Microsoft 365 Defender

Stop attacks with automated, cross-domain security and built-in AI.

Microsoft 365 E5 benefit with Microsoft Sentinel

Microsoft 365 E5 and Microsoft 365 E5 Security customers can get Azure credits towards up to 100 MB per user per month of Microsoft 365 data ingestion, saving a typical 3,500-seat deployment $1,500 per month.

Stop attacks across Microsoft 365 services

As threats become more complex and persistent, alerts increase, and security teams are overwhelmed. Microsoft 365 Defender, part of Microsoft’s XDR solution, leverages the Microsoft 365 security portfolio to automatically analyze threat data across domains, building a complete picture of each attack in a single dashboard. With this breadth and depth of clarity defenders can now focus on critical threats and hunt for sophisticated breaches, trusting that the powerful automation in Microsoft 365 Defender detects and stops attacks anywhere in the kill chain and returns the organization to a secure state.

Stop attacks before they happen

Reduce your attack surface and eliminate persistent threats.

Detect and automate across domains

Integrate threat data for rapid and complete response.

Hunt across all your data

Leverage time saved to apply your unique expertise.

Microsoft 365 Defender capabilities

Protect your Microsoft 365 environment

Leverage the best-in-class Microsoft 365 security portfolio to automatically analyze data across domains.


Manage and secure hybrid identities and simplify employee, partner, and customer access.


Deliver preventive protection, post-breach detection, automated investigation, and response for endpoints.

Cloud apps

Get visibility, control data, and detect threats across cloud services and apps.

Email and documents

Secure your email, documents, and collaboration tools with Microsoft Defender for Office 365.

Industry recognition

Screenshot from video.


Protecting your enterprise means bringing together insights from all your security tools. Microsoft 365 Defender integrates with cloud-native security information and event manager (SIEM), Microsoft Sentinel.


Microsoft Sentinel delivers intelligent security analytics for your entire enterprise from a single console. Connect with data from your Microsoft products and all other sources, and take advantage of AI to make your threat detection and response smarter and faster. Eliminate security infrastructure setup and maintenance and scale to meet your security needs.


Microsoft Sentinel also connects to Microsoft Defender for Cloud, a built-in tool that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Microsoft Defender for Cloud protects your hybrid data, cloud-native services, and servers from threats and seamlessly integrates with your existing security solutions while leveraging Microsoft’s vast threat intelligence.

Learn more about Microsoft 365 Defender

Blog series

Stay up to date with the latest news and features about Microsoft 365 Defender.


Microsoft 365 Defender is included with some Microsoft 365 and Office 365 Security and Enterprise licenses.

Tech community

Learn best practices, get updates, and engage with product teams in the Microsoft 365 Defender tech community.

1. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, express or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.