Microsoft Defender XDR
General

Microsoft 365 Defender Portal

In brief

The page replaces “Microsoft Defender XDR” with “Microsoft Defender” in integration links, feature descriptions, headings, and learning-path text. The documented settings path remains **Settings > Microsoft Defender XDR**.

What Defender admins need to know

Use the updated terminology when referencing these Microsoft Defender portal experiences and documentation.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

What to expect

Microsoft Defender XDR correlates signals from various Microsoft security solutions in the Microsoft Defender portal to help security teams investigate and respond to attacks into a set of unified experiences for:

  • Incidents & alerts
  • Hunting

Incident and alert investigations

Microsoft Defender XDR correlates alerts and events from all Microsoft security solutions across all assets in your entire organization into incidents. Incidents are a collection of alerts that are related to a single threat or attack. Incidents are prioritized based on the severity of the threat and the potential impact on your organization.

:::image type="content" source="media/incidents-ss-incidents.png" alt-text="The Incidents page in the Microsoft Defender portal." lightbox="media/incidents-ss-incidents.png":::

You can build custom detection rules and hunt for specific threats in your environment. Hunting uses a query-based threat hunting tool that lets you proactively inspect events in your organization to locate threat indicators and entities. These rules run automatically to check for, and then respond to, suspected breach activity, misconfigured machines, and other findings.

For more information, see Proactively hunt for threats with advanced hunting in Microsoft Defender.

Actions and submissions

Actions are tasks performed on entities in the Microsoft Defender portal. Actions can be performed on an asset like a device or user, can be performed on a single entity or on multiple entities at once, and be performed manually or automatically.

Automated actions are capabilities within Microsoft Defender XDR that help you address alerts and incidents automatically and speedily respond to attacks. Automated actions include:

Threat analytics

Threat analytics is the Microsoft Defender XDR threat intelligence solution from expert Microsoft security researchers. It's designed to assist security teams to be as efficient as possible while facing emerging threats like:

  • Active threat actors and their campaigns
  • Popular and new attack techniques
  • Common attack surfaces
  • Prevalent malware

Microsoft Defender XDR settings

You can manage settings for Microsoft Defender XDR in the Settings > Microsoft Defender XDR page in the Microsoft Defender portal. The settings page is where you can configure the following:

Training for security analysts

With this learning path from Microsoft Learn, you can understand Microsoft Defender XDR and how it can help identify, control, and remediate security threats.

Training: Mitigate threats using Microsoft Defender XDR