A security analyst needs to investigate a potential ransomware attack affecting multiple endpoints. They want to centralize detection and response across devices, email, and applications. Which Microsoft solution should they use?
Microsoft Defender XDR (formerly Microsoft 365 Defender) is the correct choice because it provides extended detection and response capabilities across multiple security domains. It unifies signals from endpoints (Defender for Endpoint), email and collaboration (Defender for Office 365), identities (Defender for Identity), and cloud apps (Defender for Cloud Apps). This comprehensive correlation is crucial for investigating multi-stage attacks like ransomware, allowing analysts to trace the attack chain from initial compromise to impact across the entire Microsoft 365 ecosystem, offering a unified incident view.
Why this answer
Microsoft Defender XDR (formerly Microsoft 365 Defender) provides unified detection and response across endpoints, email, identities, and applications. Microsoft Sentinel is a SIEM for broader security data. Defender for Cloud is for cloud workloads.
Defender for Endpoint only covers endpoints.