Microsoft Defender for Endpoint: Endpoint Security, EDR, and Vulnerability Management in Microsoft Defender XDR
Microsoft Defender Advanced Threat Protection, formerly known as MDATP, is now Microsoft Defender for Endpoint. In 2026, it is a core part of Microsoft Defender XDR, helping organizations protect endpoints, detect advanced attacks, investigate incidents, and reduce exposure across Windows, macOS, Linux, iOS, Android, and server workloads.
From MDATP to Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is Microsoft’s endpoint protection platform for prevention, endpoint detection and response, automated investigation, threat hunting, and vulnerability management. The old names Microsoft Defender Advanced Threat Protection and MDATP are still common in older documentation, but the current product name is Microsoft Defender for Endpoint.
The experience is now managed primarily from the Microsoft Defender portal at security.microsoft.com, where endpoint alerts, device inventory, incidents, advanced hunting, vulnerability data, and Microsoft Defender XDR correlations are brought together.
What Defender for Endpoint does
Defender for Endpoint helps security teams prevent, detect, investigate, and respond to endpoint threats. On Windows 11 and supported Windows Server versions, it uses built-in operating system sensors plus Microsoft Defender Antivirus and endpoint security controls. For macOS, Linux, iOS, and Android, onboarding requires the appropriate Microsoft Defender app, package, or platform-specific configuration.
Core capabilities include endpoint detection and response, attack surface reduction, tamper protection, network protection, web protection, device control, automated investigation and response, device isolation, live response, EDR in block mode, advanced hunting with KQL, and integration with Microsoft Defender XDR incidents.
Deployment is easier than traditional agents, but it still requires planning
Older descriptions often said there is nothing to deploy because Windows includes the Defender for Endpoint sensor. In practice, organizations still need a proper onboarding and configuration plan. Windows devices must be onboarded to the tenant, Microsoft Defender Antivirus must be in the correct active or passive state, endpoint security policies must be configured, and non-Windows devices require platform-specific deployment.
Common deployment methods include Microsoft Intune endpoint security policies and security baselines, Microsoft Configuration Manager, Group Policy, onboarding scripts, local scripts for testing, VDI and non-persistent device onboarding, and mobile device management for iOS and Android. For servers, Microsoft Defender for Servers through Microsoft Defender for Cloud is often the right path, especially for hybrid and multicloud environments.
Incidents, alerts, and Defender XDR correlation
The Microsoft Defender portal shows incidents and alerts across endpoints, identities, email, collaboration tools, cloud apps, and cloud workloads when the corresponding Defender products are enabled. This is a major difference from the older MDATP-only experience.
Endpoint alerts can be correlated with Microsoft Defender for Office 365 signals, Microsoft Defender for Identity signals, Microsoft Defender for Cloud Apps activity, and Microsoft Defender for Cloud workload alerts. For example, an investigation may show that malware activity on a device originated from a phishing email, identify who else received the message, and show whether mail was delivered, quarantined, blocked, or remediated.
Automated investigation and response
Automated investigation and response helps reduce manual workload by analyzing alerts, collecting evidence, building an incident story, and recommending or taking remediation actions depending on configuration and licensing. Actions can include stopping processes, quarantining files, removing persistence mechanisms, and remediating detected threats.
Organizations should review automation levels, device groups, approval requirements, exclusions, and alert tuning before enabling broad automated remediation. High-confidence automation can significantly improve response time, but it should be aligned with the organization’s operational risk tolerance.
Live response and containment
Live response gives authorized security operators a secure remote shell to a device for investigation and containment. It can be used to collect forensic data, run approved scripts, inspect files, and take immediate action during an active investigation.
Other response actions may include isolating a device from the network, restricting app execution, collecting an investigation package, initiating antivirus scans, and submitting suspicious files for analysis. These actions should be controlled with role-based access, just-in-time operational processes, and clear incident response procedures.
Advanced hunting and security operations
Advanced hunting uses Kusto Query Language to search across endpoint and Microsoft Defender XDR data. Security teams can hunt for suspicious processes, unusual network connections, vulnerable software exposure, lateral movement indicators, identity activity, and email-related events.
Hunting queries can support proactive threat hunting, incident scoping, custom detections, executive reporting, and integration with Microsoft Sentinel. Built-in reports in the Defender portal should be the starting point, while APIs, advanced hunting exports, Microsoft Sentinel workbooks, and optional Power BI reporting can be used for custom analytics.
Microsoft Defender Vulnerability Management
Threat & Vulnerability Management has evolved into Microsoft Defender Vulnerability Management. It provides visibility into exposed devices, software inventory, weaknesses, CVEs, missing security updates, insecure configurations, exposure score, and prioritized security recommendations.
Security teams can review affected devices, related software, exploitability context, remediation guidance, and business impact. Remediation workflows can be connected with Microsoft Intune so endpoint teams can deploy configuration changes, security baselines, app updates, or patching actions. Some advanced vulnerability management features require specific licenses, standalone subscriptions, or add-ons depending on the customer’s Microsoft 365 and Defender plan.
Licensing options for CSP customers in 2026
Licensing should be reviewed before deployment because available features vary by plan. Common CSP and NCE-aligned options include Microsoft Defender for Endpoint Plan 1, Microsoft Defender for Endpoint Plan 2, Microsoft Defender for Business, Microsoft 365 Business Premium, Microsoft 365 E5, Microsoft Defender Vulnerability Management, and Microsoft Defender for Servers through Microsoft Defender for Cloud.
Microsoft 365 Business Premium includes Microsoft Defender for Business for small and midsize organizations. Microsoft 365 E5 includes Microsoft Defender for Endpoint Plan 2 and broader Microsoft Defender XDR capabilities. Defender for Endpoint Plan 1 focuses on next-generation protection and attack surface reduction, while Plan 2 adds advanced EDR, automated investigation, hunting, and richer security operations capabilities. Server protection is typically licensed through Defender for Servers, not by assigning standard user endpoint licenses to servers.
For CSP customers, licensing should also account for New Commerce Experience terms, monthly or annual commitments, add-on eligibility, tenant prerequisites, and whether the organization needs Microsoft Sentinel, Defender for Office 365, Defender for Identity, Intune, or Defender Vulnerability Management capabilities.
Platform support and feature differences
Defender for Endpoint supports a broad set of platforms, but not every feature is identical on every operating system. Windows 11 and supported Windows Server versions generally provide the richest integration because endpoint sensors and Microsoft Defender Antivirus are built into the platform. macOS and Linux require onboarding packages and have platform-specific protection and EDR capabilities. iOS and Android focus more on mobile threat defense, web protection, phishing protection, and device risk signals.
A successful rollout should define device groups, platform coverage, exclusions, mobile management requirements, server requirements, and minimum operating system versions before onboarding production devices.
Reporting, retention, and integrations
The Microsoft Defender portal includes dashboards and reports for incidents, devices, vulnerabilities, software inventory, recommendations, device health, web protection, and security operations. Advanced hunting provides flexible querying, and APIs can be used for custom reporting or integration with external systems.
Microsoft Sentinel is the preferred SIEM and SOAR integration path for organizations that need long-term retention, cross-platform analytics, automation playbooks, and centralized security monitoring. Data retention in Defender and Sentinel depends on licensing, configuration, and workspace retention settings, so it should be validated as part of the architecture rather than assumed from older MDATP guidance.
Recommended 2026 implementation approach
A modern Defender for Endpoint project should start with licensing and readiness assessment, followed by a pilot group, baseline policy design, onboarding method selection, device group design, alert and automation tuning, vulnerability management setup, and incident response testing.
Important configuration areas include Microsoft Defender Antivirus policy, cloud-delivered protection, tamper protection, endpoint detection and response settings, EDR in block mode where appropriate, attack surface reduction rules, network protection, web content filtering, device control, role-based access, alert notifications, automated investigation settings, and Defender XDR service integrations.
Key takeaways
- Microsoft Defender Advanced Threat Protection is now Microsoft Defender for Endpoint and is managed in the Microsoft Defender portal.
- Defender for Endpoint is strongest when used as part of Microsoft Defender XDR, alongside email, identity, cloud app, and cloud workload protection.
- Deployment still requires planning, even though Windows includes built-in Defender sensors.
- Licensing varies across Defender for Endpoint P1, P2, Defender for Business, Microsoft 365 Business Premium, Microsoft 365 E5, Defender Vulnerability Management, and Defender for Servers.
- Vulnerability management, advanced hunting, automated investigation, live response, and Sentinel integration are central to a mature endpoint security program.
IT Partner can help you review your Microsoft 365 and CSP licensing, plan a Defender for Endpoint rollout, configure Intune endpoint security policies, enable Microsoft Defender XDR integrations, and validate your incident response readiness.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.