Microsoft Defender
Also known as: Microsoft Defender for Endpoint
Following adds this technology to your private workspace so related learning is easier to organise and revisit.
What is Microsoft Defender?
Microsoft Defender is a family of security products covering endpoints, identities, cloud applications, email and cloud infrastructure. This profile connects the concept to KBY's practical engineering guidance.
The individual services collect telemetry and detections that can be correlated in the Microsoft security platform. Licensing, onboarding, sensor health, policy scope and response authority determine what protection is actually active in a tenant.
Prevent, detect, investigate and respond to threats across Microsoft-managed environments.
2 resources for Microsoft Defender
Browse by purpose, from definitions and learning through operations, diagnostics and controlled recovery.
Learn and operate with Microsoft Defender
Ordered as a reader progression -- from core definitions through to operational reference -- using only the content already connected in the technology registry.
Systems Engineering(2)
Learn the architecture, concepts and engineering context.
- Engineering Security & Operations for Predictable Microsoft Defender OperationsHow to move a single Microsoft Defender alert-handling workflow from design to a verified, recoverable state, using least-privilege roles, read-only checks and a rehearsed rollback. Open
- Failure-Aware Security Operations Architecture for Microsoft DefenderA bounded, failure-aware Security & Operations workflow for Microsoft Defender: detection, semi-automated investigation, reversible device isolation, and a validated recovery path with least-privilege role separation. Open