How M365D works as an XDR
M365D automatically collects, correlates, and analyzes alert and threat data from across your endpoints onboarded to MDE, your emails from MDO, your applications from MDA, and your identities from Azure Active Directory (AD) Identity Protection and MDI. M365D uses artificial intelligence (AI) and automation to help you stop attacks automatically and remediate affected entities into a compliant state once more.
Unlike the EDR part of M365D (Defender for Endpoint), which is a post-breach security service, the XDR service is a unified pre- and post-breach security service.
The following diagram illustrates an ongoing attack, starting with a phishing email arriving in an unsuspecting user’s mailbox. The user unknowingly opens the attachment, installing malware on the user’s endpoint, which is then used to move laterally within the environment gaining higher privileges and ultimately exfiltrating data:
Figure 18.1...