Describe the Microsoft 365 Defender Suite
Microsoft 365 Defender is a cloud-based XDR suite that leverages billions of data points across the Microsoft 365 environment to provide detection, prevention, investigation, and response insights across workloads to protect against cybersecurity attacks.
Workloads protected under Microsoft 365 Defender are the following:
- Endpoints: Workstations, mobile devices, and servers
- Office 365: Emails, Teams chats, and SharePoint Online/OneDrive for Business files
- Identity: Users, behaviors, activities, and credentials
- Cloud apps: First- and third-party SaaS systems incorporated within an organization
With all these workloads covered by Microsoft 365 Defender, security administrators can then use a security information and event management (SIEM) and security orchestration, automation, and response (SOAR) product such as Microsoft Sentinel to help collect data and alerts and track them as security incidents. That will...