4.4.1. Microsoft Defender XDR Services
💡 First Principle: Microsoft Defender XDR is the coordination layer that ingests signals from Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps, correlates related signals across all of them, and presents security teams with a single unified incident and investigation experience — rather than four disconnected alert queues.
| Defender Product | Protects |
|---|---|
| Defender for Office 365 | Email and collaboration content |
| Defender for Endpoint | Devices (laptops, servers, mobile) |
| Defender for Identity | On-premises Active Directory signals |
| Defender for Cloud Apps | SaaS application usage (CASB) |
| Defender Vulnerability Management | Attack surface / unpatched software across devices |
| Defender Threat Intelligence | External threat actor and infrastructure data |
⚠️ Exam Trap: Defender XDR is not a separate agent or install — it's the correlation and incident layer sitting on top of the specialized Defender products, unifying their signals rather than duplicating their function.
Reflection Question: A phishing email leads to a compromised laptop, which is then used to probe the on-premises domain controller. Which three Defender products would each detect part of this attack, and what does Defender XDR add on top of their individual detections?