Microsoft Learn references
Microsoft Defender Field Guides: The Complete Collection
Every reference the book lists, as a link, under the book's own headings. If a page has moved, search Microsoft Learn for its title.
Part 1: Microsoft Defender XDR
Defender XDR Overview and Zero Trust
- What is Microsoft Defender XDR?
- Microsoft Defender XDR in the Microsoft Defender portal
- Get started with Microsoft Defender XDR
- Pilot and deploy Microsoft Defender XDR
- Zero Trust with Microsoft Defender XDR
- Defender XDR in the Microsoft Defender portal (unified SecOps)
Licensing, Prerequisites, and Turning It On
- Microsoft Defender XDR prerequisites
- Turn on Microsoft Defender XDR
- Microsoft Defender XDR for US Government customers
- EDR detection test for verifying device's onboarding and reporting services
- Microsoft Defender service description
Incidents, Alerts, and the Correlation Engine
- Incidents and alerts in the Microsoft Defender portal
- Alert correlation and incident merging in the Microsoft Defender portal
- Investigate alerts in Microsoft Defender XDR
- Prioritize incidents in the Microsoft Defender portal
- Manage incidents in Microsoft Defender
- Plan an incident response workflow in the Microsoft Defender portal
Workload Signal Sources
- Zero-hour auto purge (ZAP) in Microsoft Defender for Office 365
- Manage incidents and alerts from Microsoft Defender for Office 365
- Microsoft Defender for Identity deployment overview
- Deploy the Defender for Identity sensor v3.x
- Microsoft Defender for Identity in the Microsoft Defender portal
- Create Defender for Cloud Apps anomaly detection policies
- Common Defender for Cloud Apps threat protection policies
- What is Microsoft Entra ID Protection?
- Microsoft Entra ID Protection risk reports
- Microsoft Defender for Cloud alerts and incidents in Microsoft Defender XDR
Unified RBAC
- Microsoft Defender unified role-based access control (RBAC)
- Permissions in Microsoft Defender unified RBAC
- Activate Microsoft Defender unified RBAC
Alert Tuning and Noise Reduction
- Tune an alert (alert tuning) in Microsoft Defender XDR
- Alert policies in the Microsoft Defender portal
- Manage Defender for Endpoint alert suppression rules
Automated Investigation and Response (AIR)
- Automated investigation and response in Microsoft Defender XDR
- Configure automated investigation and response capabilities in Microsoft Defender XDR
- Automated investigation and response (AIR) in Microsoft Defender for Office 365 Plan 2
- Automated remediation in AIR (configure automated remediation)
Automatic Attack Disruption
- Automatic attack disruption in Microsoft Defender
- Configure automatic attack disruption in Microsoft Defender XDR
- Details and results of an automatic attack disruption action
Threat Analytics
Case Management and Collaboration
- Manage security operations cases natively in the Microsoft Defender portal
- Streamline incident response using tasks in the Microsoft Defender portal
- View and manage cases across multiple tenants in the Microsoft Defender multitenant portal
Embedded Security Copilot and AI Agents
- Microsoft Security Copilot and Chat in Microsoft Defender
- Microsoft Security Copilot experiences
- Microsoft Security Copilot Phishing Triage Agent in Microsoft Defender
Sentinel Unified Platform and Advanced Hunting
- Connect Microsoft Sentinel to the Microsoft Defender portal
- Microsoft Defender XDR integration with Microsoft Sentinel
- Proactively hunt for threats with advanced hunting in Microsoft Defender XDR
- Understand the advanced hunting schema
- Advanced hunting with Microsoft Sentinel data in the Microsoft Defender portal
Part 2: Microsoft Defender for Endpoint
Platform overview and architecture
- Microsoft Defender for Endpoint overview
- Identify your architecture and select a deployment method for Defender for Endpoint
- Microsoft Defender for Endpoint on Windows
- Automatic attack disruption in Microsoft Defender XDR
Licensing, plans, and prerequisites
- Overview of Microsoft Defender for Endpoint Plan 1
- Microsoft Defender service description
- Minimum requirements for Microsoft Defender for Endpoint
- Manage Microsoft Defender for Endpoint subscription settings across client devices
- What is Microsoft Defender for Business?
Network connectivity
- Onboarding devices using streamlined connectivity for Microsoft Defender for Endpoint
- Configure your network environment to ensure connectivity with Defender for Endpoint service
- Microsoft Defender for Endpoint streamlined connectivity URLs - commercial
Onboarding Windows devices
- Onboarding using Microsoft Intune
- Configure Microsoft Defender for Endpoint with Intune and onboard devices
- Onboard servers through Microsoft Defender for Endpoint's onboarding experience
- Run a detection test on a device recently onboarded to Microsoft Defender for Endpoint
- Run the client analyzer on Windows
Onboarding macOS, Linux, and Mobile
- Microsoft Defender for Endpoint on macOS prerequisites
- Deploy Microsoft Defender for Endpoint on macOS with Microsoft Intune
- Set preferences for Microsoft Defender for Endpoint on macOS
- Microsoft Defender for Endpoint on Linux
- Prerequisites for Microsoft Defender for Endpoint on Linux
- Microsoft Defender for Endpoint mobile threat defense on Android and iOS
- Deploy and configure Microsoft Defender for Endpoint on Android
Defender for Cloud and servers
- Onboard servers through Defender for Cloud (Defender for Servers)
- Protect your servers with Defender for Servers
- Connect your non-Azure servers to Microsoft Defender for Cloud with Defender for Endpoint
- Connect your non-Azure machines to Microsoft Defender for Cloud (Azure Arc)
Next-generation protection and antivirus
- Microsoft Defender Antivirus compatibility with other security products
- Microsoft Defender Antivirus in passive mode
- Endpoint detection and response (EDR) in block mode
- EDR in block mode frequently asked questions (FAQ)
Advanced features and tamper protection
- Configure advanced features in Defender for Endpoint
- Protect security settings with tamper protection
- Manage tamper protection for your organization using the Microsoft Defender portal
- Built-in protection helps guard against ransomware
- Get started with troubleshooting mode in Microsoft Defender for Endpoint
Attack surface reduction
- Attack surface reduction (ASR) rules overview
- Attack surface reduction (ASR) rules reference
- Attack surface reduction (ASR) rules deployment guide
- Monitor attack surface reduction (ASR) rule activity
- Web protection in Microsoft Defender for Endpoint
- Web content filtering in Microsoft Defender for Endpoint
- Protect important folders with controlled folder access
Security settings management
Device groups, roles, and automation
- Create and manage device groups
- Automation levels in automated investigation and remediation capabilities
- Overview of automated investigations
- Configure automated investigation and remediation capabilities in Microsoft Defender for Endpoint
Vulnerability management
- Compare Microsoft Defender Vulnerability Management plans and capabilities
- Microsoft Defender Vulnerability Management overview page (dashboard insights)
- Exposure score in Defender Vulnerability Management
- Microsoft Secure Score for Devices
- Security recommendations
- Block vulnerable applications with Microsoft Defender Vulnerability Management
Investigation, response actions, and live response
- Take response actions on a device
- Investigate devices in Microsoft Defender for Endpoint
- Investigate entities on devices using live response
- Restrict response actions on high-value assets
- Device entity page in Microsoft Defender
Alerts, advanced hunting, and custom detections
- Proactively hunt for threats with advanced hunting in Microsoft Defender
- Learn the advanced hunting query language
- Create custom detection rules in Microsoft Defender XDR
Part 3: Microsoft Sentinel
Platform Overview and the Defender Portal
- What is Microsoft Sentinel security information and event management (SIEM)?
- What is Microsoft Sentinel?
- Microsoft Sentinel in the Microsoft Defender portal
- Connect Microsoft Sentinel to the Microsoft Defender portal
- Transition your Microsoft Sentinel environment to the Defender portal
- Microsoft Defender XDR integration with Microsoft Sentinel
Licensing, Cost Planning, and Onboarding
- Plan costs and understand Microsoft Sentinel pricing and billing
- Onboard Microsoft Sentinel
- Deploy for unified security operations
Workspace Design and Multi-Tenant Architecture
- Prepare for multiple workspaces and tenants in Microsoft Sentinel
- Extend Microsoft Sentinel across workspaces and tenants
- Design a Log Analytics workspace architecture
- Manage Microsoft Sentinel workspaces at scale (Azure Lighthouse)
Roles, RBAC, and Access Control
- Roles and permissions in the Microsoft Sentinel platform
- Map existing RBAC permissions to Microsoft Defender unified RBAC permissions
- Configure Microsoft Sentinel scoping (row-level RBAC)
Data Tiers, Retention, and the Sentinel Data Lake
- What is Microsoft Sentinel data lake?
- Onboard to Microsoft Sentinel data lake and Microsoft Sentinel graph
- Set up connectors for the Microsoft Sentinel data lake
Content Hub and Data Connectors
- Discover and manage Microsoft Sentinel out-of-the-box content
- Microsoft Sentinel out-of-the-box content overview
- Find your Microsoft Sentinel data connector
- Microsoft Sentinel data connectors
Ingestion: AMA, DCRs, Windows Events, Syslog, and CEF
- Connect Microsoft Sentinel to Microsoft services with a Windows agent-based data connector
- Syslog and Common Event Format (CEF) via AMA connectors for Microsoft Sentinel
- Ingest syslog and CEF messages to Microsoft Sentinel with the Azure Monitor Agent
- Collect logs from text files with the Azure Monitor Agent and ingest to Microsoft Sentinel
- Custom data ingestion and transformation in Microsoft Sentinel
Analytics Rules and Detection
- Threat detection in Microsoft Sentinel
- Scheduled analytics rules in Microsoft Sentinel
- Quick threat detection with near-real-time (NRT) analytics rules in Microsoft Sentinel
- Advanced multistage attack detection (Fusion) in Microsoft Sentinel
- Configure multistage attack detection (Fusion) rules in Microsoft Sentinel
Watchlists, Threat Intelligence, and Hunting
- Watchlists in Microsoft Sentinel
- Build queries or detection rules with watchlists in Microsoft Sentinel
- Threat intelligence in Microsoft Sentinel
- Use STIX/TAXII to import and export threat intelligence in Microsoft Sentinel
- Connect your threat intelligence platform to Microsoft Sentinel with the upload API
- Threat hunting in Microsoft Sentinel
- Conduct end-to-end proactive threat hunting in Microsoft Sentinel
- Keep track of data during hunting with Microsoft Sentinel (bookmarks)
- Jupyter notebooks with Microsoft Sentinel hunting capabilities
- Get started with Jupyter notebooks and MSTICPy in Microsoft Sentinel
UEBA (User and Entity Behavior Analytics)
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel
- Enable User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel
Automation, Playbooks, and SOAR
- Automation in Microsoft Sentinel: security orchestration, automation, and response (SOAR)
- Automate threat response with playbooks in Microsoft Sentinel
- Microsoft Sentinel SOAR content catalog
Workbooks, SOC Optimization, MITRE, and the Sentinel Graph
- Commonly used Microsoft Sentinel workbooks
- Manage your SOC better with incident metrics
- Optimize your security operations (SOC optimization)
- View MITRE ATT&CK framework coverage in Microsoft Sentinel
- Investigate Microsoft Sentinel incidents in depth in the Azure portal
- KQL and the Microsoft Sentinel data lake
- Create KQL jobs in the Microsoft Sentinel data lake
- Explore Microsoft Sentinel data lake with the data exploration collection (MCP)
Part 4: Threat Hunting with KQL
Unified Platform and Hunting Surfaces
- What are unified security operations in the Microsoft Defender portal?
- Microsoft Sentinel in the Microsoft Defender portal
- Connect Microsoft Sentinel to the Microsoft Defender portal
- Hunting in the Microsoft Defender portal
- Proactively hunt for threats with advanced hunting in Microsoft Defender
- Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal
Licensing, Quotas, and Data Coverage
- Choose between guided and advanced modes to hunt in Microsoft Defender XDR
- Quotas and usage parameters (advanced hunting service limits)
- Use the advanced hunting query resource report
- Handle advanced hunting errors
- Extend advanced hunting coverage with the right settings
KQL Foundations and Query Best Practices
- Learn the advanced hunting query language
- Advanced hunting query best practices
- Best practices for Kusto Query Language queries
- Optimize log queries in Azure Monitor
Advanced Hunting Schema Tables
- Understand the advanced hunting schema
- Migrate advanced hunting queries from Microsoft Defender for Endpoint
- DeviceProcessEvents table
- IdentityLogonEvents table
- IdentityDirectoryEvents table
- EmailPostDeliveryEvents table
- UrlClickEvents table
- CloudAppEvents table
Writing, Sharing, and Taking Action on Queries
- Advanced hunting example for Microsoft Defender for Office 365
- Take action on advanced hunting query results
- Microsoft Security Copilot in advanced hunting
Custom Detection Rules
- Create custom detection rules in Microsoft Defender XDR
- Feature comparison: Sentinel analytics rules and Defender custom detections
- Threat detection in Microsoft Sentinel
Sentinel Hunting, Bookmarks, and Hunts
- Threat hunting in Microsoft Sentinel
- Conduct end-to-end proactive threat hunting in Microsoft Sentinel
- Keep track of data during hunting with Microsoft Sentinel (bookmarks)
Entity Graphs, UEBA, and Blast Radius
- Enable User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel
- Advanced threat detection with UEBA in Microsoft Sentinel
- Investigate incidents in the Microsoft Defender portal (blast radius)
- Query the enterprise exposure graph
- make-graph operator
- Schemas and operators overview (Security Exposure Management)
Data Lake, KQL Jobs, Search Jobs, and Summary Rules
- Manage data tiers and retention in Microsoft Sentinel
- KQL jobs, summary rules, and search jobs
- Search for specific events across large datasets in Microsoft Sentinel
- Aggregate Microsoft Sentinel data with summary rules
- Aggregate data in a Log Analytics workspace by using summary rules