Brings Defender products such as Cloud Apps, Identity, Office 365 and Endpoint together, joining their signals into incidents that span the time before and after a breach. Includes advanced hunting and automatic disruption of attacks.
Also called Microsoft 365 Defender, Microsoft 365 Defender.
Read more: Microsoft Learn
In the Ultra Transcenders books
SC-500SC-900AB-900SC-200SC-401
Each book explains Microsoft Defender XDR in context, with comparison tables and the common traps.
Terms in this definition
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- Microsoft 365
Formerly Office 365, Microsoft's software-as-a-service productivity suite. A Microsoft Entra tenant provides its identity, and its data is not governed by Azure RBAC.
- Span
One operation inside a trace, such as a single LLM call or prompt flow node, carrying attributes plus start and end times. Nested spans reveal the order of calls.
- Advanced hunting
Threat-hunting feature of the Microsoft Defender portal that runs KQL over 30 days of raw Defender XDR data, plus onboarded Sentinel data, and supports custom detections. It finds activity after it happens rather than blocking it.
Related terms
- Automatic attack disruption
A Microsoft Defender XDR feature that links signals into a high-confidence incident and, while ransomware, business email compromise or a similar attack is still in progress, contains the affected accounts and devices on its own. Security staff can reverse these actions.
- DisruptionAndResponseEvents
Lets you query, in advanced hunting, what automatic attack disruption has done across Microsoft Defender XDR. It is still a preview feature.
- Incident
A case that Microsoft Defender XDR or Microsoft Sentinel builds by correlating several alerts that look like parts of one attack. It lists the assets involved and the evidence, and analysts can assign it and update its status as they investigate.
- Unified security operations
An experience in the Microsoft Defender portal that combines Microsoft Sentinel with Microsoft Defender XDR so that threats can be detected, investigated and responded to in one place. Once 31 March 2027 has passed, Sentinel will be offered only in the Defender portal.
- XDR
Extended detection and response: pulling together and linking threat signals from several areas, such as email, devices, identities and apps, instead of examining each in isolation. Microsoft offers this as Microsoft Defender XDR.