Security
Microsoft Defender XDR
A unified security operations experience that correlates signals from supported identities, endpoints, email, applications, and cloud services into incidents.
Key points
- Incidents correlate related alerts
- Advanced hunting supports investigation
- Automated investigation can assist remediation
When to use it
- Investigate a cross-workload attack
- Review related entities and alerts
Exam tips
- Defender XDR does not assign content permissions
- Threat intelligence adds context but an alert still needs investigation