Lesson 38 — Microsoft Defender XDR Integration
Microsoft Defender for Cloud detects threats against cloud workloads. Microsoft Defender XDR brings those signals into a unified incident experience with evidence from identities, endpoints, email, applications and Microsoft Sentinel.
This integration allows analysts to investigate Defender for Cloud alerts and incidents in the Microsoft Defender portal, correlate related activity across security domains, review affected entities and use advanced hunting, automated investigation and response capabilities where supported.
This lesson explains the unified incident model, cross-domain alert correlation, entity and timeline investigation, advanced hunting, incident synchronisation, attack disruption and the operational decisions required to avoid duplicate workflows.
What you will learn
This lesson follows Defender for Cloud evidence into the unified Defender XDR incident workflow.
Defender for Cloud and Defender XDR integration flow
↓
Microsoft Defender for Cloud generates alerts and incidents
↓
Alerts appear in the Microsoft Defender portal
↓
Defender XDR correlates cloud, endpoint, identity, email and application signals
↓
Related alerts are grouped into a unified incident
↓
Analysts review the graph, timeline, assets and evidence
↓
Advanced hunting expands the investigation
↓
Automated investigation runs where supported
↓
Attack disruption may contain high-confidence active threats
↓
Sentinel adds third-party data, analytics and playbooks
↓
Analysts validate containment and close the unified incident
Cross-domain investigation sources
| Security domain | Evidence added | Example |
|---|---|---|
| Defender for Cloud | Cloud-resource and workload alerts. | Suspicious Key Vault access. |
| Defender for Endpoint | Process, file, network and device evidence. | PowerShell on a compromised VM. |
| Defender for Identity | Identity and lateral-movement evidence. | Suspicious credential use. |
| Defender for Office 365 | Email, link and attachment evidence. | Phishing message that delivered the initial access. |
| Defender for Cloud Apps | SaaS and application activity. | Risky OAuth application activity. |
| Microsoft Sentinel | Third-party, custom and long-term telemetry. | Firewall, proxy and custom application logs. |
Learning objectives
- Explain Defender for Cloud and Defender XDR integration.
- Understand unified incidents and alerts.
- Investigate cloud, identity and endpoint evidence together.
- Use entity pages, timelines and incident graphs.
- Use advanced hunting for cross-domain analysis.
- Understand automated investigation and attack disruption.
- Avoid duplicate incident and connector workflows.
What is Microsoft Defender XDR?
Microsoft Defender XDR is a unified extended detection and response platform that correlates signals across endpoints, identities, email, collaboration tools, applications and cloud workloads.
Defender for Cloud role
Defender for Cloud provides cloud-security posture management and workload protection across Azure, AWS, Google Cloud and hybrid resources.
Integration purpose
The integration brings Defender for Cloud alerts and incidents into the Microsoft Defender portal so analysts can investigate cloud evidence alongside other security domains.
Microsoft Defender portal
The Microsoft Defender portal provides a unified location for incidents, alerts, advanced hunting, assets, threat intelligence and response.
Unified security operations
When Microsoft Sentinel is onboarded to the Defender portal, Defender XDR and Sentinel share incidents, alerts, entities and investigation workflows.
Alert ingestion
Defender XDR collects Defender for Cloud alerts so they can participate in cross-domain incident correlation.
Incident correlation
Related alerts can be grouped into one incident when they share entities, timing, techniques or attack context.
Unified incident queue
The incident queue provides one operational view for alerts from Defender products, Defender for Cloud and Microsoft Sentinel.
Alert queue
The alert queue allows analysts to filter, prioritise and investigate individual detections across connected Microsoft security products.
Cloud-resource context
Defender for Cloud alerts include affected cloud resources, subscriptions, resource groups, workload types and evidence specific to the detection.
Device context
Defender for Endpoint adds process, file, network, device and vulnerability evidence when the cloud resource includes or connects to a protected endpoint.
Identity context
Defender for Identity and Microsoft Entra signals can show suspicious sign-ins, credential misuse, privilege changes and lateral movement.
Email context
Defender for Office 365 can reveal phishing, malicious attachments, links and mailbox activity that preceded the cloud compromise.
Application context
Defender for Cloud Apps and Entra application telemetry can add service-principal, OAuth, SaaS and session evidence.
Sentinel context
Microsoft Sentinel can add third-party data, custom analytics, watchlists, threat intelligence and long-term telemetry.
Incident graph
The incident graph displays relationships between alerts, users, devices, IP addresses, applications, mailboxes and cloud resources.
Incident timeline
The incident timeline helps analysts reconstruct the order of alerts, automated actions and investigation events.
Assets tab
The assets view summarises users, devices, mailboxes, applications and cloud resources associated with the incident.
Evidence and response
Evidence pages provide investigation details and available response actions for supported entities.
Alert story
The alert story explains the detection, affected entities, evidence, attack technique and recommended investigation steps.
MITRE ATT&CK
ATT&CK tactics and techniques help place each alert within a broader attack lifecycle.
Cross-domain correlation
An endpoint alert, identity alert and cloud-workload alert may represent one attack rather than three separate events.
Cloud incidents
Defender for Cloud incidents can contain alerts across several cloud resources and can be represented within the Defender portal.
Incident ownership
Assign incidents to analysts or teams and use status, classification, tags and comments to maintain workflow.
Incident severity
Incident severity should reflect the combined evidence, affected assets and business impact rather than the highest alert alone.
Incident naming
Use the incident title and summary as a starting point, then update analyst notes when the investigation reveals a clearer attack story.
Alert classification
Classify alerts and incidents as true positive, benign positive, false positive or undetermined according to the available evidence.
Automated investigation and response
Defender XDR can automatically investigate supported suspicious entities and events and recommend or perform remediation actions.
AIR scope
Automated investigation support varies by alert source, workload, licence and evidence type. Do not assume every Defender for Cloud alert triggers the same automated investigation.
Investigation status
Review automated investigation status, findings, pending actions and remediation results before closing the incident.
Action centre
The Action centre records automated and manual remediation actions and allows authorised analysts to approve or reverse supported actions.
Automatic attack disruption
Automatic attack disruption uses high-confidence signals to contain active attacks at machine speed where supported.
Attack disruption scope
Disruption actions depend on available Defender XDR and Sentinel signals, supported entities and confidence thresholds.
Human oversight
Analysts should review automated actions, business impact and residual access even when attack disruption succeeds.
Advanced hunting
Advanced hunting uses KQL to search across Defender XDR and, in unified deployments, Microsoft Sentinel data.
Hunting schema
Tables can include device, identity, email, cloud-application and alert information depending on connected services.
AlertInfo
AlertInfo provides alert metadata such as title, severity, category, service source and detection source.
AlertEvidence
AlertEvidence contains entities and evidence associated with Defender XDR alerts.
Cloud evidence
Cloud evidence can include resource identifiers, IP addresses, accounts, workloads and supporting detection details.
DeviceProcessEvents
DeviceProcessEvents helps identify process execution associated with a compromised cloud-hosted device.
DeviceNetworkEvents
DeviceNetworkEvents can reveal outbound connections, command-and-control and data transfer.
IdentityLogonEvents
IdentityLogonEvents can show authentication activity linked to a user or identity-based attack.
CloudAppEvents
CloudAppEvents can add application and cloud-service activity where relevant and available.
Sentinel data in hunting
When Sentinel is onboarded to the Defender portal, analysts can query Sentinel data alongside Defender XDR tables.
Custom detections
Advanced hunting queries can support custom detection rules for recurring cloud attack patterns where the required data is available.
Entity pivoting
Pivot from a resource or alert to the associated identity, device, IP address, application and related incidents.
User investigation
Review sign-ins, risk, devices, roles, applications and incidents associated with the user.
Device investigation
Review alerts, timeline, processes, network activity, logged-on users and response actions for the device.
Application investigation
Review service-principal credentials, permissions, consent, sign-ins and cloud activity.
Cloud-resource investigation
Review Defender for Cloud alert details, resource configuration, Azure Activity Log and workload-specific evidence.
Incident synchronisation
In unified workflows, incident and alert state can synchronise between Defender XDR, Defender for Cloud and Microsoft Sentinel according to the active integration.
Avoid duplicate connectors
Do not maintain overlapping Defender for Cloud and Defender XDR incident ingestion paths without understanding duplication and ownership.
Avoid duplicate analytics
Custom analytics should add new detection value rather than recreate alerts already produced and correlated by Defender XDR.
Microsoft Sentinel integration
Sentinel extends Defender XDR with third-party telemetry, custom analytics, hunting, workbooks, automation rules and playbooks.
Automation rules
Sentinel automation rules can assign, tag, close or enrich unified incidents and trigger playbooks.
Playbooks
Logic App playbooks can notify owners, enrich entities, create tickets and perform approved response actions.
Permissions
Defender portal access, hunting, response and action-centre approvals require appropriate security roles.
Role-based access
Use least-privilege role assignments so analysts can investigate without receiving unnecessary destructive permissions.
Data availability
Investigation depth depends on licensing, connected Defender products, Sentinel onboarding, data retention and sensor health.
Connector health
Validate that Defender for Cloud alerts and incidents are arriving in the Defender portal and associated with the correct tenant and workspace.
Testing
Use approved simulation or validation methods to prove cloud alerts are correlated with identity and endpoint evidence as expected.
Operational ownership
Define whether the Defender XDR queue, Sentinel queue or unified Defender portal is the system of record for incident handling.
Common mistake: isolated review
Do not investigate the Defender for Cloud alert without checking related identity, endpoint, email and application evidence.
Common mistake: trusting automation blindly
Automated investigation and disruption reduce response time but still require validation and business-aware oversight.
Common mistake: duplicate incidents
Overlapping connectors and incident-creation rules can split evidence across multiple cases.
Common mistake: unsupported assumptions
Do not assume every cloud alert supports automated remediation, disruption or the same evidence schema.
Validation
Confirm incident correlation, entity mapping, hunting data, response permissions, action-centre behaviour and synchronisation before relying on the integration.
Example advanced hunting query
This query provides a starting point for reviewing Defender for Cloud alerts and their evidence in advanced hunting. Available fields and table content depend on the active integration, licences and connected data sources.
Agent Foskett investigation: “The virtual machine alert looked isolated…”
↓
The alert appeared in the Microsoft Defender portal
↓
Defender XDR grouped it with a Defender for Endpoint alert
↓
The endpoint timeline showed credential-dumping activity
↓
A related identity alert showed an unusual privileged sign-in
↓
The same account had created a service-principal credential
↓
Defender for Cloud recorded Key Vault access from that application
↓
Email evidence showed the user had opened a malicious attachment earlier
↓
Sentinel data showed the same IP address against another cloud workload
↓
Agent Foskett reviewed the unified incident graph
↓
Advanced hunting connected the user, device, application and cloud resource
↓
The compromised account was disabled
↓
The endpoint was isolated
↓
The service-principal credential was revoked
↓
Key Vault secrets were rotated
↓
Automated actions were reviewed in the Action centre
↓
The virtual machine alert had looked isolated
↓
Until Defender XDR connected the entire attack
Defender XDR integration validation checklist
| Area | Question | Evidence |
|---|---|---|
| Portal visibility | Are Defender for Cloud alerts visible? | Incidents and alerts queues. |
| Correlation | Are related alerts grouped correctly? | Unified incident graph and timeline. |
| Entities | Are users, devices, apps and cloud resources mapped? | Assets and evidence views. |
| Hunting | Can analysts query alert and evidence tables? | Advanced hunting results. |
| Automation | Which incidents support automated investigation? | Investigation status and Action centre. |
| Disruption | Are attack-disruption actions supported and reviewed? | Incident actions and audit history. |
| Sentinel | Is Sentinel enriching rather than duplicating incidents? | Connector and incident-creation configuration. |
| Permissions | Can analysts investigate and respond safely? | Security roles and response testing. |
| Ownership | Which queue is the system of record? | SOC operating model and escalation matrix. |
Key takeaways
- Defender for Cloud alerts and incidents are available in the Microsoft Defender portal.
- Defender XDR correlates cloud evidence with endpoint, identity, email and application signals.
- Unified incidents provide one graph, timeline and assets view for related activity.
- Advanced hunting supports cross-domain KQL investigation.
- Automated investigation and response capabilities vary by alert source and supported workload.
- Automatic attack disruption can contain high-confidence active attacks where supported.
- The Action centre records and manages supported remediation actions.
- Microsoft Sentinel adds third-party telemetry, custom analytics and playbooks.
- Overlapping connectors and analytics can create duplicate incidents.
- The integration must be validated for visibility, correlation, hunting, response and ownership.
What Agent Foskett checked
- Defender portal incident
- Cloud-resource alert
- Endpoint timeline
- User sign-ins
- Service principal
- Key Vault activity
- Email evidence
- Sentinel telemetry
- Incident graph
- Advanced hunting
- Action centre
- Response status
Best practices
- Use the unified incident queue.
- Investigate across security domains.
- Review every mapped entity.
- Use advanced hunting.
- Validate automated actions.
- Avoid duplicate connectors.
- Keep Sentinel enrichment purposeful.
- Apply least-privilege roles.
- Test correlation regularly.
- Define one system of record.
Related Agent Foskett resources
Continue learning
How does Microsoft Defender for Cloud integrate with Microsoft Defender XDR?
Defender for Cloud alerts and incidents are available in the Microsoft Defender portal, where Defender XDR correlates cloud-resource evidence with endpoint, identity, email, application and Microsoft Sentinel signals.
Microsoft Defender XDR Integration Lesson
This Agent Foskett lesson explains unified incidents, alert correlation, cross-domain evidence, advanced hunting, automated investigation, attack disruption, Action centre, Sentinel integration and validation.
