sentinel

Collect, analyze, and manage security data at scale using automation and orchestration.| Microsoft Sentinel fully integrates with Defender XDR in the Defender portal, providing additional threat protection capabilities such as attack disruption, unified entities and incidents, and SOC optimization.

For more information, see Microsoft Sentinel in the Defender portal. Microsoft Defender Threat Intelligence

Integrate threat intelligence into SOC operations. | The Defender Threat Intelligence platform extends the threat intelligenceMicrosoft Threat Intelligence capabilities that are included in Microsoft Defender XDR and Microsoft Sentinel.

Gather
Sentinel aggregate and enrich threat data from multiple sources to provide a pool of threat intelligence signals and data.sources. Security teams use this data to understand adversary activities,activity, analyze attacks, investigate indicators of compromise, and hunt for security threats.

For more information, see Microsoft Threat Intelligence in Microsoft Defender XDR.

Microsoft Security Exposure Management

Proactively reduce security risk.| Use Security Exposure Management to reduce organizational attack surfaces and remediate security posture.

Continuously discover assets and data to get a comprehensive view of security across business assets. With the additional data context that Security Exposure Management provides, you can clearly visualize, analyze, and remediate weak areas of security. Microsoft Defender for Cloud

Protect cloud workloads. | Defender for Cloud improves multicloud security posture, and protects cloud workloads against threats.

Defender for Cloud integrates into the Defender portal to provide a unified view of cloud security alerts, and a single location for investigations.