Microsoft Learn references

Microsoft Defender Field Guides: The Complete Collection

Every reference the book lists, as a link, under the book's own headings. If a page has moved, search Microsoft Learn for its title.

Part 1: Microsoft Defender XDR

Defender XDR Overview and Zero Trust

Licensing, Prerequisites, and Turning It On

Incidents, Alerts, and the Correlation Engine

Workload Signal Sources

Unified RBAC

Alert Tuning and Noise Reduction

Automated Investigation and Response (AIR)

Automatic Attack Disruption

Threat Analytics

Case Management and Collaboration

Embedded Security Copilot and AI Agents

Sentinel Unified Platform and Advanced Hunting

Part 2: Microsoft Defender for Endpoint

Platform overview and architecture

Licensing, plans, and prerequisites

Network connectivity

Onboarding Windows devices

Onboarding macOS, Linux, and Mobile

Defender for Cloud and servers

Next-generation protection and antivirus

Advanced features and tamper protection

Attack surface reduction

Security settings management

Device groups, roles, and automation

Vulnerability management

Investigation, response actions, and live response

Alerts, advanced hunting, and custom detections

Part 3: Microsoft Sentinel

Platform Overview and the Defender Portal

Licensing, Cost Planning, and Onboarding

Workspace Design and Multi-Tenant Architecture

Roles, RBAC, and Access Control

Data Tiers, Retention, and the Sentinel Data Lake

Content Hub and Data Connectors

Ingestion: AMA, DCRs, Windows Events, Syslog, and CEF

Analytics Rules and Detection

Watchlists, Threat Intelligence, and Hunting

UEBA (User and Entity Behavior Analytics)

Automation, Playbooks, and SOAR

Workbooks, SOC Optimization, MITRE, and the Sentinel Graph

Part 4: Threat Hunting with KQL

Unified Platform and Hunting Surfaces

Licensing, Quotas, and Data Coverage

KQL Foundations and Query Best Practices

Advanced Hunting Schema Tables

Writing, Sharing, and Taking Action on Queries

Custom Detection Rules

Sentinel Hunting, Bookmarks, and Hunts

Entity Graphs, UEBA, and Blast Radius

Data Lake, KQL Jobs, Search Jobs, and Summary Rules

Notebooks, MITRE ATT&CK, and Threat Analytics