At security.microsoft.com, one place to work with Defender XDR, Microsoft Sentinel, Defender for Cloud Apps and further Microsoft security products.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Defender portal in context, with comparison tables and the common traps.
Terms in this definition
- XDR
Extended detection and response: pulling together and linking threat signals from several areas, such as email, devices, identities and apps, instead of examining each in isolation. Microsoft offers this as Microsoft Defender XDR.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
Related terms
- Action center
Remediation steps taken against devices, mailboxes and identities, whether triggered by automated investigations, attack disruption or a person, are gathered on this Microsoft Defender portal page. Pending items can be approved or rejected here, and finished ones reversed.
- Advanced hunting
Threat-hunting feature of the Microsoft Defender portal that runs KQL over 30 days of raw Defender XDR data, plus onboarded Sentinel data, and supports custom detections. It finds activity after it happens rather than blocking it.
- Cloud Secure Score
Shown in the Microsoft Defender portal, this posture score weights outstanding cloud recommendations by how risky each is, by whether assets face the internet and similar factors, and by how critical those assets are. The Azure portal keeps the older classic score.
- Intel explorer
Where analysts in the Microsoft Defender portal go to search threat intelligence by type, whether a threat actor, campaign, indicator, tool or vulnerability. Threat analytics reports can be opened from there as well.
- Multitenant management
Lets analysts see incidents, alerts, cases and advanced hunting from many tenants and their Sentinel workspaces together, at mto.security.microsoft.com in the Microsoft Defender portal.
- Security Copilot embedded experience
Security Copilot surfaced within another product, for example the Microsoft Defender portal. There is no workspace picker here, unlike the standalone portal; the tenant's designated workspace is always used.
- Threat analytics
Analysis written by Microsoft's security researchers about current attackers and campaigns, indicating whether a given threat is affecting your own organisation. These reports now appear in Intel explorer in the Microsoft Defender portal.
- Unified security operations
An experience in the Microsoft Defender portal that combines Microsoft Sentinel with Microsoft Defender XDR so that threats can be detected, investigated and responded to in one place. Once 31 March 2027 has passed, Sentinel will be offered only in the Defender portal.