What is Microsoft Defender for EndPoint?
Microsoft Defender for Endpoint from Microsoft is an enterprise endpoint security platform with advanced threat protection. It enables you to prevent, detect, investigate, and respond to threats to your devices. Microsoft Defender for Endpoint automatically examines and analyses alerts to resolve breaches to help you focus on other tasks. The Defender for Endpoint integrated with Windows Defender also serves as an antivirus, antimalware, ransomware mitigation, and more with centralised management and reporting.
Microsoft Defender for Endpoint Capabilities
Threat & Vulnerability Management
Threat & Vulnerability management is the first solution to handle threats and efficiently provide a solution for the attack.

Defender for Endpoint offers continuous real-time discovery of threats and vulnerabilities by effectively identifying, assessing, and remediating vulnerabilities and misconfigurations while prioritising your organisation’s most essential devices and sensitive information.
Continuous real-time discovery
- Vulnerability assessment across the entire stack.
- Broad secure configuration assessment of the software and applications.
Threat & Business Prioritisation
- Scans threats and provides a report to secure business devices and data.
- Built-in end-to-end remediation process to minimise business downtime.
Attack Surface Reduction
Microsoft Defender has an attack surface reduction feature, the most effective method for blocking the most common attack techniques used in cyberattacks and malicious software. It also performs threat filtering and isolation. It provides straightforward monitoring and reporting alerts, incidents, and threat analysis to prevent exploitation.
Attack Surface Reduction Rules
- Productivity App rule
- Email Rule
- Polymorphic threats
- Lateral movement & credential theft
Next-generation Protection
Defender from Microsoft Office 365 provides behavioural heuristics-based real-time protection. It immediately detects new and emerging threats, analyses them in a secure environment, and stops them before progressing.
Microsoft Defender for Endpoint next-generation protection engines.
| In the cloud | On the client |
| Metadata-based ML engine – Stops new threats quickly by analysing metadata. | ML engine – Spots new and unknown threats using client-based ML models. |
| Behaviour-based ML engine – Identifies new threats with process trees and suspicious behaviour sequences. | Emulation engine – Evaluate files based on how they would behave when run. |
| AMSI-paired ML engine – Detects files less and in-memory attacks using paired client and cloud ML models. | Memory scanning engine – Detects malicious code running in memory. |
| File classification ML engine – Detects new malware by running multi-class, deep neural network classifiers. | AMSI integration engine – Detects files and in-memory attacks. |
| Detonation-based ML engine – Catches new malware by detonating unknown files. | Heuristics engine – Catches malware variants or new strains with similar characteristics. |
| Reputation ML engine – Catches threats with a lousy reputation, direct or by association. | Emulation engine – Evaluates files based on how they would behave when run. |
| Smart rules engine – Blocks threats using expert-written rules. | Network engine – Catches malicious network activities. |
Endpoint Detection and Response
Microsoft Defender for Endpoint has advanced detection, investigation, hunting, live response, and response actions that better protect your platforms. Endpoint provides a complete process execution tree, machine timeline activities, and other affected machines/users to view activities to increase security resilience and effectively prevent or contain the threat.
- Correlated post-breach detection – examines and analyses the data and systems after the attack to plan preventative solutions.
- Investigation experience – Provide complete detailed information on activities, machines/users.
- Incident – describes and narrates the end-to-end attack story.
- Advanced hunting – provides custom detection and customer response.
- Response actions (+EDR blocks) –
- Deep file analysis
- Live response – analysis, files, process, library, registry etc.
- Threat analytics – shows how you work and act against significant threats.
Auto Investigation & Remediation
Threats step in anytime, which leads to a 24/7 need for investigation and remediation. It is also great to work if done manually. It adds extra cost to the organisation to do manual checking analysis. It is time-consuming and gives a higher risk of experiencing outages due to unmonitored or missed attacks. Microsoft Defender is capable of automatically investigating alerts and remediating threats immediately.
Defender for EndPoint will investigate all threats and the severity level for remediation actions, including moving files to quarantine, stopping service, removing tasks, and more. Pending and completing will be tracked in the action centre.
Microsoft Threats Experts
In addition to a competitive endpoint security job, Microsoft Defender for Endpoint has threat experts who can advise and provide insights about suspicious activities in your organisation. Microsoft Defender for Endpoint pricing and licensing details are available on request.
It is an add-on service where you need to apply or subscribe to get a deep analysis of the threats, proactive hunting to discover known and unknown attacks, identify high-risk alerts, get additional clarification on suspicious behaviour warnings, and give protection advice and action. The Microsoft Expert feature is available in several portals for faster data and report engagement.
The following table compares the Defender for business features and capabilities ( Plan 1 and Plan 2 ) to Microsoft 365 Business Premium.
| Customer Size | < 300 Seats | > 300 Seats | > 300 Seats |
| Endpoint Capabilities \ SKU | Microsoft Defender for Business | Microsoft Defender for Endpoint Plan 1 | Microsoft Defender for Endpoint Plan 2 |
| Centralised management | √ | √ | √ |
| Simplified Client Configuration | √ | ||
| Threat and Vulnerability Management | √ | √ | |
| Attack Surface Reduction | √ | √ | √ |
| Next-Gen Protection | √ | √ | √ |
| Endpoint Detection and Response | √ | √ | |
| Automated Investigation and Response | √ | √ | |
| Threat Hunting and 6-months data retention | √ | ||
| Threat Analytics | √ | √ | |
| Cross-platform support for Microsoft Defender for Endpoint on Mac and Microsoft Defender for Endpoint on ios and Android | √ | √ | √ |
| Microsoft Threat Experts | √ | ||
| Partner APIs | √ | √ | √ |
| Microsoft 365 Lighthouse for viewing security incidents across customers | √ |
(1) Onboard and manage devices in the Microsoft Defender for Endpoint URL (https://security.microsoft.com) or with Microsoft Endpoint Manager (https://endpoint.microsoft.com).
(2) Endpoint detection and response (EDR) capabilities in Defender for Business include behaviour-based detection and the following four types of manual response actions:
Run antivirus scan
Isolate device
Stop and quarantine a file
Add an indicator to block or allow a file
(3) In Defender for Business, automated investigation and response are turned on by default, tenant-wide. If you turn off automatic analysis and response, it affects real-time protection. See Review settings for advanced features.
(4) There is no timeline view in Defender for Business.
(5) In Defender for Business, threat analytics are optimised for small and medium-sized businesses.
(6) During the preview program, Windows client devices are supported for onboarding in the Microsoft 365 Defender portal (https://security.microsoft.com). You can use the local script method. See Onboard Devices to Microsoft Defender for Business.





