Defender Portal
In brief
The overview now refers to Microsoft Threat Intelligence and describes capabilities in Microsoft Defender XDR and Microsoft Sentinel that aggregate and enrich threat data from multiple sources.
What Defender admins need to know
Administrators should use the updated terminology when referencing threat-intelligence capabilities.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
--- | ---
Microsoft Defender XDR
Detect and respond to cybersecurity threats. | Defender XDR includes a suite of services that come together in the Defender portal to provide unified threat protection across the enterprise.
Defender XDR services collect, correlate, and analyze threat data and signals across endpoints and devices, identities, email, apps, and OT/IoT assets. In the portal you can review, investigate, and respond to security alerts and incidents, automatically disrupt attacks, and proactively hunt for threats.
Learn more about Defender XDR in the Defender portal.
Microsoft Sentinel
Collect, analyze, and manage security data at scale using automation and orchestration.| Microsoft Sentinel fully integrates with Defender XDR in the Defender portal, providing additional threat protection capabilities such as attack disruption, unified entities and incidents, and SOC optimization.
For more information, see Microsoft Sentinel in the Defender portal.
Microsoft Defender Threat Intelligence
Integrate threat intelligence into SOC operations. | The Defender Threat Intelligence platform extends the threat intelligenceMicrosoft Threat Intelligence capabilities that are included in Microsoft Defender XDR and Microsoft Sentinel.Sentinel aggregate and enrich threat data from multiple
Gathersources to provide a pool of threat intelligence signals and data.sources. Security teams use this data to understand adversary activities,activity, analyze attacks, investigate indicators of compromise, and hunt for security threats.
For more information, see Microsoft Threat Intelligence in Microsoft Defender XDR.
Microsoft Security Exposure Management
Proactively reduce security risk.| Use Security Exposure Management to reduce organizational attack surfaces and remediate security posture.
Continuously discover assets and data to get a comprehensive view of security across business assets. With the additional data context that Security Exposure Management provides, you can clearly visualize, analyze, and remediate weak areas of security.
Microsoft Defender for Cloud
Protect cloud workloads. | Defender for Cloud improves multicloud security posture, and protects cloud workloads against threats.
Defender for Cloud integrates into the Defender portal to provide a unified view of cloud security alerts, and a single location for investigations.
@@ -33,7 +33,7 @@ Service | Details --- | --- **Microsoft Defender XDR**<br/><br/> Detect and respond to cybersecurity threats. | [Defender XDR includes a suite of services](/defender-xdr/microsoft-365-defender) that come together in the Defender portal to provide unified threat protection across the enterprise.<br/><br/> Defender XDR services collect, correlate, and analyze threat data and signals across endpoints and devices, identities, email, apps, and OT/IoT assets. In the portal you can review, investigate, and respond to security alerts and incidents, automatically disrupt attacks, and proactively hunt for threats.<br/><br/>[Learn more](defender-xdr-portal.md) about Defender XDR in the Defender portal. **Microsoft Sentinel**<br/><br/> Collect, analyze, and manage security data at scale using automation and orchestration.| Microsoft Sentinel fully integrates with Defender XDR in the Defender portal, providing additional threat protection capabilities such as attack disruption, unified entities and incidents, and SOC optimization.<br/><br/> For more information, see [Microsoft Sentinel in the Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal).-**Microsoft Defender Threat Intelligence**<br/><br/> Integrate threat intelligence into SOC operations. | The [Defender Threat Intelligence](/defender/threat-intelligence/what-is-microsoft-defender-threat-intelligence-defender-ti) platform extends the threat intelligence capabilities that are included in Defender XDR and Microsoft Sentinel.<br/><br/> Gather data from multiple sources to provide a pool of threat intelligence signals and data. Security teams use this data to understand adversary activities, analyze attacks, and hunt for security threats. +**Microsoft Threat Intelligence**<br/><br/> Integrate threat intelligence into SOC operations. | Microsoft Threat Intelligence capabilities in Microsoft Defender XDR and Microsoft Sentinel aggregate and enrich threat data from multiple sources. Security teams use this data to understand adversary activity, analyze attacks, investigate indicators of compromise, and hunt for threats.<br/><br/>For more information, see [Microsoft Threat Intelligence in Microsoft Defender XDR](/defender-xdr/defender-threat-intelligence). **Microsoft Security Exposure Management**<br/><br/> Proactively reduce security risk.| Use [Security Exposure Management](/security-exposure-management/microsoft-security-exposure-management) to reduce organizational attack surfaces and remediate security posture.<br/><br/> Continuously discover assets and data to get a comprehensive view of security across business assets. With the additional data context that Security Exposure Management provides, you can clearly visualize, analyze, and remediate weak areas of security. **Microsoft Defender for Cloud**<br/><br/> Protect cloud workloads. | [Defender for Cloud](/defender-xdr/microsoft-365-security-center-defender-cloud) improves multicloud security posture, and protects cloud workloads against threats.<br/><br/> Defender for Cloud integrates into the Defender portal to provide a unified view of cloud security alerts, and a single location for investigations. 