Defender Xdr Portal
In brief
The documentation now refers to “Defender XDR” instead of “Defender for XDR” in the automated investigation and response description.
What Defender admins need to know
Administrators will see updated product terminology when reviewing this guidance; no action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Responding to threats
Defender for XDR provides automated investigation and response capabilities. Automation reduces the volume of alerts that must be handled manually by SOC teams.
As alerts create incidents, automated investigations produce a verdict that determines whether a threat was found. When suspicious and malicious threats are identified, remediation actions include sending a file to quarantine, stopping a process, blocking a URL, or isolating a device.
@@ -66,7 +66,7 @@ Defender XDR provides threat hunting capabilities in the Defender portal. ## Responding to threats -Defender for XDR provides [automated investigation and response](/defender-xdr/m365d-autoir) capabilities. Automation reduces the volume of alerts that must be handled manually by SOC teams. +Defender XDR provides [automated investigation and response](/defender-xdr/m365d-autoir) capabilities. Automation reduces the volume of alerts that must be handled manually by SOC teams. As alerts create incidents, automated investigations produce a verdict that determines whether a threat was found. When suspicious and malicious threats are identified, remediation actions include sending a file to quarantine, stopping a process, blocking a URL, or isolating a device. 