Microsoft Unified SecOps Platform
General

Defender Xdr Portal

In brief

The documentation now refers to “Defender XDR” instead of “Defender for XDR” in the automated investigation and response description.

What Defender admins need to know

Administrators will see updated product terminology when reviewing this guidance; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Responding to threats

Defender for XDR provides automated investigation and response capabilities. Automation reduces the volume of alerts that must be handled manually by SOC teams.

As alerts create incidents, automated investigations produce a verdict that determines whether a threat was found. When suspicious and malicious threats are identified, remediation actions include sending a file to quarantine, stopping a process, blocking a URL, or isolating a device.