Describe the capabilities of Microsoft security solutions
Microsoft Defender XDR Family
CoreDistinguish the Defender XDR services, their protection domains, threat intelligence, vulnerability management, and portal.
Aligned to the SC-900 skills measured as of July 28, 2026; product behavior verified September 10, 2026.
Why this matters
Cross-domain attacks can move through email, endpoints, identities, and cloud apps. Defender XDR correlates signals while each family member protects a distinct surface.
Must Know
- Microsoft Defender XDR is an extended detection and response platform that correlates signals, alerts, and incidents across supported Defender services.
- Microsoft Defender for Office 365 protects collaboration workloads such as email and Microsoft 365 content from threats including phishing and malicious content.
- Microsoft Defender for Endpoint helps prevent, detect, investigate, and respond to endpoint threats.
- Microsoft Defender for Cloud Apps provides visibility and control for cloud-app use and helps identify risky cloud behaviors.
- Microsoft Defender for Identity uses signals associated with on-premises Active Directory identities to detect identity-focused threats.
- Microsoft Defender Vulnerability Management discovers and prioritizes endpoint vulnerabilities and misconfigurations to reduce exposure.
- Microsoft Defender Threat Intelligence provides external threat context about actors, infrastructure, indicators, and related internet activity.
- The Microsoft Defender portal provides a unified security operations experience for incidents, alerts, hunting, reports, assets, and integrated Defender capabilities.
Compare and Distinguish
- Office 365 vs Endpoint: email/collaboration protection versus device and endpoint protection.
- Cloud Apps vs Identity: cloud-application visibility and control versus identity threat detection associated with Active Directory.
- Vulnerability Management vs XDR incident response: reduce exploitable exposure before or alongside attack activity versus correlate and investigate detected attacks.
- Defender TI vs an internal alert: external threat context and infrastructure research versus evidence generated inside the organization's environment.
- Defender portal vs a protection service: unified operations surface versus the underlying product capability producing signals.
Scenario examples
- A phishing message and subsequent endpoint activity are correlated into a broader incident in Defender XDR.
- A security team identifies unsanctioned cloud-app use with Defender for Cloud Apps.
- An analyst enriches an indicator with Defender TI while investigating a Defender XDR incident.
Exam traps
- Defender for Cloud and Defender for Cloud Apps are different products.
- Defender for Identity is not the same as Microsoft Entra ID Protection.
- Vulnerability management focuses on exposure and remediation priority, not only active incident correlation.
- The Defender portal unifies experiences; it does not erase each service's protection boundary.
Key takeaways
- XDR correlates protection signals across domains.
- Match each Defender service to email, endpoints, cloud apps, identity, exposure, or external intelligence.
- Use the Defender portal as the unified operations surface.
- Do not confuse similarly named Defender products.
Ready for the quiz?
- Which service protects email and collaboration?
- Which service finds risky cloud-app use?
- How does Defender TI differ from Vulnerability Management?
Related objectives
- D3.4.S1 — Describe Microsoft Defender XDR services
- D3.4.S2 — Describe Microsoft Defender for Office 365
- D3.4.S3 — Describe Microsoft Defender for Endpoint
- D3.4.S4 — Describe Microsoft Defender for Cloud Apps
- D3.4.S5 — Describe Microsoft Defender for Identity
- D3.4.S6 — Describe Microsoft Defender Vulnerability Management
- D3.4.S7 — Describe Microsoft Defender Threat Intelligence (Defender TI)
- D3.4.S8 — Describe the Microsoft Defender portal