What Microsoft Defender means in practice
Defender is the security platform most Microsoft 365 customers already own without fully deploying. The name covers several distinct products, and confusion between them is common. Microsoft Defender Antivirus is the built-in antimalware engine in Windows. Microsoft Defender for Endpoint adds endpoint detection and response, attack surface reduction, vulnerability management and automated investigation. Defender for Office 365 protects email and collaboration with safe links, safe attachments, anti-phishing policies and automated response. Defender for Identity monitors on-premises Active Directory for lateral movement and credential attacks. Defender for Cloud Apps governs sanctioned and unsanctioned SaaS usage.
The value of the family sits in correlation. A phishing email delivered to one mailbox, a credential used from an unusual location, and a suspicious process on a laptop are three low-confidence signals individually; joined into a single incident by Defender XDR they describe an intrusion. That correlation is why replacing point products with the Microsoft stack often improves detection even where the individual products are comparable.
Licensing determines which parts you have. Business Premium includes Defender for Office 365 Plan 1 and Defender for Business, which covers most endpoint protection needs for smaller organisations. E3 does not include Defender for Endpoint Plan 2 without an add-on. E5 includes the full stack including Defender for Identity and Cloud Apps. Buying E5 and leaving it unconfigured is one of the more expensive mistakes we are called in to correct.
Configuration and tuning matter more than deployment. Default policies are deliberately conservative; anti-phishing impersonation protection, safe attachment policies, attack surface reduction rules and device control all need to be set against how the organisation actually works. Alerts then need somebody watching them — a platform that detects an intrusion at 2am and reports it to an unmonitored inbox has not helped anyone.
How we help with this
Related terms
- APRA CPS 230CPS 230 is the APRA prudential standard on operational risk management.
- APRA CPS 234CPS 234 is the APRA prudential standard on information security.
- Azure Virtual Desktop (AVD)Azure Virtual Desktop is Microsoft's cloud virtual desktop infrastructure service.
- Conditional AccessConditional Access is the policy engine in Microsoft Entra ID that decides what happens after a sign-in is authenticated.
