A phishing email lands in a mailbox. The user clicks. A credential is harvested, a sign-in follows from a new location, and a malicious process starts on a laptop. Seen separately, each event might look minor. Seen together, it is an attack in progress.
Microsoft Defender XDR is built to see them together. This guide explains what it is, how it works and how to deploy it effectively.
Seen together, it is an attack in progress.
What is Microsoft Defender XDR?
Defender XDR is a unified, pre- and post-breach defence suite that coordinates detection, prevention, investigation and response across endpoints, identities, email and applications. It was renamed from Microsoft 365 Defender in 2023 and is managed through the Microsoft Defender portal.
What are the components of Defender XDR?
| Component | Protects | Key capabilities |
|---|---|---|
| Defender for Endpoint | Windows, macOS, Linux, mobile devices | EDR, attack surface reduction, vulnerability management |
| Defender for Office 365 | Email and collaboration | Safe Links, Safe Attachments, anti-phishing, attack simulation |
| Defender for Identity | On-premises Active Directory | Detects lateral movement and credential attacks |
| Defender for Cloud Apps | SaaS applications | Shadow IT discovery, session controls, app governance |
| Entra ID Protection | Cloud identities | Risky sign-ins and users (signals into XDR) |
Licensing varies: Microsoft 365 E5 includes the full suite. Microsoft 365 E3 includes Defender for Endpoint Plan 1 and, since July 2026, Defender for Office 365 Plan 1. Business Premium includes Defender for Business and Defender for Office 365 Plan 1.
Components of Microsoft Defender XDR
Illustration in progress
What is the difference between EDR and XDR?
EDR (endpoint detection and response) focuses on devices. XDR extends detection and response across multiple domains (endpoint, email, identity and cloud apps) and correlates them. Instead of four alerts in four consoles, the analyst sees one incident showing the full attack chain.
EDR vs XDR comparison
Illustration in progress
How does Defender XDR handle an incident?
- Detection: each component raises alerts.
- Correlation: related alerts are grouped into a single incident with an attack story.
- Automated investigation: Defender examines affected entities and gathers evidence.
- Response: actions such as isolating a device, disabling a user, or removing emails from all mailboxes, either automatically or with approval.
- Hunting: analysts use advanced hunting (KQL queries) across 30 days of data for deeper investigation.
How do you deploy Defender XDR well?
- Onboard all endpoints to Defender for Endpoint, ideally through Intune.
- Enable attack surface reduction rules, starting in audit mode.
- Configure Defender for Office 365 presets (Standard or Strict) for anti-phishing, Safe Links and Safe Attachments.
- Deploy Defender for Identity sensors on domain controllers if you still run on-premises Active Directory.
- Connect Defender for Cloud Apps to discover shadow IT and govern OAuth apps.
- Set automation levels for automated investigation and response.
- Integrate with a SIEM such as Microsoft Sentinel if you need broader correlation.
- Define who responds, in-house or managed, around the clock.
Where does Security Copilot fit?
Microsoft Security Copilot uses generative AI inside the Defender portal to summarise incidents, explain scripts, guide response and write hunting queries. It can help analysts work faster, but it does not replace the need for skilled people and well-configured tools.
How Crozaint approaches Defender XDR
Threat detection with Defender XDR is part of the Deploy phase (4–12 weeks) of Crozaint's Microsoft 365 security programme, alongside Entra ID, Intune and Purview. We onboard devices, configure email protection, tune attack surface reduction and set response automation appropriate to your risk appetite.
After deployment, you choose: Crozaint Managed, with 24/7 SOC operations and SLA-backed response, or Your Team Operated, with runbooks, playbooks and training handed over. Both models are reversible.
Common mistakes to avoid
- Owning E5 but running Defender with default settings
- Leaving attack surface reduction rules in audit mode forever
- No one monitoring incidents outside working hours
- Partial endpoint onboarding, leaving blind spots
- Ignoring Defender for Cloud Apps and OAuth app risk
Conclusion
Defender XDR turns scattered alerts into clear incidents. Configure it properly, onboard everything and make sure someone is always watching.
Own Defender but not sure it is configured well? Book a 30-minute discovery call with Crozaint.

