Extended detection and response: pulling together and linking threat signals from several areas, such as email, devices, identities and apps, instead of examining each in isolation. Microsoft offers this as Microsoft Defender XDR.
Also called extended detection and response.
Read more: Microsoft Learn
In the Ultra Transcenders books
SC-900AB-900SC-200SC-300SC-401MD-102ALZ
Each book explains XDR in context, with comparison tables and the common traps.
Terms in this definition
- ACID
Four promises a database transaction makes: atomicity, consistency, isolation and durability. Azure Cosmos DB honours them, with snapshot isolation, only inside one logical partition, using stored procedures, triggers or transactional batch.
- Microsoft Defender XDR
Brings Defender products such as Cloud Apps, Identity, Office 365 and Endpoint together, joining their signals into incidents that span the time before and after a breach. Includes advanced hunting and automatic disruption of attacks.
Related terms
- Advanced hunting
Threat-hunting feature of the Microsoft Defender portal that runs KQL over 30 days of raw Defender XDR data, plus onboarded Sentinel data, and supports custom detections. It finds activity after it happens rather than blocking it.
- Alert tuning
Formerly called alert suppression. Defender XDR lets you write rules so that alerts with matching evidence, for example a given file, process or IP address, are hidden or closed automatically, which is handy for known activity like security testing; Microsoft ships some built-in rules too.
- Custom detection
Microsoft now suggests these Defender XDR rules when creating new detections for Sentinel or Defender XDR. Each is built on an advanced hunting query, runs periodically or in near real time (NRT), raises alerts and may take response actions.
- Enhanced Alert Trigger
Lets AI-generated playbooks start automatically when an alert arrives, whichever workspace it came from and whether its source was Sentinel, Defender or XDR. It is an option for automation rules set across the whole tenant in the Defender portal.
- Fusion
A machine-learning engine in Sentinel that stitches weak signals together into serious incidents spanning several stages of an attack, via one built-in rule called Advanced Multistage Attack Detection. Onboarding Sentinel to the Defender portal turns it off, as the correlation engine in Defender XDR does that job there.
- Incident correlation
Controls whether Sentinel analytics rule alerts get grouped by the Defender XDR correlation engine. For the tenant it starts switched off, but each rule can set its own value.
- Microsoft Defender portal
At security.microsoft.com, one place to work with Defender XDR, Microsoft Sentinel, Defender for Cloud Apps and further Microsoft security products.
- Primary workspace
In the Defender portal, each tenant picks one Microsoft Sentinel workspace whose alerts get correlated with Defender XDR. Any others you onboard count as secondary, and their incidents are handled separately.