defender-xdr
Microsoft Defender XDR
Microsoft Defender XDR is a unified pre- and post-breach defence suite. It natively correlates signals across endpoints (MDE), identities (MDI + Entra ID Protection), email/collaboration (MDO), and cloud apps (MDA) to deliver a single prioritised incident with the full attack story - graph, timeline, evidence, and recommended actions.
When to use
Running coordinated detection and response across the Microsoft 365 estate from one portal (security.microsoft.com), instead of investigating each workload in isolation. Also when you need the attack disruption feature - it requires the XDR correlation.
Do not use this skill when ingesting third-party logs or writing custom KQL detections
across non-Microsoft sources (sentinel), merging Sentinel + Defender into one portal
(unified-secops-platform), or tuning endpoint-only policies (defender-for-endpoint).