Is security currently top of mind at your org? Understand Microsoft Defender XDR in this Pluralsight course clip!
Video Summary
Here are the key points from the video:
- Overview of Microsoft Defender XDR: It’s a unified defense suite that coordinates detection, prevention, investigation, and response across various domains like endpoints, identities, email, and applications to protect against sophisticated attacks.
- Microsoft Defender Portal: This is the central hub for managing security services across your Microsoft environment. It allows monitoring of identities, data, devices, apps, and infrastructure, and is customizable based on the admin’s role and preferences.
- Microsoft Secure Score: This feature provides a quick way to understand and improve your security posture. It prioritizes actions based on their potential to reduce risk, using a gamified approach to encourage tackling high-impact items first.
- Incident Management: The portal allows security teams to view and manage incidents comprehensively. For example, a multi-stage incident involving multiple users and alerts can be viewed as a whole, enabling a more effective response.
- Continuous Assessment: Security is an ongoing process. The secure score can fluctuate based on new devices and resources, emphasizing the need for continuous assessment and improvement to maintain a strong security posture.
For more information, read the transcript blog below, or watch the video above!
Video Transcript
Let’s start by doing an overview of Microsoft Defender XDR and its services. Microsoft Defender XDR is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks. Until November 2023, Microsoft Defender XDR was known as Microsoft 365 Defender, and you might still find many online sources that mention the old name.
Microsoft Defender XDR has six main services: Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender Vulnerability Management, Microsoft Defender Threat Intelligence, and Microsoft Defender for Cloud Apps. All these services work together to provide complete protection of your Microsoft cloud services. One of the big advantages of Microsoft Defender XDR is that it’s an integrated cross-domain solution that stitches together signals from endpoints, identities, data, and applications, grouping all those signals together in incidents. This allows security teams to see the attack as a whole and focus on remediating the full picture rather than only looking at a piece of the puzzle at a time. For example, in an incident, you might see two impacted devices and three impacted users, allowing the security team to address the entire incident comprehensively.
The Microsoft Defender Portal is the central location for security teams to manage security services across your Microsoft environment. It allows you to monitor identities, data, devices, apps, and infrastructure in a single location and can be accessed at security.microsoft.com. However, only certain administrative roles have access to it, such as the global administrator, security admin, security operator, or security reader role. The portal’s home page features a customizable navigation on the left side and a card-based layout in the middle, allowing each admin to personalize their view based on what makes them more productive.
One of the cards you might notice is the Microsoft Secure Score. The goal of the Microsoft Secure Score is to provide a quick way to understand your security posture and help prioritize actions based on their potential to reduce risk. It uses a gamified approach, where higher-impact actions give you more points towards your secure score. This not only helps improve security but also provides a clear way to present security progress to management and non-technical executives. For example, a recommendation might be to ensure that multi-factor authentication is enabled for all users in administrative roles. The secure score includes recommendations from various Microsoft products and third-party products, and Microsoft continuously adds new integrations.
In the demo, we explored the Microsoft Defender Portal and the Microsoft Secure Score. The portal’s navigation and card-based layout are customizable, allowing admins to focus on the most important controls and alerts. The secure score helps prioritize actions to improve security posture, and the incident management feature allows security teams to view and manage incidents comprehensively. For example, a multi-stage incident involving multiple users and alerts can be viewed as a whole, enabling a more effective response. Security is an ongoing process, and the secure score can fluctuate based on new devices and resources, emphasizing the need for continuous assessment and improvement.