Which Microsoft Defender XDR product protects which workload
Verdict: Match the workload to the product: devices are Endpoint, email is Office 365, directory identities are Identity, SaaS apps are Cloud Apps, and asset vulnerabilities are Vulnerability Management. XDR is the suite that unifies them.
| Criterion | Defender for Endpoint | Defender for Office 365 | Defender for Identity | Defender for Cloud Apps | Defender Vulnerability Management |
|---|---|---|---|---|---|
| Protects | Devices: laptops, phones, tablets, PCs | Email and collaboration in Microsoft 365 | Identities via AD and Entra ID signals | SaaS applications and their data | Assets against vulnerabilities and misconfigurations |
| Signature capability | Endpoint detection and response | Defends messages, links, and collaboration tools | Detects identity-based attacks | CASB Shadow IT discovery and risk ranking | Risk-based assessment and built-in remediation |
Rules
- Defender for Office 365 is the primary email and collaboration security solution, defending against threats in messages, links, and collaboration tools.
- Defender for Endpoint is the enterprise endpoint security platform for devices such as laptops, phones, and PCs.
- Defender for Cloud Apps delivers CASB Shadow IT discovery, risk-ranks cloud services, and protects SaaS data.
- Defender for Identity detects identity-based attacks using on-premises Active Directory and Microsoft Entra ID signals.
- Defender XDR is the unified pre- and post-breach suite that coordinates response across endpoints, identities, email, and apps; within it, identities are protected by Defender for Identity plus Entra ID Protection.
- Defender Threat Intelligence aggregates DNS, WHOIS, malware, and SSL data with reputation scoring for threat-infrastructure analysis.
Traps
- Defender for Endpoint is one product feeding the XDR suite, not the suite itself - the suite is Defender XDR.
- Vulnerability Management assesses assets; it does not detect identity attacks (Identity) or secure email (Office 365).