Agent Foskett Academy • Defender for Endpoint • Module 1 • Lesson 4

Lesson 4 — Understanding the Device Page

The Device Page is the central investigation view for a selected endpoint in Microsoft Defender for Endpoint.

It brings together alerts, timeline events, logged-on users, software, vulnerabilities, security recommendations and response actions.

This lesson explains how analysts use the Device Page to understand endpoint context, confirm suspicious activity and decide what to investigate or respond to next.

Device Inventory helps you find the endpoint. The Device Page helps you understand everything Defender knows about it.
Agent Foskett Microsoft Defender for Endpoint Device Page lesson
What you will learn

This lesson explains how the Device Page acts as the investigation dashboard for an endpoint.

How to read the device overview
Where alerts, users and timeline events appear
How software and vulnerabilities add context
When to use device response actions

Learning objectives

After completing this lesson, you should be able to use the Device Page as the central investigation view for an endpoint.

  • Explain the purpose of the Device Page.
  • Identify the main device overview fields.
  • Review alerts, users, timeline activity and exposure data.
  • Understand how software, vulnerabilities and recommendations add context.
  • Recognise when device response actions may be required.

The problem this solves

An inventory record tells you that a device exists and whether it appears risky or exposed.

The Device Page brings the evidence together so the analyst can understand what is happening on that specific endpoint.

What is the Device Page?

The Device Page is the detailed investigation view for one endpoint in Microsoft Defender for Endpoint.

It combines identity, alert, timeline, software, vulnerability and response information so analysts can move from asset context into investigation and containment.

Agent Foskett tip:

Think of the Device Page as the endpoint investigation dashboard. It is where device context becomes operational evidence.

How the Device Page fits into an investigation

Device Inventory │ ▼ Select Device │ ▼ Device Page ├── Overview ├── Alerts ├── Timeline ├── Logged-on Users ├── Software ├── Vulnerabilities ├── Security Recommendations └── Response Actions

Device overview

The overview section summarises the current state of the endpoint.

It commonly includes the device name, operating system, risk level, exposure level, health, last seen activity, tags and management information.

Device name and identity

Confirm the hostname and device identity before taking action.

Renamed, rebuilt or duplicated endpoints can cause analysts to investigate the wrong record if identifiers and timestamps are not checked carefully.

Risk level

Risk reflects current or recent security concern associated with the endpoint.

A device with active alerts or suspicious behaviour may require immediate investigation, even if the visible alert appears isolated.

Exposure level

Exposure represents weaknesses that could increase the likelihood or impact of compromise.

Use exposure context to understand whether vulnerable software, insecure configuration or missing updates may have contributed to the attack path.

Last seen and health

Last seen activity and sensor health help confirm whether the endpoint is currently reporting.

Do not rely on the absence of recent events if the device is offline, inactive or experiencing sensor problems.

Operating system and platform

The operating system provides important context for available telemetry and response options.

Windows, macOS, Linux and server platforms may expose different capabilities and investigation detail.

Device tags and groups

Tags and groups help identify business function, ownership, location, sensitivity and operational importance.

This context can change the priority and urgency of the investigation.

Device value

Critical systems such as domain controllers, privileged workstations and production servers deserve additional scrutiny.

Business importance should be considered alongside technical alert severity.

What analysts should review first

AreaWhat it tells the analyst
OverviewWhat the device is, how important it is and whether it is healthy.
AlertsWhat Defender has detected on the endpoint.
TimelineWhat happened before, during and after the suspicious activity.
UsersWhich identities were associated with the device.
Software and vulnerabilitiesWhether exposed applications or weaknesses may have contributed.
Response actionsWhat containment or evidence collection options are available.

Active alerts

The alerts section shows security detections associated with the device.

Review severity, status, detection source, affected entities and whether the alert belongs to a larger Defender XDR incident.

Parent incident

An endpoint alert may be only one part of a wider attack.

Always check the parent incident for identity, email or cloud evidence that may explain how the endpoint activity began.

Device timeline

The timeline presents endpoint activity in chronological order.

It can contain process, file, network, registry, logon and other security-relevant events collected from the device.

Why chronology matters

The same event can mean different things depending on what occurred immediately before and after it.

The timeline helps analysts reconstruct the attack sequence rather than viewing isolated indicators.

Logged-on users

The users section helps identify which accounts were associated with the endpoint.

This can reveal interactive users, privileged accounts, service accounts or unexpected identities that require further investigation.

User pivots

A suspicious device may lead to a compromised identity investigation.

Pivot from the endpoint into user alerts, sign-ins, identity risk and other devices used by the same account.

Software inventory

The software view helps analysts understand what applications and versions are installed.

This can reveal outdated software, unexpected tools, remote access utilities or applications relevant to the incident.

Vulnerabilities

Vulnerability information can show whether known weaknesses affect the device.

This helps determine whether exploitation was possible and whether urgent remediation is required.

Security recommendations

Security recommendations identify configuration and remediation actions that can reduce exposure.

These may include updating software, changing security settings or removing risky applications.

Missing updates

Missing operating system or application updates may create an attack path.

Use the Device Page to connect the affected endpoint with the relevant exposure and remediation information.

Example investigation workflow

Open Device Page │ ▼ Confirm Device Identity and Health │ ▼ Review Active Alerts and Parent Incident │ ▼ Examine Timeline Around Suspicious Activity │ ▼ Check Logged-on Users │ ▼ Review Software, Vulnerabilities and Recommendations │ ▼ Decide Whether Response Action Is Required

Response actions

The available response actions depend on platform support, permissions and device state.

Common actions include isolating the device, collecting an investigation package, running an antivirus scan, restricting app execution and starting Live Response.

Isolate device

Isolation can restrict network communication while preserving communication with Defender for Endpoint.

Use isolation when containment is necessary, but consider business impact before acting on critical systems.

Collect investigation package

An investigation package gathers endpoint artefacts that may help with deeper analysis.

This can support evidence collection when timeline data alone is not enough.

Run antivirus scan

A scan can help identify malicious files or unwanted software present on the endpoint.

Scanning should support the investigation, not replace timeline review and incident analysis.

Restrict app execution

Restricting application execution can reduce the ability of untrusted software to run.

This can be useful during containment but should be applied with an understanding of operational impact.

Live Response

Live Response provides a remote shell for authorised investigation and remediation tasks.

It is a powerful capability and should be used by trained analysts with appropriate permissions and audit awareness.

Advanced Hunting pivot

The Device Page can lead into Advanced Hunting when the analyst needs broader telemetry or cross-device comparison.

Use the device identifier or hostname to query process, network, file, registry and logon tables.

Related devices

Attackers often move between endpoints.

Look for the same user, process, hash, IP address or domain across other devices to determine whether the activity is isolated or widespread.

Common mistake

A common mistake is reviewing only the visible alert and ignoring the rest of the Device Page.

The timeline, users, vulnerabilities and software context may reveal the real cause and scope of the incident.

Another common mistake

Do not take containment action without confirming device identity and business importance.

Isolating the wrong endpoint or a critical production system can create unnecessary disruption.

Agent Foskett investigation tip

The Device Page is your endpoint investigation dashboard.

Use it to connect device context, alerts, timeline activity, users, software, vulnerabilities and response actions into one complete endpoint story.

Best practices

  • Confirm the device identity before acting.
  • Review the parent Defender XDR incident.
  • Use the timeline to reconstruct activity.
  • Check logged-on users and identity context.
  • Review software, vulnerabilities and recommendations.
  • Consider business impact before containment.

Agent Foskett takeaway

The Device Page brings endpoint investigation evidence into one place.

It helps analysts move from a device record to a complete understanding of what happened, who was involved, what weaknesses existed and what response may be required.

Lesson summary
The Device Page is the central investigation view for an endpoint. It combines device context, active alerts, timeline activity, logged-on users, software, vulnerabilities, security recommendations and response actions so analysts can understand what happened and decide what to do next.
Defender for Endpoint Academy

Related Agent Foskett learning

These links connect Lesson 4 with Device Inventory, timeline analysis, endpoint telemetry and the wider Agent Foskett Academy.

Continue learning

Continue through the Defender for Endpoint Academy or explore the wider Agent Foskett learning library.

Microsoft Defender for Endpoint Device Page

The Device Page in Microsoft Defender for Endpoint brings together device overview information, alerts, timeline activity, logged-on users, software inventory, vulnerabilities, security recommendations and response actions.

Defender for Endpoint Lesson 4

This Agent Foskett Defender for Endpoint Academy lesson explains how analysts use the Device Page to investigate endpoint activity, review device context, pivot into related evidence and perform containment or remediation actions.