Terme informatique

Microsoft Defender for Endpoint

A platform EDR Microsoft to protect and monitor posts and servers.

⌚ About 1 min read
View my favorites

Simple definition

Microsoft Defender for Endpoint is an endpoint security platform for workstations and servers that combines prevention, detection, and response.

Technical definition

The platform includes capabilities such as next-generation protection, attack surface reduction, Endpoint Detection and Response (EDR), automated investigation and response, and vulnerability-management features. Devices are onboarded to the service so they can send telemetry and security teams can investigate alerts and incidents.

What is it used for?

Detect malicious behavior on endpoints, reduce attack opportunities, investigate incidents, and perform response actions on affected devices.

Practical example

A workstation runs a suspicious script after a malicious attachment is opened. Defender for Endpoint correlates the behavior with other signals, raises an EDR alert, and lets the SOC investigate the device timeline and perform response actions such as isolation when appropriate.

Common issues

  • Device is not onboarded or the sensor no longer communicates
  • Attack surface reduction policy is too restrictive or in an unexpected mode
  • Alert cannot be investigated because of permissions or scope
  • Local security settings conflict with centrally managed policy

Key takeaway: Defender for Endpoint is more than antivirus; its role includes EDR, attack-surface reduction, investigation, and response.

♡ 0