Key takeaways
What is Microsoft Defender?
Microsoft Defender is the umbrella name for Microsoft's security products across endpoints, Microsoft 365, identities, cloud applications and cloud infrastructure. These services share security signals through the Microsoft Defender portal and, where licensing allows, can correlate related activity into incidents.
For an Australian small or medium-sized business, the most relevant services are commonly Microsoft Defender for Business, Microsoft Defender for Office 365 and the integrated Microsoft Defender XDR experience. Larger or more complex organisations may also use Defender for Endpoint Plan 2, Defender for Identity, Defender for Cloud Apps and Microsoft Defender for Cloud.
Defender works best as an operating security system: prevention, detection, investigation and response must all be designed, owned and maintained.
Understanding the Microsoft Defender product family
Similar product names can make licensing and architecture confusing. The table below explains the role of the main services without assuming that every feature is included in every Microsoft subscription.
| Service | Primary purpose | Typical capabilities |
|---|---|---|
| Microsoft Defender Antivirus | Built-in antimalware protection for Windows | Real-time protection, cloud-delivered protection, scanning and remediation |
| Microsoft Defender for Business | Endpoint security for small and medium-sized organisations | Endpoint detection and response, vulnerability management, ASR, automated investigation and central management |
| Microsoft Defender for Endpoint | Enterprise endpoint security | Advanced prevention, detection, investigation, response and threat hunting, depending on plan |
| Microsoft Defender for Office 365 | Email and collaboration protection | Anti-phishing, impersonation protection, Safe Links, Safe Attachments and investigation features, depending on plan |
| Microsoft Defender for Identity | Identity threat detection | Detection of suspicious identity activity across supported directory environments |
| Microsoft Defender for Cloud Apps | Cloud application visibility and control | Application discovery, session controls, anomaly detection and information protection integrations |
| Microsoft Defender XDR | Unified investigation and response | Cross-domain incidents, advanced hunting, alert correlation and automated response, subject to licensing |
Licensing and coverage
Microsoft 365 Business Premium is often a strong starting point for organisations with up to 300 users because it includes Microsoft Defender for Business and Microsoft Defender for Office 365 Plan 1. These provide endpoint and email protection capabilities that many businesses already own but have not fully deployed.
Licensing should still be verified at the service-plan level. Different plans provide different investigation, automation, hunting and retention capabilities. Coverage also needs to account for servers, shared devices, contractors, mobile platforms, personally owned devices and any users on mixed licence arrangements.
Confirm user entitlements
Review which licences are assigned, which service plans are enabled and whether every protected user is correctly covered.
Confirm device entitlements
Include Windows, macOS, mobile devices, servers and any devices managed outside the standard Microsoft 365 model.
Map required capabilities
Identify whether the business needs advanced hunting, longer data retention, identity sensors or cloud-app controls.
Avoid shelfware
Prioritise deployment and operational ownership before purchasing additional features that the team cannot yet use effectively.
Build the endpoint protection foundation first
Endpoint security begins with complete onboarding and healthy telemetry. A sophisticated policy provides little value when laptops, desktops or servers are missing, inactive, misconfigured or sending incomplete data.
Defender should be integrated with Intune where appropriate so that security configuration, device compliance and access decisions work together. Security settings management can also help manage supported devices that are not fully enrolled in Intune, but the management design should be documented and consistent.
A practical endpoint security operating model
Core endpoint settings to verify
- Real-time and cloud-delivered protection are enabled and reporting correctly.
- Tamper protection prevents unauthorised security-setting changes.
- Potentially unwanted application protection is configured deliberately.
- Firewall profiles are enabled and exceptions are documented.
- Endpoint detection and response is active across every supported device.
- Automated investigation and remediation settings match the organisation's risk tolerance.
- Device isolation, live response and containment permissions are restricted to appropriate roles.
Attack surface reduction rules
Attack surface reduction rules target behaviours that attackers commonly use, such as malicious scripts, credential theft, executable content launched from email or Office applications, and abuse of trusted system tools.
ASR rules should not be enabled blindly across every device. Microsoft provides audit, warn and block options for many rules. A sensible rollout uses pilot groups, reviews telemetry, resolves genuine compatibility issues and then progressively moves suitable rules into enforcement.
Establish a representative pilot
Include users, applications and device types that reflect the broader environment, not only IT staff.
Collect audit data
Identify legitimate business processes that would be affected and separate them from genuinely risky behaviour.
Use precise exclusions
Avoid broad folder or process exclusions. Document the owner, reason, scope and review date for every exception.
Move rules into warn or block
Enforce controls in stages and monitor incidents, support requests and business impact after each change.
Review continuously
Retest exclusions and adjust the policy as software, business processes and Microsoft recommendations change.
Protect email and collaboration with Defender for Office 365
Email remains a common initial access path. Defender for Office 365 extends the built-in protections in Exchange Online with stronger anti-phishing, impersonation protection, Safe Links and Safe Attachments capabilities.
Microsoft generally recommends using its Standard or Strict preset security policies as a baseline, with carefully designed exceptions where required. SPF, DKIM and DMARC should also be configured for active and inactive domains because policy alone cannot compensate for weak email authentication.
Safe Links
Scans and evaluates supported links, including time-of-click checks in email and supported collaboration experiences.
Safe Attachments
Analyses suspicious files in a protected environment to help identify unknown malware and malicious behaviour.
Anti-phishing
Uses spoof intelligence, mailbox intelligence and impersonation controls to identify deceptive messages.
Threat response
Supports investigation, quarantine, submissions, reporting and automated actions depending on the licensed plan.
Email protection checks
- Every user is included in the intended preset or custom protection policy.
- Executives, finance staff and other high-risk users receive appropriate impersonation protection.
- Safe Links and Safe Attachments policies cover email, Teams and supported Microsoft 365 workloads as intended.
- User-reported phishing is configured and routed to a monitored process.
- Quarantine permissions, notifications and release processes are appropriate.
- Tenant Allow/Block List entries and other overrides are reviewed for risky or expired exceptions.
- SPF, DKIM and DMARC are implemented and monitored for every sending domain.
Use Microsoft Defender XDR as the investigation layer
Microsoft Defender XDR brings security information together in the Microsoft Defender portal. When the required services and licences are present, alerts from endpoints, email, identities and cloud applications can be correlated into incidents that show a broader attack story.
The unified portal does not remove the need for operational discipline. Teams still need alert triage standards, role-based access, evidence handling, escalation paths and a clear definition of when to isolate a device, disable an account or involve external incident-response specialists.
| Capability | Why it matters | Operational question |
|---|---|---|
| Incident correlation | Groups related alerts into a broader attack narrative | Who validates and owns the incident? |
| Advanced hunting | Allows proactive queries across available security data | Does the team have the skills and time to use it? |
| Automated investigation | Can analyse evidence and take or recommend remediation actions | What automation level is approved? |
| Response actions | Supports containment such as device isolation and account actions | Who is authorised to contain business systems? |
Alert management and incident response
A Defender deployment is incomplete until someone is responsible for its alerts. The organisation should define who monitors the portal, how often it is checked, what constitutes a critical event and when a case must be escalated.
Named ownership
Assign primary and backup owners for endpoint, identity and email security alerts.
Response targets
Define realistic acknowledgement and investigation targets based on severity and business impact.
Response playbooks
Document steps for phishing, compromised accounts, malware, ransomware and suspicious administrator activity.
Testing and exercises
Run tabletop and technical tests to confirm that permissions, contacts and containment actions work under pressure.
Minimum incident workflow
- Validate the alert and identify affected users, devices, applications and data.
- Determine severity, scope, business impact and whether active attacker activity is continuing.
- Contain the threat using proportionate actions such as isolation, session revocation or account restriction.
- Preserve relevant evidence and document decisions, timestamps and actions.
- Remove persistence, remediate vulnerabilities and restore affected services safely.
- Complete a post-incident review and update policies, playbooks and training.
A practical Microsoft Defender deployment roadmap
Organisations often try to deploy every feature at once. A staged roadmap produces better results because foundational coverage and ownership are established before advanced controls are enforced.
Discover and design
Confirm licences, users, devices, platforms, servers, existing security products, regulatory needs and response responsibilities.
Onboard and validate
Connect supported endpoints and workloads, verify sensor health and reconcile the Defender inventory against authoritative asset records.
Apply baseline protection
Configure antivirus, EDR, tamper protection, firewall, email security and role-based access using tested baselines.
Harden progressively
Deploy ASR rules, web protection, device control and stricter email policies through pilots and controlled enforcement.
Operationalise response
Build alert queues, response targets, playbooks, escalation contacts, reporting and regular security review meetings.
Measure and improve
Track coverage, exposure, unresolved recommendations, alert trends, response performance and recurring control failures.
Microsoft Defender review checklist
Use this checklist as a starting point for a structured review. It should be adapted to the organisation's licences, operating systems, applications, compliance obligations and risk profile.
Common Microsoft Defender deployment mistakes
Assuming defaults are enough
Built-in protection is valuable, but it does not replace a design matched to the organisation's users, devices and risk.
Ignoring incomplete coverage
Unmanaged laptops, servers, contractors and stale records can create blind spots that dashboards do not make obvious.
Leaving controls in audit mode
Audit data is useful during rollout, but controls that never reach enforcement may not stop an attack.
No one owns the alerts
Technology cannot compensate for an unmonitored queue or unclear authority to investigate and contain threats.
Broad exclusions
Convenient exclusions can undermine multiple controls. They should be precise, documented and reviewed regularly.
Buying before deploying
Additional licensing has limited value when existing endpoint and email capabilities are not fully configured or operated.
Frequently asked questions
Microsoft Defender is the name used for a family of Microsoft security products that protect endpoints, email, identities, cloud applications and Microsoft 365 services. The exact capabilities available depend on licensing and configuration.
Microsoft 365 Business Premium includes Microsoft Defender for Business for endpoint protection and Microsoft Defender for Office 365 Plan 1 for email and collaboration protection. Organisations should still verify current service-plan assignments and supported users and devices.
No. Microsoft Defender Antivirus is the built-in antimalware component in Windows. Defender for Business adds broader capabilities such as endpoint detection and response, vulnerability management, automated investigation and centralised security management.
In many environments, yes. Defender detects and responds to threats, while Intune manages device enrolment, configuration, compliance, applications and access-related device posture. The two services are strongest when designed to work together.
Attack surface reduction rules help block risky behaviours commonly used by malware, such as Office applications launching child processes or scripts downloading executable content. Rules should be assessed, tested in audit or warn mode where appropriate, and then enforced deliberately.
Alerts need a named owner, severity-based response targets, documented escalation paths and regular review. High-value detections should be tested so the organisation knows who investigates, isolates devices, contains accounts and communicates with stakeholders.
Microsoft Defender, Intune and Entra ID can support several Essential Eight controls, including application hardening, patching, multifactor authentication and restriction of administrative privileges. Alignment still depends on the organisation's complete technology environment and implementation.
A formal review should generally occur at least annually and after major licensing, device, operating-system, architecture or security changes. Alert operations, device health and exposure recommendations should be reviewed more frequently.
Official Microsoft references
Microsoft product features and licensing can change. Confirm current requirements against the official documentation before making purchasing or deployment decisions.
Need help reviewing Microsoft Defender?
Fedelta can assess your current licensing, endpoint coverage, email protection, security policies and incident-response readiness, then create a prioritised improvement roadmap.