Microsoft 365 Defender XDR – centralizing investigation and response
Throughout this chapter, you have learned about the four core services that make up Microsoft 365 Defender. These services benefit from centralized investigation and incident response options in the Microsoft 365 Defender portal, accessed as a website at security.microsoft.com. We refer to this unified capability as XDR. In this section, you will learn about those capabilities.
Incidents and alerts
Security is simpler with unified review and response. When dealing with an attack, you don’t want to be slowed down and have the job complicated by navigating multiple systems and correlating events manually. Microsoft 365 Defender incidents and alerts provide such a unified system, including consolidating related objects to make the big picture clearer.
An alert is created when a service identifies risky, suspicious, or malicious activity. You will also learn later in this book how to create your...