---
# source: src/content/solutions/en/endpoint-security/microsoft-defender-atp.md
# route:  /en/solutions/endpoint-security/microsoft-defender-atp/
title: Microsoft Defender
tags: [endpoint-security, security]
vendors: [microsoft]
summary: Endpoint detection and response from the Microsoft stack. If you already have M365 E5, you have usually already licensed it.
photoNeed: A security console on screen with real alerts in it, being triaged
stub: false
draft: false
kind: product
addon: false
vendorName: Microsoft Defender for Endpoint
status: current
---

## What it is

Defender for Endpoint reads what actually happens on a device and reports sequences that do
not fit. The analysis runs in Microsoft's cloud, and the signals come from the operating
system itself rather than from an agent bolted on afterwards.

## What it is for

Estates that are on Microsoft anyway. The practical advantage is rarely detection quality;
it is that identity, device management and endpoint security use the same groups and the
same console.

## What to watch

Two things. Licensing first: the full feature set depends on the plan, and the difference
between tiers is exactly the part you miss later. Then the first few weeks: backup agents,
monitoring and home-grown scripts all look like attackers to an EDR. Those exceptions
belong in writing, or in two years there is a rule set nobody wants to touch.
