Lesson 4 — Understanding the Device Page
The Device Page is the central investigation view for a selected endpoint in Microsoft Defender for Endpoint.
It brings together alerts, timeline events, logged-on users, software, vulnerabilities, security recommendations and response actions.
This lesson explains how analysts use the Device Page to understand endpoint context, confirm suspicious activity and decide what to investigate or respond to next.
What you will learn
This lesson explains how the Device Page acts as the investigation dashboard for an endpoint.
Learning objectives
After completing this lesson, you should be able to use the Device Page as the central investigation view for an endpoint.
- Explain the purpose of the Device Page.
- Identify the main device overview fields.
- Review alerts, users, timeline activity and exposure data.
- Understand how software, vulnerabilities and recommendations add context.
- Recognise when device response actions may be required.
The problem this solves
An inventory record tells you that a device exists and whether it appears risky or exposed.
The Device Page brings the evidence together so the analyst can understand what is happening on that specific endpoint.
What is the Device Page?
The Device Page is the detailed investigation view for one endpoint in Microsoft Defender for Endpoint.
It combines identity, alert, timeline, software, vulnerability and response information so analysts can move from asset context into investigation and containment.
Think of the Device Page as the endpoint investigation dashboard. It is where device context becomes operational evidence.
How the Device Page fits into an investigation
Device overview
The overview section summarises the current state of the endpoint.
It commonly includes the device name, operating system, risk level, exposure level, health, last seen activity, tags and management information.
Device name and identity
Confirm the hostname and device identity before taking action.
Renamed, rebuilt or duplicated endpoints can cause analysts to investigate the wrong record if identifiers and timestamps are not checked carefully.
Risk level
Risk reflects current or recent security concern associated with the endpoint.
A device with active alerts or suspicious behaviour may require immediate investigation, even if the visible alert appears isolated.
Exposure level
Exposure represents weaknesses that could increase the likelihood or impact of compromise.
Use exposure context to understand whether vulnerable software, insecure configuration or missing updates may have contributed to the attack path.
Last seen and health
Last seen activity and sensor health help confirm whether the endpoint is currently reporting.
Do not rely on the absence of recent events if the device is offline, inactive or experiencing sensor problems.
Operating system and platform
The operating system provides important context for available telemetry and response options.
Windows, macOS, Linux and server platforms may expose different capabilities and investigation detail.
Device tags and groups
Tags and groups help identify business function, ownership, location, sensitivity and operational importance.
This context can change the priority and urgency of the investigation.
Device value
Critical systems such as domain controllers, privileged workstations and production servers deserve additional scrutiny.
Business importance should be considered alongside technical alert severity.
What analysts should review first
| Area | What it tells the analyst |
|---|---|
| Overview | What the device is, how important it is and whether it is healthy. |
| Alerts | What Defender has detected on the endpoint. |
| Timeline | What happened before, during and after the suspicious activity. |
| Users | Which identities were associated with the device. |
| Software and vulnerabilities | Whether exposed applications or weaknesses may have contributed. |
| Response actions | What containment or evidence collection options are available. |
Active alerts
The alerts section shows security detections associated with the device.
Review severity, status, detection source, affected entities and whether the alert belongs to a larger Defender XDR incident.
Parent incident
An endpoint alert may be only one part of a wider attack.
Always check the parent incident for identity, email or cloud evidence that may explain how the endpoint activity began.
Device timeline
The timeline presents endpoint activity in chronological order.
It can contain process, file, network, registry, logon and other security-relevant events collected from the device.
Why chronology matters
The same event can mean different things depending on what occurred immediately before and after it.
The timeline helps analysts reconstruct the attack sequence rather than viewing isolated indicators.
Logged-on users
The users section helps identify which accounts were associated with the endpoint.
This can reveal interactive users, privileged accounts, service accounts or unexpected identities that require further investigation.
User pivots
A suspicious device may lead to a compromised identity investigation.
Pivot from the endpoint into user alerts, sign-ins, identity risk and other devices used by the same account.
Software inventory
The software view helps analysts understand what applications and versions are installed.
This can reveal outdated software, unexpected tools, remote access utilities or applications relevant to the incident.
Vulnerabilities
Vulnerability information can show whether known weaknesses affect the device.
This helps determine whether exploitation was possible and whether urgent remediation is required.
Security recommendations
Security recommendations identify configuration and remediation actions that can reduce exposure.
These may include updating software, changing security settings or removing risky applications.
Missing updates
Missing operating system or application updates may create an attack path.
Use the Device Page to connect the affected endpoint with the relevant exposure and remediation information.
Example investigation workflow
Response actions
The available response actions depend on platform support, permissions and device state.
Common actions include isolating the device, collecting an investigation package, running an antivirus scan, restricting app execution and starting Live Response.
Isolate device
Isolation can restrict network communication while preserving communication with Defender for Endpoint.
Use isolation when containment is necessary, but consider business impact before acting on critical systems.
Collect investigation package
An investigation package gathers endpoint artefacts that may help with deeper analysis.
This can support evidence collection when timeline data alone is not enough.
Run antivirus scan
A scan can help identify malicious files or unwanted software present on the endpoint.
Scanning should support the investigation, not replace timeline review and incident analysis.
Restrict app execution
Restricting application execution can reduce the ability of untrusted software to run.
This can be useful during containment but should be applied with an understanding of operational impact.
Live Response
Live Response provides a remote shell for authorised investigation and remediation tasks.
It is a powerful capability and should be used by trained analysts with appropriate permissions and audit awareness.
Advanced Hunting pivot
The Device Page can lead into Advanced Hunting when the analyst needs broader telemetry or cross-device comparison.
Use the device identifier or hostname to query process, network, file, registry and logon tables.
Related devices
Attackers often move between endpoints.
Look for the same user, process, hash, IP address or domain across other devices to determine whether the activity is isolated or widespread.
Common mistake
A common mistake is reviewing only the visible alert and ignoring the rest of the Device Page.
The timeline, users, vulnerabilities and software context may reveal the real cause and scope of the incident.
Another common mistake
Do not take containment action without confirming device identity and business importance.
Isolating the wrong endpoint or a critical production system can create unnecessary disruption.
Agent Foskett investigation tip
Use it to connect device context, alerts, timeline activity, users, software, vulnerabilities and response actions into one complete endpoint story.
Best practices
- Confirm the device identity before acting.
- Review the parent Defender XDR incident.
- Use the timeline to reconstruct activity.
- Check logged-on users and identity context.
- Review software, vulnerabilities and recommendations.
- Consider business impact before containment.
Agent Foskett takeaway
The Device Page brings endpoint investigation evidence into one place.
It helps analysts move from a device record to a complete understanding of what happened, who was involved, what weaknesses existed and what response may be required.
Related Agent Foskett learning
Continue learning
Microsoft Defender for Endpoint Device Page
The Device Page in Microsoft Defender for Endpoint brings together device overview information, alerts, timeline activity, logged-on users, software inventory, vulnerabilities, security recommendations and response actions.
Defender for Endpoint Lesson 4
This Agent Foskett Defender for Endpoint Academy lesson explains how analysts use the Device Page to investigate endpoint activity, review device context, pivot into related evidence and perform containment or remediation actions.
