Microsoft Defender
Also known as: Microsoft Defender for Endpoint
Following adds this technology to your private workspace so related learning is easier to organise and revisit.
What is Microsoft Defender?
Microsoft Defender is a family of security products covering endpoints, identities, cloud applications, email and cloud infrastructure. This profile connects the concept to KBY's practical engineering guidance.
The individual services collect telemetry and detections that can be correlated in the Microsoft security platform. Licensing, onboarding, sensor health, policy scope and response authority determine what protection is actually active in a tenant.
Prevent, detect, investigate and respond to threats across Microsoft-managed environments.
- Endpoint protection
- Email filtering
- Threat hunting
13+ resources for Microsoft Defender
Browse by purpose, from definitions and learning through operations, diagnostics and controlled recovery.
Learn and operate with Microsoft Defender
Ordered as a reader progression -- from core definitions through to operational reference -- using only the content already connected in the technology registry.
Lexicon Definitions(1)
Start here: understand the core vocabulary.
Systems Engineering(12+)
Learn the architecture, concepts and engineering context.
- When Security & Operations Changes Go Wrong in Microsoft DefenderHow a bounded Microsoft Defender policy change (ASR rule or exclusion) can silently reduce detection coverage, and how to validate, contain and recover it safely. Open
- A Practical Security & Operations Recovery Plan for Microsoft DefenderA bounded, evidence-led plan for implementing, validating and safely rolling back a Microsoft Defender exclusion or tamper-protection change across a managed device group. Open
- Security & Operations Failure Signals in Microsoft DefenderA bounded Microsoft Defender for Endpoint workflow: how to verify telemetry, automation levels and remediation actually complete, and how to recover safely when they do not. Open
- What to Monitor in Security & Operations with Microsoft DefenderA bounded, evidence-led workflow for scoping, validating and safely rolling back Microsoft Defender monitoring rules in a pilot device group before wider rollout. Open
- Making Security & Operations Easier to Recover with Microsoft DefenderA bounded Microsoft Defender workflow for isolating, validating and safely releasing an endpoint during a security investigation, with explicit rollback and audit boundaries. Open
- Security & Operations Reliability Checks with Microsoft DefenderA technical guide to implementing bounded automated isolation with Microsoft Defender for Endpoint, focusing on validation, failure modes, and safe recovery paths for security operations. Open
- Reducing Security & Operations Risk with Microsoft DefenderA technical guide to implementing a bounded Microsoft Defender for Endpoint workflow. Learn how to automate device isolation safely, validate responses, and recover from errors in a non-production environment. Open
- Recovering a Bounded Alert-to-Isolation Workflow in Microsoft DefenderA bounded, evidence-led walkthrough of designing, validating and safely recovering a Microsoft Defender device-isolation workflow, including failure modes and rollback boundaries. Open
- Operating a Bounded Alert-to-Containment Workflow with Microsoft DefenderA bounded, evidence-led workflow for triaging and reversibly containing a single Microsoft Defender endpoint alert, with validation, failure modes and rollback. Open
- Security & Operations Guardrails for Microsoft DefenderA bounded, evidence-led approach to designing, validating and safely recovering a Microsoft Defender security operations workflow, from scope boundary design through rollback. Open
- Security & Operations Change Control with Microsoft DefenderA bounded, evidence-led workflow for controlling Microsoft Defender policy changes: staged scope, audit-first validation, explicit failure modes and a decoupled rollback path. Open
- Recovering Security & Operations Safely with Microsoft DefenderHow to pilot, validate and safely reverse a Microsoft Defender attack-surface-reduction change without risking production enforcement. Open