Key takeaways

Microsoft Defender is a product family covering endpoints, email, identities and cloud services.
Defender for Business provides strong endpoint security for many small and medium organisations.
Configuration, device coverage and alert ownership matter as much as licensing.
Attack surface reduction and email protection should be tested and progressively enforced.

What is Microsoft Defender?

Microsoft Defender is the umbrella name for Microsoft's security products across endpoints, Microsoft 365, identities, cloud applications and cloud infrastructure. These services share security signals through the Microsoft Defender portal and, where licensing allows, can correlate related activity into incidents.

For an Australian small or medium-sized business, the most relevant services are commonly Microsoft Defender for Business, Microsoft Defender for Office 365 and the integrated Microsoft Defender XDR experience. Larger or more complex organisations may also use Defender for Endpoint Plan 2, Defender for Identity, Defender for Cloud Apps and Microsoft Defender for Cloud.

Defender works best as an operating security system: prevention, detection, investigation and response must all be designed, owned and maintained.

Understanding the Microsoft Defender product family

Similar product names can make licensing and architecture confusing. The table below explains the role of the main services without assuming that every feature is included in every Microsoft subscription.

Service Primary purpose Typical capabilities
Microsoft Defender Antivirus Built-in antimalware protection for Windows Real-time protection, cloud-delivered protection, scanning and remediation
Microsoft Defender for Business Endpoint security for small and medium-sized organisations Endpoint detection and response, vulnerability management, ASR, automated investigation and central management
Microsoft Defender for Endpoint Enterprise endpoint security Advanced prevention, detection, investigation, response and threat hunting, depending on plan
Microsoft Defender for Office 365 Email and collaboration protection Anti-phishing, impersonation protection, Safe Links, Safe Attachments and investigation features, depending on plan
Microsoft Defender for Identity Identity threat detection Detection of suspicious identity activity across supported directory environments
Microsoft Defender for Cloud Apps Cloud application visibility and control Application discovery, session controls, anomaly detection and information protection integrations
Microsoft Defender XDR Unified investigation and response Cross-domain incidents, advanced hunting, alert correlation and automated response, subject to licensing

Licensing and coverage

Microsoft 365 Business Premium is often a strong starting point for organisations with up to 300 users because it includes Microsoft Defender for Business and Microsoft Defender for Office 365 Plan 1. These provide endpoint and email protection capabilities that many businesses already own but have not fully deployed.

Licensing should still be verified at the service-plan level. Different plans provide different investigation, automation, hunting and retention capabilities. Coverage also needs to account for servers, shared devices, contractors, mobile platforms, personally owned devices and any users on mixed licence arrangements.

Confirm user entitlements

Review which licences are assigned, which service plans are enabled and whether every protected user is correctly covered.

Confirm device entitlements

Include Windows, macOS, mobile devices, servers and any devices managed outside the standard Microsoft 365 model.

Map required capabilities

Identify whether the business needs advanced hunting, longer data retention, identity sensors or cloud-app controls.

Avoid shelfware

Prioritise deployment and operational ownership before purchasing additional features that the team cannot yet use effectively.

Build the endpoint protection foundation first

Endpoint security begins with complete onboarding and healthy telemetry. A sophisticated policy provides little value when laptops, desktops or servers are missing, inactive, misconfigured or sending incomplete data.

Defender should be integrated with Intune where appropriate so that security configuration, device compliance and access decisions work together. Security settings management can also help manage supported devices that are not fully enrolled in Intune, but the management design should be documented and consistent.

A practical endpoint security operating model

Onboard every supported endpoint Establish an accurate device inventory and confirm sensor health, operating-system support and active reporting.
Apply preventive controls Configure antivirus, firewall, tamper protection, web protection, device control and attack surface reduction.
Measure exposure and vulnerabilities Review software inventory, security recommendations, high-risk weaknesses and remediation ownership.
Detect, investigate and contain Assign alert ownership, investigate incidents and use isolation or other response actions when appropriate.

Core endpoint settings to verify

  • Real-time and cloud-delivered protection are enabled and reporting correctly.
  • Tamper protection prevents unauthorised security-setting changes.
  • Potentially unwanted application protection is configured deliberately.
  • Firewall profiles are enabled and exceptions are documented.
  • Endpoint detection and response is active across every supported device.
  • Automated investigation and remediation settings match the organisation's risk tolerance.
  • Device isolation, live response and containment permissions are restricted to appropriate roles.

Attack surface reduction rules

Attack surface reduction rules target behaviours that attackers commonly use, such as malicious scripts, credential theft, executable content launched from email or Office applications, and abuse of trusted system tools.

ASR rules should not be enabled blindly across every device. Microsoft provides audit, warn and block options for many rules. A sensible rollout uses pilot groups, reviews telemetry, resolves genuine compatibility issues and then progressively moves suitable rules into enforcement.

Establish a representative pilot

Include users, applications and device types that reflect the broader environment, not only IT staff.

Collect audit data

Identify legitimate business processes that would be affected and separate them from genuinely risky behaviour.

Use precise exclusions

Avoid broad folder or process exclusions. Document the owner, reason, scope and review date for every exception.

Move rules into warn or block

Enforce controls in stages and monitor incidents, support requests and business impact after each change.

Review continuously

Retest exclusions and adjust the policy as software, business processes and Microsoft recommendations change.

Protect email and collaboration with Defender for Office 365

Email remains a common initial access path. Defender for Office 365 extends the built-in protections in Exchange Online with stronger anti-phishing, impersonation protection, Safe Links and Safe Attachments capabilities.

Microsoft generally recommends using its Standard or Strict preset security policies as a baseline, with carefully designed exceptions where required. SPF, DKIM and DMARC should also be configured for active and inactive domains because policy alone cannot compensate for weak email authentication.

Safe Links

Scans and evaluates supported links, including time-of-click checks in email and supported collaboration experiences.

Safe Attachments

Analyses suspicious files in a protected environment to help identify unknown malware and malicious behaviour.

Anti-phishing

Uses spoof intelligence, mailbox intelligence and impersonation controls to identify deceptive messages.

Threat response

Supports investigation, quarantine, submissions, reporting and automated actions depending on the licensed plan.

Email protection checks

  • Every user is included in the intended preset or custom protection policy.
  • Executives, finance staff and other high-risk users receive appropriate impersonation protection.
  • Safe Links and Safe Attachments policies cover email, Teams and supported Microsoft 365 workloads as intended.
  • User-reported phishing is configured and routed to a monitored process.
  • Quarantine permissions, notifications and release processes are appropriate.
  • Tenant Allow/Block List entries and other overrides are reviewed for risky or expired exceptions.
  • SPF, DKIM and DMARC are implemented and monitored for every sending domain.

Use Microsoft Defender XDR as the investigation layer

Microsoft Defender XDR brings security information together in the Microsoft Defender portal. When the required services and licences are present, alerts from endpoints, email, identities and cloud applications can be correlated into incidents that show a broader attack story.

The unified portal does not remove the need for operational discipline. Teams still need alert triage standards, role-based access, evidence handling, escalation paths and a clear definition of when to isolate a device, disable an account or involve external incident-response specialists.

Capability Why it matters Operational question
Incident correlation Groups related alerts into a broader attack narrative Who validates and owns the incident?
Advanced hunting Allows proactive queries across available security data Does the team have the skills and time to use it?
Automated investigation Can analyse evidence and take or recommend remediation actions What automation level is approved?
Response actions Supports containment such as device isolation and account actions Who is authorised to contain business systems?

Alert management and incident response

A Defender deployment is incomplete until someone is responsible for its alerts. The organisation should define who monitors the portal, how often it is checked, what constitutes a critical event and when a case must be escalated.

Named ownership

Assign primary and backup owners for endpoint, identity and email security alerts.

Response targets

Define realistic acknowledgement and investigation targets based on severity and business impact.

Response playbooks

Document steps for phishing, compromised accounts, malware, ransomware and suspicious administrator activity.

Testing and exercises

Run tabletop and technical tests to confirm that permissions, contacts and containment actions work under pressure.

Minimum incident workflow

  1. Validate the alert and identify affected users, devices, applications and data.
  2. Determine severity, scope, business impact and whether active attacker activity is continuing.
  3. Contain the threat using proportionate actions such as isolation, session revocation or account restriction.
  4. Preserve relevant evidence and document decisions, timestamps and actions.
  5. Remove persistence, remediate vulnerabilities and restore affected services safely.
  6. Complete a post-incident review and update policies, playbooks and training.

A practical Microsoft Defender deployment roadmap

Organisations often try to deploy every feature at once. A staged roadmap produces better results because foundational coverage and ownership are established before advanced controls are enforced.

Discover and design

Confirm licences, users, devices, platforms, servers, existing security products, regulatory needs and response responsibilities.

Onboard and validate

Connect supported endpoints and workloads, verify sensor health and reconcile the Defender inventory against authoritative asset records.

Apply baseline protection

Configure antivirus, EDR, tamper protection, firewall, email security and role-based access using tested baselines.

Harden progressively

Deploy ASR rules, web protection, device control and stricter email policies through pilots and controlled enforcement.

Operationalise response

Build alert queues, response targets, playbooks, escalation contacts, reporting and regular security review meetings.

Measure and improve

Track coverage, exposure, unresolved recommendations, alert trends, response performance and recurring control failures.

Microsoft Defender review checklist

Use this checklist as a starting point for a structured review. It should be adapted to the organisation's licences, operating systems, applications, compliance obligations and risk profile.

Confirm current Microsoft security licences and service-plan assignments.
Reconcile the Defender device inventory against the authoritative asset list.
Identify inactive, unsupported, duplicated or unhealthy device records.
Verify antivirus, cloud protection, EDR, firewall and tamper protection status.
Review vulnerability and security recommendations by exposure and business criticality.
Assess ASR rules, deployment modes, exclusions and unresolved audit findings.
Review Intune security policies, conflicts and compliance enforcement.
Confirm all intended users are protected by email and collaboration security policies.
Review Safe Links, Safe Attachments, anti-phishing and impersonation settings.
Review email authentication and risky allow-list or override entries.
Confirm alerts have owners, escalation paths and documented response targets.
Test device isolation, account containment and evidence-preservation procedures.
Review security roles, portal permissions and privileged access.
Document exceptions with an owner, reason, expiry date and compensating controls.
Create a prioritised improvement roadmap with accountable owners and due dates.

Common Microsoft Defender deployment mistakes

Assuming defaults are enough

Built-in protection is valuable, but it does not replace a design matched to the organisation's users, devices and risk.

Ignoring incomplete coverage

Unmanaged laptops, servers, contractors and stale records can create blind spots that dashboards do not make obvious.

Leaving controls in audit mode

Audit data is useful during rollout, but controls that never reach enforcement may not stop an attack.

No one owns the alerts

Technology cannot compensate for an unmonitored queue or unclear authority to investigate and contain threats.

Broad exclusions

Convenient exclusions can undermine multiple controls. They should be precise, documented and reviewed regularly.

Buying before deploying

Additional licensing has limited value when existing endpoint and email capabilities are not fully configured or operated.

Frequently asked questions

Official Microsoft references

Microsoft product features and licensing can change. Confirm current requirements against the official documentation before making purchasing or deployment decisions.

Need help reviewing Microsoft Defender?

Fedelta can assess your current licensing, endpoint coverage, email protection, security policies and incident-response readiness, then create a prioritised improvement roadmap.

Discuss your environment