Lesson 2 — Microsoft Defender XDR vs Defender for Endpoint
Microsoft Defender for Endpoint protects and investigates devices.
Microsoft Defender XDR brings endpoint, identity, email and cloud application signals together into a unified incident and investigation experience.
The two are closely connected, but they are not the same product. Understanding the difference helps analysts know where endpoint evidence comes from and how it becomes part of a wider attack story.
What you will learn
This lesson explains the scope of Defender for Endpoint and how its endpoint signals become part of Microsoft Defender XDR.
Learning objectives
After completing this lesson, you should understand the relationship between Microsoft Defender XDR and Microsoft Defender for Endpoint.
- Explain what Microsoft Defender XDR is.
- Explain what Defender for Endpoint is responsible for.
- Understand how endpoint alerts become part of wider incidents.
- Recognise shared and product-specific investigation experiences.
- Choose the correct scope for an investigation or response action.
The problem this solves
The names are similar, and both appear in the Microsoft Defender portal.
Without understanding their scope, analysts may confuse the endpoint product with the wider cross-domain XDR platform.
What is Microsoft Defender XDR?
Microsoft Defender XDR is Microsoft's unified detection, investigation and response platform across multiple security domains.
It brings together signals from endpoints, identities, email, collaboration tools and cloud applications so related activity can be correlated into incidents.
Think of Defender XDR as the wider investigation layer. Defender for Endpoint is one of the major signal and response sources inside it.
How the platforms connect
Defender for Endpoint scope
Defender for Endpoint focuses on devices and endpoint activity.
Its scope includes endpoint protection, EDR, device inventory, device timelines, Advanced Hunting telemetry, vulnerability management and device response actions.
Defender XDR scope
Defender XDR focuses on the attack across security domains.
It correlates alerts and evidence from supported Defender products into incidents that represent a wider threat or attack campaign.
Shared portal experience
Both experiences are accessed through the Microsoft Defender portal.
This unified portal can make the products feel identical, but the underlying capabilities and data ownership still differ.
Endpoint alerts
Defender for Endpoint generates alerts from suspicious or malicious device activity.
Those alerts can remain endpoint-focused while also contributing to a wider Defender XDR incident.
Cross-domain incidents
Defender XDR can group related endpoint, identity, email and cloud application alerts into one incident.
This helps analysts investigate the complete attack rather than treating every alert as an isolated event.
Advanced Hunting
Advanced Hunting can query endpoint and cross-domain telemetry using KQL.
Endpoint tables such as DeviceProcessEvents and DeviceNetworkEvents sit alongside identity, email and cloud application tables in the wider hunting experience.
Device-specific investigations
When the question is about one endpoint, analysts often pivot into the device page, device timeline, software inventory and device response actions.
These are Defender for Endpoint-focused experiences.
Incident-wide investigations
When the question is about the complete attack, analysts review the Defender XDR incident, contributing alerts, entities, evidence and attack story.
This wider view may reveal identity or email activity that occurred before the endpoint alert.
Defender XDR versus Defender for Endpoint
| Microsoft Defender XDR | Microsoft Defender for Endpoint |
|---|---|
| Cross-domain detection, investigation and response platform. | Endpoint security, detection, investigation and response product. |
| Correlates alerts across supported Microsoft security services. | Produces detailed device alerts and telemetry. |
| Focuses on incidents and attack stories. | Focuses on devices, timelines, processes, files and network activity. |
| Supports unified incidents, hunting and response coordination. | Supports endpoint protection, EDR, TVM and direct device actions. |
Identity signals
Identity alerts may explain how an attacker gained access to an account before using it on a device.
Defender XDR can connect that identity evidence with endpoint activity.
Email signals
Email alerts may show the phishing message or malicious attachment that started the attack.
The resulting endpoint execution may then appear in Defender for Endpoint.
Cloud application signals
Cloud application alerts may reveal suspicious sessions, OAuth activity or data access.
Defender XDR helps connect those events with the user and device involved.
Response actions
Some actions are device-specific, such as isolation or Live Response.
Other incident actions coordinate the wider investigation, including assigning ownership, reviewing evidence and managing the incident status.
Real-world attack sequence
Where to begin
Start with the incident when multiple products or entities are involved.
Start with the device page when you already know the investigation is limited to one endpoint.
Where to pivot next
Move between the incident, alerts, users and devices as the evidence expands.
The correct investigation scope may change as new information appears.
Common mistake
A common mistake is treating Defender XDR and Defender for Endpoint as interchangeable names.
One is the wider XDR platform; the other is the endpoint security product that contributes endpoint evidence and response capabilities.
Another common mistake
Do not investigate an endpoint alert without checking whether it belongs to a larger incident.
The email, identity or cloud activity may explain how the endpoint compromise began.
Agent Foskett investigation tip
Defender for Endpoint tells you what happened on the endpoint. Defender XDR helps explain how that endpoint activity connects to the wider compromise.
Best practices
- Review the parent Defender XDR incident.
- Use the device page for endpoint detail.
- Check identity and email evidence.
- Use Advanced Hunting for cross-domain pivots.
- Coordinate response actions across the incident.
Agent Foskett takeaway
Defender for Endpoint provides endpoint protection, telemetry and direct device response.
Microsoft Defender XDR combines that endpoint evidence with other security domains to create a unified attack investigation.
Related Agent Foskett learning
Continue learning
Microsoft Defender XDR vs Microsoft Defender for Endpoint
Microsoft Defender XDR is a cross-domain detection and response platform, while Microsoft Defender for Endpoint provides endpoint protection, EDR, device telemetry, vulnerability management and device response actions.
Defender for Endpoint Lesson 2
This Agent Foskett Defender for Endpoint Academy lesson explains product scope, endpoint alerts, Defender XDR incidents, Advanced Hunting, device investigations and cross-domain response.
