Microsoft Defender Suite ReferenceMicrosoft Defender Suite Reference

Produktüberblick, Lizenzmatrix, Integrationen und operative Einsatzmuster für die Microsoft-Defender-Suite.Product overview, licensing matrix, integrations, and operational usage patterns for the Microsoft Defender suite.

PortalPortal

security.microsoft.com als einheitliche Incident-Ansicht.security.microsoft.com as the unified incident view.

AbdeckungCoverage

Endpoints, Identity, Email, SaaS, Cloud und SIEM.Endpoints, identity, email, SaaS, cloud, and SIEM.

IntegrationIntegration

Defender XDR + Sentinel + Entra + Intune.Defender XDR + Sentinel + Entra + Intune.

Defender XDR ÜberblickDefender XDR overview

Die Microsoft-Defender-Suite konsolidiert Sicherheitsdaten und Steuerungen rund um Endpunkte, E-Mail, Identitäten, Cloud-Apps und Cloud-Ressourcen. Das operative Zentrum ist das einheitliche Portal unter security.microsoft.com, ergänzt um Defender for Cloud im Azure-Portal und Sentinel für SIEM/SOAR.The Microsoft Defender suite consolidates security data and controls around endpoints, email, identities, cloud apps, and cloud resources. The operational center is the unified portal at security.microsoft.com, complemented by Defender for Cloud in the Azure portal and Sentinel for SIEM and SOAR.

Defender for Endpoint P1/P2Defender for Endpoint P1/P2

CapabilityCapabilityP1P1P2P2
Next-gen protection / AVJaYes
Attack Surface ReductionJaYes
EDRBasisAdvanced
Device inventoryJaYes
Threat & Vulnerability ManagementEingeschränktFull
Automated investigation and remediationNeinYes

Defender for Office 365 P1/P2Defender for Office 365 P1/P2

KontrolleControlNutzenPurpose
Safe LinksSafe LinksURL-Rewrite und Klickschutz für Mail und Collaboration.URL rewrite and click protection for email and collaboration.
Safe AttachmentsSafe AttachmentsSandboxing für Anhänge und detonationsbasierte Analyse.Sandboxing for attachments and detonation-based analysis.
Anti-phishingAnti-phishingSpoof-, impersonation- und mailbox-intelligence-basierter Schutz.Spoof, impersonation, and mailbox-intelligence-based protection.
AIRAIRAutomated investigation and remediation für Mail-Events.Automated investigation and remediation for email events.

Defender for IdentityDefender for Identity

BereichAreaBeschreibungDescription
Sensor deploymentSensor deploymentSensoren auf Domänencontrollern oder per standalone sensor bereitstellen.Deploy sensors on domain controllers or as standalone sensors.
AlertsAlertsKerberoasting, DCSync, Pass-the-Ticket, Suspicious LDAP und weitere Indikatoren.Kerberoasting, DCSync, pass-the-ticket, suspicious LDAP, and more indicators.
Lateral movement pathsLateral movement pathsPfadanalysen für laterale Bewegung und kritische Abhängigkeiten.Path analysis for lateral movement and critical dependencies.

Defender for Cloud AppsDefender for Cloud Apps

FunktionFunctionBeschreibungDescription
DiscoveryDiscoveryShadow-IT erkennen über Firewall-, Proxy- oder Defender-Daten.Discover shadow IT through firewall, proxy, or Defender data.
App governanceApp governanceOAuth-Apps, Permissions und riskante App-Verhaltensmuster überwachen.Monitor OAuth apps, permissions, and risky app behavior.
Session controlSession controlReverse-Proxy-basierte Echtzeitkontrolle für Downloads, Watermarks und Monitoring.Reverse-proxy-based real-time control for downloads, watermarks, and monitoring.
PoliciesPoliciesAnomaly, activity, file und app-based policies für SaaS und M365.Anomaly, activity, file, and app-based policies for SaaS and M365.

Defender for CloudDefender for Cloud

ModulModuleNutzenPurpose
CSPMCSPMSecure Score, Empfehlungen und Governance für Cloud-Konfiguration.Secure Score, recommendations, and governance for cloud configuration.
CWPCWPWorkload-Schutz für VMs, SQL, Storage, Containers und mehr.Workload protection for VMs, SQL, storage, containers, and more.
RecommendationsRecommendationsPriorisierte Maßnahmen mit regulatorischem Mapping.Prioritized actions with regulatory mapping.

Microsoft SentinelMicrosoft Sentinel

BausteinBuilding blockNutzenPurpose
Data connectorsData connectorsEntra, M365, Defender, Firewalls, EDR und viele Drittquellen anbinden.Connect Entra, M365, Defender, firewalls, EDR, and many third-party sources.
Analytics rulesAnalytics rulesKQL-basierte Erkennung, Fusion und UEBA.KQL-based detection, fusion, and UEBA.
PlaybooksPlaybooksSOAR-Orchestrierung via Logic Apps.SOAR orchestration through Logic Apps.
WorkbooksWorkbooksDashboards für Jagd, Metriken und Management-Berichte.Dashboards for hunting, metrics, and management reporting.

Integration der ProdukteIntegration between products

QuelleSourceIntegriert mitIntegrates withMehrwertValue
Defender for EndpointDefender XDR, Sentinel, IntuneGerätealarme, TVM und Device Context in Incident-Ketten.Device alerts, TVM, and device context inside incident chains.
Defender for Office 365Defender XDR, Exchange, SentinelMail-Events werden mit Identität und Endpoint-Telemetrie korreliert.Email events are correlated with identity and endpoint telemetry.
Defender for IdentityDefender XDR, Entra ID, SentinelOn-prem AD-Angriffe werden mit Cloud-Identität verbunden.On-prem AD attacks are connected with cloud identity.
Defender for Cloud AppsConditional Access, Defender XDR, SentinelSession Control und OAuth-Governance schließen die SaaS-Lücke.Session control and OAuth governance close the SaaS gap.

LizenzanforderungenLicensing requirements

ProduktProductTypische LizenzTypical license
Defender for EndpointMicrosoft 365 E5 / Security E5 / Defender for Endpoint P2Microsoft 365 E5 / Security E5 / Defender for Endpoint P2
Defender for Office 365Defender for Office 365 P1/P2 oder M365 E5Defender for Office 365 P1/P2 or M365 E5
Defender for IdentityM365 E5 / Security E5 / standaloneM365 E5 / Security E5 / standalone
Defender for Cloud AppsM365 E5 / Security E5 / standaloneM365 E5 / Security E5 / standalone
Defender for CloudAzure-planabhängig, pro Resource und PlanAzure-plan-dependent, per resource and plan
SentinelAzure consumption-basiert + DatenvolumenAzure consumption-based plus data volume

GitHub-ReferenzenGitHub references

RepositoryRepositoryNutzenPurpose
microsoft/Microsoft-365-Defender-Hunting-QueriesKQL- und Hunting-Queries für Defender XDR.KQL and hunting queries for Defender XDR.
Azure/Azure-SentinelAnalytics Rules, Workbooks, Playbooks und Community Content für Sentinel.Analytics rules, workbooks, playbooks, and community content for Sentinel.
PowerShell
Connect-MgGraph -Scopes "SecurityEvents.Read.All"
# Grundlegend: Entra Risk + Defender Incident Korrelationsdaten lesen
Invoke-MgGraphRequest -Method GET -Uri "https://graph.microsoft.com/v1.0/security/incidents"