Simple definition
Microsoft Defender for Endpoint is an endpoint security platform for workstations and servers that combines prevention, detection, and response.
Technical definition
The platform includes capabilities such as next-generation protection, attack surface reduction, Endpoint Detection and Response (EDR), automated investigation and response, and vulnerability-management features. Devices are onboarded to the service so they can send telemetry and security teams can investigate alerts and incidents.
What is it used for?
Detect malicious behavior on endpoints, reduce attack opportunities, investigate incidents, and perform response actions on affected devices.
Practical example
A workstation runs a suspicious script after a malicious attachment is opened. Defender for Endpoint correlates the behavior with other signals, raises an EDR alert, and lets the SOC investigate the device timeline and perform response actions such as isolation when appropriate.
Common issues
- Device is not onboarded or the sensor no longer communicates
- Attack surface reduction policy is too restrictive or in an unexpected mode
- Alert cannot be investigated because of permissions or scope
- Local security settings conflict with centrally managed policy
Key takeaway: Defender for Endpoint is more than antivirus; its role includes EDR, attack-surface reduction, investigation, and response.