Agent Foskett Academy • Microsoft Defender for Cloud • Module 4 • Lesson 38

Lesson 38 — Microsoft Defender XDR Integration

Microsoft Defender for Cloud detects threats against cloud workloads. Microsoft Defender XDR brings those signals into a unified incident experience with evidence from identities, endpoints, email, applications and Microsoft Sentinel.

This integration allows analysts to investigate Defender for Cloud alerts and incidents in the Microsoft Defender portal, correlate related activity across security domains, review affected entities and use advanced hunting, automated investigation and response capabilities where supported.

This lesson explains the unified incident model, cross-domain alert correlation, entity and timeline investigation, advanced hunting, incident synchronisation, attack disruption and the operational decisions required to avoid duplicate workflows.

The virtual machine alert looked isolated—until Defender XDR connected the identity, endpoint and cloud evidence.
Agent Foskett Microsoft Defender XDR Integration lesson
What you will learn

This lesson follows Defender for Cloud evidence into the unified Defender XDR incident workflow.

Unified incidents
Cross-domain evidence
Advanced hunting
Automated response

Defender for Cloud and Defender XDR integration flow

Defender plans monitor cloud workloads

Microsoft Defender for Cloud generates alerts and incidents

Alerts appear in the Microsoft Defender portal

Defender XDR correlates cloud, endpoint, identity, email and application signals

Related alerts are grouped into a unified incident

Analysts review the graph, timeline, assets and evidence

Advanced hunting expands the investigation

Automated investigation runs where supported

Attack disruption may contain high-confidence active threats

Sentinel adds third-party data, analytics and playbooks

Analysts validate containment and close the unified incident

Cross-domain investigation sources

Security domainEvidence addedExample
Defender for CloudCloud-resource and workload alerts.Suspicious Key Vault access.
Defender for EndpointProcess, file, network and device evidence.PowerShell on a compromised VM.
Defender for IdentityIdentity and lateral-movement evidence.Suspicious credential use.
Defender for Office 365Email, link and attachment evidence.Phishing message that delivered the initial access.
Defender for Cloud AppsSaaS and application activity.Risky OAuth application activity.
Microsoft SentinelThird-party, custom and long-term telemetry.Firewall, proxy and custom application logs.

Learning objectives

  • Explain Defender for Cloud and Defender XDR integration.
  • Understand unified incidents and alerts.
  • Investigate cloud, identity and endpoint evidence together.
  • Use entity pages, timelines and incident graphs.
  • Use advanced hunting for cross-domain analysis.
  • Understand automated investigation and attack disruption.
  • Avoid duplicate incident and connector workflows.

What is Microsoft Defender XDR?

Microsoft Defender XDR is a unified extended detection and response platform that correlates signals across endpoints, identities, email, collaboration tools, applications and cloud workloads.

Defender for Cloud role

Defender for Cloud provides cloud-security posture management and workload protection across Azure, AWS, Google Cloud and hybrid resources.

Integration purpose

The integration brings Defender for Cloud alerts and incidents into the Microsoft Defender portal so analysts can investigate cloud evidence alongside other security domains.

Microsoft Defender portal

The Microsoft Defender portal provides a unified location for incidents, alerts, advanced hunting, assets, threat intelligence and response.

Unified security operations

When Microsoft Sentinel is onboarded to the Defender portal, Defender XDR and Sentinel share incidents, alerts, entities and investigation workflows.

Alert ingestion

Defender XDR collects Defender for Cloud alerts so they can participate in cross-domain incident correlation.

Incident correlation

Related alerts can be grouped into one incident when they share entities, timing, techniques or attack context.

Unified incident queue

The incident queue provides one operational view for alerts from Defender products, Defender for Cloud and Microsoft Sentinel.

Alert queue

The alert queue allows analysts to filter, prioritise and investigate individual detections across connected Microsoft security products.

Cloud-resource context

Defender for Cloud alerts include affected cloud resources, subscriptions, resource groups, workload types and evidence specific to the detection.

Device context

Defender for Endpoint adds process, file, network, device and vulnerability evidence when the cloud resource includes or connects to a protected endpoint.

Identity context

Defender for Identity and Microsoft Entra signals can show suspicious sign-ins, credential misuse, privilege changes and lateral movement.

Email context

Defender for Office 365 can reveal phishing, malicious attachments, links and mailbox activity that preceded the cloud compromise.

Application context

Defender for Cloud Apps and Entra application telemetry can add service-principal, OAuth, SaaS and session evidence.

Sentinel context

Microsoft Sentinel can add third-party data, custom analytics, watchlists, threat intelligence and long-term telemetry.

Incident graph

The incident graph displays relationships between alerts, users, devices, IP addresses, applications, mailboxes and cloud resources.

Incident timeline

The incident timeline helps analysts reconstruct the order of alerts, automated actions and investigation events.

Assets tab

The assets view summarises users, devices, mailboxes, applications and cloud resources associated with the incident.

Evidence and response

Evidence pages provide investigation details and available response actions for supported entities.

Alert story

The alert story explains the detection, affected entities, evidence, attack technique and recommended investigation steps.

MITRE ATT&CK

ATT&CK tactics and techniques help place each alert within a broader attack lifecycle.

Cross-domain correlation

An endpoint alert, identity alert and cloud-workload alert may represent one attack rather than three separate events.

Cloud incidents

Defender for Cloud incidents can contain alerts across several cloud resources and can be represented within the Defender portal.

Incident ownership

Assign incidents to analysts or teams and use status, classification, tags and comments to maintain workflow.

Incident severity

Incident severity should reflect the combined evidence, affected assets and business impact rather than the highest alert alone.

Incident naming

Use the incident title and summary as a starting point, then update analyst notes when the investigation reveals a clearer attack story.

Alert classification

Classify alerts and incidents as true positive, benign positive, false positive or undetermined according to the available evidence.

Automated investigation and response

Defender XDR can automatically investigate supported suspicious entities and events and recommend or perform remediation actions.

AIR scope

Automated investigation support varies by alert source, workload, licence and evidence type. Do not assume every Defender for Cloud alert triggers the same automated investigation.

Investigation status

Review automated investigation status, findings, pending actions and remediation results before closing the incident.

Action centre

The Action centre records automated and manual remediation actions and allows authorised analysts to approve or reverse supported actions.

Automatic attack disruption

Automatic attack disruption uses high-confidence signals to contain active attacks at machine speed where supported.

Attack disruption scope

Disruption actions depend on available Defender XDR and Sentinel signals, supported entities and confidence thresholds.

Human oversight

Analysts should review automated actions, business impact and residual access even when attack disruption succeeds.

Advanced hunting

Advanced hunting uses KQL to search across Defender XDR and, in unified deployments, Microsoft Sentinel data.

Hunting schema

Tables can include device, identity, email, cloud-application and alert information depending on connected services.

AlertInfo

AlertInfo provides alert metadata such as title, severity, category, service source and detection source.

AlertEvidence

AlertEvidence contains entities and evidence associated with Defender XDR alerts.

Cloud evidence

Cloud evidence can include resource identifiers, IP addresses, accounts, workloads and supporting detection details.

DeviceProcessEvents

DeviceProcessEvents helps identify process execution associated with a compromised cloud-hosted device.

DeviceNetworkEvents

DeviceNetworkEvents can reveal outbound connections, command-and-control and data transfer.

IdentityLogonEvents

IdentityLogonEvents can show authentication activity linked to a user or identity-based attack.

CloudAppEvents

CloudAppEvents can add application and cloud-service activity where relevant and available.

Sentinel data in hunting

When Sentinel is onboarded to the Defender portal, analysts can query Sentinel data alongside Defender XDR tables.

Custom detections

Advanced hunting queries can support custom detection rules for recurring cloud attack patterns where the required data is available.

Entity pivoting

Pivot from a resource or alert to the associated identity, device, IP address, application and related incidents.

User investigation

Review sign-ins, risk, devices, roles, applications and incidents associated with the user.

Device investigation

Review alerts, timeline, processes, network activity, logged-on users and response actions for the device.

Application investigation

Review service-principal credentials, permissions, consent, sign-ins and cloud activity.

Cloud-resource investigation

Review Defender for Cloud alert details, resource configuration, Azure Activity Log and workload-specific evidence.

Incident synchronisation

In unified workflows, incident and alert state can synchronise between Defender XDR, Defender for Cloud and Microsoft Sentinel according to the active integration.

Avoid duplicate connectors

Do not maintain overlapping Defender for Cloud and Defender XDR incident ingestion paths without understanding duplication and ownership.

Avoid duplicate analytics

Custom analytics should add new detection value rather than recreate alerts already produced and correlated by Defender XDR.

Microsoft Sentinel integration

Sentinel extends Defender XDR with third-party telemetry, custom analytics, hunting, workbooks, automation rules and playbooks.

Automation rules

Sentinel automation rules can assign, tag, close or enrich unified incidents and trigger playbooks.

Playbooks

Logic App playbooks can notify owners, enrich entities, create tickets and perform approved response actions.

Permissions

Defender portal access, hunting, response and action-centre approvals require appropriate security roles.

Role-based access

Use least-privilege role assignments so analysts can investigate without receiving unnecessary destructive permissions.

Data availability

Investigation depth depends on licensing, connected Defender products, Sentinel onboarding, data retention and sensor health.

Connector health

Validate that Defender for Cloud alerts and incidents are arriving in the Defender portal and associated with the correct tenant and workspace.

Testing

Use approved simulation or validation methods to prove cloud alerts are correlated with identity and endpoint evidence as expected.

Operational ownership

Define whether the Defender XDR queue, Sentinel queue or unified Defender portal is the system of record for incident handling.

Common mistake: isolated review

Do not investigate the Defender for Cloud alert without checking related identity, endpoint, email and application evidence.

Common mistake: trusting automation blindly

Automated investigation and disruption reduce response time but still require validation and business-aware oversight.

Common mistake: duplicate incidents

Overlapping connectors and incident-creation rules can split evidence across multiple cases.

Common mistake: unsupported assumptions

Do not assume every cloud alert supports automated remediation, disruption or the same evidence schema.

Validation

Confirm incident correlation, entity mapping, hunting data, response permissions, action-centre behaviour and synchronisation before relying on the integration.

Example advanced hunting query

AlertInfo | where Timestamp > ago(24h) | where ServiceSource has "Defender for Cloud" | join kind=leftouter AlertEvidence on AlertId | project Timestamp, Title, Severity, Category, ServiceSource, EntityType, EntityValue, EvidenceRole | order by Timestamp desc

This query provides a starting point for reviewing Defender for Cloud alerts and their evidence in advanced hunting. Available fields and table content depend on the active integration, licences and connected data sources.

Agent Foskett investigation: “The virtual machine alert looked isolated…”

Defender for Cloud detected suspicious command execution on an Azure VM

The alert appeared in the Microsoft Defender portal

Defender XDR grouped it with a Defender for Endpoint alert

The endpoint timeline showed credential-dumping activity

A related identity alert showed an unusual privileged sign-in

The same account had created a service-principal credential

Defender for Cloud recorded Key Vault access from that application

Email evidence showed the user had opened a malicious attachment earlier

Sentinel data showed the same IP address against another cloud workload

Agent Foskett reviewed the unified incident graph

Advanced hunting connected the user, device, application and cloud resource

The compromised account was disabled

The endpoint was isolated

The service-principal credential was revoked

Key Vault secrets were rotated

Automated actions were reviewed in the Action centre

The virtual machine alert had looked isolated

Until Defender XDR connected the entire attack
Unified incidents turn separate product alerts into one investigation story.

Defender XDR integration validation checklist

AreaQuestionEvidence
Portal visibilityAre Defender for Cloud alerts visible?Incidents and alerts queues.
CorrelationAre related alerts grouped correctly?Unified incident graph and timeline.
EntitiesAre users, devices, apps and cloud resources mapped?Assets and evidence views.
HuntingCan analysts query alert and evidence tables?Advanced hunting results.
AutomationWhich incidents support automated investigation?Investigation status and Action centre.
DisruptionAre attack-disruption actions supported and reviewed?Incident actions and audit history.
SentinelIs Sentinel enriching rather than duplicating incidents?Connector and incident-creation configuration.
PermissionsCan analysts investigate and respond safely?Security roles and response testing.
OwnershipWhich queue is the system of record?SOC operating model and escalation matrix.

Key takeaways

  • Defender for Cloud alerts and incidents are available in the Microsoft Defender portal.
  • Defender XDR correlates cloud evidence with endpoint, identity, email and application signals.
  • Unified incidents provide one graph, timeline and assets view for related activity.
  • Advanced hunting supports cross-domain KQL investigation.
  • Automated investigation and response capabilities vary by alert source and supported workload.
  • Automatic attack disruption can contain high-confidence active attacks where supported.
  • The Action centre records and manages supported remediation actions.
  • Microsoft Sentinel adds third-party telemetry, custom analytics and playbooks.
  • Overlapping connectors and analytics can create duplicate incidents.
  • The integration must be validated for visibility, correlation, hunting, response and ownership.

What Agent Foskett checked

  • Defender portal incident
  • Cloud-resource alert
  • Endpoint timeline
  • User sign-ins
  • Service principal
  • Key Vault activity
  • Email evidence
  • Sentinel telemetry
  • Incident graph
  • Advanced hunting
  • Action centre
  • Response status

Best practices

  • Use the unified incident queue.
  • Investigate across security domains.
  • Review every mapped entity.
  • Use advanced hunting.
  • Validate automated actions.
  • Avoid duplicate connectors.
  • Keep Sentinel enrichment purposeful.
  • Apply least-privilege roles.
  • Test correlation regularly.
  • Define one system of record.

Related Agent Foskett resources

Continue developing practical Microsoft Defender for Cloud, Defender XDR and unified security-operations skills.

Continue learning

Continue Module 4 by turning Defender for Cloud investigation concepts into a repeatable cloud investigation playbook.

How does Microsoft Defender for Cloud integrate with Microsoft Defender XDR?

Defender for Cloud alerts and incidents are available in the Microsoft Defender portal, where Defender XDR correlates cloud-resource evidence with endpoint, identity, email, application and Microsoft Sentinel signals.

Microsoft Defender XDR Integration Lesson

This Agent Foskett lesson explains unified incidents, alert correlation, cross-domain evidence, advanced hunting, automated investigation, attack disruption, Action centre, Sentinel integration and validation.