We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Security
  2. Defender XDR
Microsoft Defender XDR

Correlation only happens across the products you actually hold a license for. Half a suite gives you half a picture.

This is the layer that joins endpoint, identity, email and cloud application signals into a single incident, disrupts attacks on its own and repairs what it can afterwards. The documentation says plainly that it correlates signals from the products you have licensed and provisioned, which is precisely why the value you get depends on your coverage rather than on how well anybody configured it.

Book an XDR coverage reviewSee what the layer adds
Microsoft Defender XDR for US organizations
  • Eleven productsFeed the correlation layer
  • One incidentInstead of alerts in separate consoles
  • Auto disruptionContainment applied without a human
  • 30 daysRaw signal available for hunting
The question to answer before anything else

Out of the eleven signal sources, how many do you genuinely hold?

Correlation happens across the products you have licensed and provisioned access to, and no further. That makes coverage rather than configuration the variable deciding what this is worth to you.

  • Four come to mind for most people: Defender for Endpoint, Defender for Office 365, Defender for Identity and Defender for Cloud Apps. Most American businesses we assess hold one or two of those and correlate across exactly that much, which yields a fraction of the cross-domain picture they believe they are getting.
  • The published list continues past those four with Defender Vulnerability Management, Defender for Cloud, Microsoft Entra ID Protection, Data Loss Prevention, App Governance, Purview Insider Risk Management and Microsoft Security Exposure Management. Several of them are routinely licensed already through an enterprise subscription and have simply never been switched on.
  • Which means the first genuinely useful exercise is not configuring anything. It is establishing which of the eleven you already hold, which of those are provisioned, and which are licensed but sitting switched off. That third list runs longer than the security team expects almost every time.
  • Attack disruption rests on the same foundation. That published example, where a malicious file found on an endpoint gets removed from every mailbox in the organization, needs both endpoint and email protection present to work. Hold one of the two and the behavior simply never happens.
Ask us to map your coverage against the eleven
What the correlation layer adds

Eight things this layer does that no individual product in the family does alone.

The description is a unified pre-breach and post-breach defense suite, natively coordinating detection, prevention, investigation and response across endpoints, identities, email and applications, with a cross-product layer sitting above and augmenting each individual component.

The licensing caveat, which decides what you actually get

The documentation states directly that correlation happens across the Microsoft security products you have licensed and provisioned access to. That one sentence matters more than anything else here. A business running endpoint protection alone gets endpoint correlation and nothing more. The cross-domain story making XDR worth buying requires those domains to be covered in the first place, and most estates cover two or three out of eleven.

One incident, not alerts in four consoles

The stated purpose of the combined incidents queue is helping security professionals concentrate on what is critical, by ensuring the full scope of an attack, the assets it touched and the automated remediation actions all arrive grouped together and promptly. For a small team, receiving one incident with a timeline attached rather than four apparently unrelated alerts is the difference between responding to something and merely triaging it.

Automatic attack disruption, with a concrete example

What happens is that high-confidence signals from several workloads get correlated, and containment actions are applied automatically to halt an attack in progress and limit lateral movement. The published example is admirably precise. A malicious file detected on an endpoint causes Defender for Office 365 to scan for and remove that same file from every email message, after which the entire suite blocks it on sight.

Self-healing across devices, identities and mailboxes

AI-powered automatic actions and playbooks return the affected assets to a secure state, drawing on the automatic remediation capabilities inside each suite product so that every impacted asset connected to an incident gets remediated wherever that is possible. For a team with no spare capacity for manual cleanup, a meaningful share of the value sits right here.

Cross-product hunting, with a thirty-day window

Query-based access reaches thirty days of historic raw signals and alert data drawn from Defender for Endpoint, Defender for Office 365, Defender for Identity and Defender for Cloud Apps. Thirty days is generous for hunting and distinctly short for investigating something discovered late, which is exactly why Sentinel and longer retention exist alongside it rather than instead of it.

Eleven contributing products, not four

Past the four Defender workloads everybody expects, the published list continues with Defender Vulnerability Management, Defender for Cloud, Microsoft Entra ID Protection, Data Loss Prevention, App Governance, Purview Insider Risk Management and Microsoft Security Exposure Management. Several of those are capabilities businesses already own and have never once connected into the wider picture.

The narrative, which is what a report actually needs

The layer is described as narrating the complete story of an attack across product alerts, behaviors and context, achieved by joining data about alerts, suspicious events and impacted assets into incidents. When somebody has to explain to a board, to an insurer or to breach counsel how an attack got in, what it reached and what was done about it, that narrative is the deliverable. A list of alerts is not.

Signal sharing that makes each product better

That cross-product layer protects against attacks and coordinates the defensive response through signal sharing and automated actions, meaning a detection in one workload strengthens all the others rather than remaining local to where it happened. This compounding effect is the genuine argument for staying inside one product family, and it is equally the reason partial coverage underdelivers against what the marketing implies.

How we approach it

Four things that decide whether this delivers what the name promises.

This is not really a thing you deploy. It is a thing that grows more valuable as the workloads underneath it get covered, which makes the coverage audit the real project rather than a preliminary to it.

We map coverage against the eleven sources first

Because correlation is documented as covering only the products you have licensed and provisioned access to. So we establish which of the eleven you hold, which of those are provisioned, and which are licensed but were never switched on. In most estates that third category is the surprise, and closing it costs nothing beyond configuration time.

We enable attack disruption deliberately, with the team briefed

Containment actions get applied automatically to halt an attack in progress and limit lateral movement, which is exactly what you want and also means the platform will act without consulting anybody first. Establishing what it is able to do, who gets told when it fires, and how an action is reviewed afterwards is a short conversation that heads off a much longer one later.

The thirty day window is treated as a design input rather than a footnote

Thirty days of raw signal is plentiful for hunting and distinctly short for investigating something discovered months afterwards, which describes the common case for a breach rather than the exception. Where your retention obligations or your realistic discovery timelines run past that, the answer is Sentinel with longer retention rather than hoping thirty days turns out to be enough.

We make sure somebody actually works the queue

One combined incident queue beats four separate consoles by a considerable margin, and it still needs a human being. We establish who triages, within what timeframe, and what happens when something arrives outside working hours. The most common failure of a genuinely good detection platform is not that it missed something. It is that nobody opened the incident it produced.

Where this matters most

Six US situations where the correlation layer changes the outcome.

The common factor is an attack that crosses domains, which describes nearly every real intrusion and almost none of the tooling most organizations have.

A phishing email that became an endpoint compromise

The most common shape of a real incident, and the one that separate consoles handle worst. With email and endpoint both feeding the correlation layer, that becomes a single incident with a timeline from the message to the device. With one of the two, it becomes two alerts that somebody has to connect by hand, if they notice at all.

A small team drowning in alerts

Two or three people between them covering endpoint, identity, email and cloud. The combined incident queue exists precisely to group the full attack scope, the impacted assets and the automated remediation actions together in one place. That grouping separates a team that responds to incidents from a team spending its entire day working out which alerts belong to each other.

A regulated firm that has to narrate an incident

The moment an insurer, a board, breach counsel or an examiner asks how the attack got in, what it reached and what was done about it. The layer is described as narrating the full story across alerts, behaviors and context, and that narrative is precisely the artifact those questions require. Reconstructing the same thing by hand from separate products takes days. For a firm weighing a state breach notification or an SEC materiality determination, days are exactly what it does not have.

An organization with no out-of-hours coverage

Automatic attack disruption applies containment without waiting for anybody, and self-healing then remediates the affected devices, identities and mailboxes wherever it can. For a business whose security capacity runs to office hours, that automation is doing the work nobody is awake to do, and on its own that is a meaningful argument for the product.

An organization on E5 using a fraction of it

This is the finding we make more often than any other. Several of the eleven signal sources turn out to be licensed already and never provisioned, and each one connected widens the correlation without a dollar of additional spend. Producing that list is a short exercise returning unusually well against the effort it takes.

A team ready to go hunting rather than only responding

Thirty days of query-based access to raw signals and alert data spanning endpoint, email, identity and cloud applications makes a genuinely useful hunting surface. For a team willing to go looking rather than waiting to be told, this is where that begins, and none of it requires Sentinel to get started.

Three positions

How much of the attack story US organizations can actually see.

Most organizations sit in the middle column. Two or three Defender workloads licensed, correlating happily with one another, producing a partial picture that people quite reasonably mistake for a complete one.
Endpoint detections
Broad coverageYes
Two or three workloadsYes
Endpoint onlyYes
Email entry point visible
Broad coverageYes
Two or three workloadsSometimes
Endpoint onlyNo
Identity movement visible
Broad coverageYes
Two or three workloadsRarely
Endpoint onlyNo
SaaS and cloud application activity visible
Broad coverageYes
Two or three workloadsRarely
Endpoint onlyNo
One incident with a full timeline
Broad coverageYes
Two or three workloadsPartial
Endpoint onlyNo
Attack disruption across workloads
Broad coverageYes
Two or three workloadsLimited
Endpoint onlyNo
Self-healing across devices, identities and mailboxes
Broad coverageYes
Two or three workloadsPartial
Endpoint onlyDevices only
Cross-product hunting available
Broad coverageYes
Two or three workloadsLimited
Endpoint onlyNo
Attack narrative available for a report
Broad coverageYes
Two or three workloadsPartial
Endpoint onlyNo
Could scope an incident for a disclosure decision
Broad coverageYes
Two or three workloadsPartial
Endpoint onlyNo
Feature
Broad coverage
Two or three workloads
Endpoint only
Endpoint detections
YesYesYes
Email entry point visible
YesSometimesNo
Identity movement visible
YesRarelyNo
SaaS and cloud application activity visible
YesRarelyNo
One incident with a full timeline
YesPartialNo
Attack disruption across workloads
YesLimitedNo
Self-healing across devices, identities and mailboxes
YesPartialDevices only
Cross-product hunting available
YesLimitedNo
Attack narrative available for a report
YesPartialNo
Could scope an incident for a disclosure decision
YesPartialNo
The signal sources

Eleven products, and what each contributes to the picture.

Taken from the published list. The right hand column describes what each source contributes to a correlated incident, which is the useful way to judge whether a particular gap matters to you or not.

Product

Defender for Endpoint

What it contributes
Detections from devices, supplying the endpoint half of almost every attack story

Product

Defender for Office 365

What it contributes
Email and collaboration, usually the entry point

Product

Defender for Identity

What it contributes
On-premises and hybrid identity, reconnaissance and lateral movement

Product

Defender for Cloud Apps

What it contributes
Activity across your SaaS estate, OAuth applications, and data sitting in third-party services

Product

Defender Vulnerability Management

What it contributes
What was exposed, and whether it was being exploited

Product

Defender for Cloud

What it contributes
Azure, AWS and GCP workload and posture signals

Product

Microsoft Entra ID Protection

What it contributes
Cloud identity risk, risky sign-ins and risky users

Product

Data Loss Prevention

What it contributes
Whether sensitive content moved during the incident

Product

App Governance

What it contributes
OAuth applications with standing permissions to your data

Product

Purview Insider Risk Management

What it contributes
Behavioral risk signals, where the actor may be internal

Product

Security Exposure Management

What it contributes
Attack paths and exposure context around the affected assets
ProductWhat it contributes
Defender for EndpointDetections from devices, supplying the endpoint half of almost every attack story
Defender for Office 365Email and collaboration, usually the entry point
Defender for IdentityOn-premises and hybrid identity, reconnaissance and lateral movement
Defender for Cloud AppsActivity across your SaaS estate, OAuth applications, and data sitting in third-party services
Defender Vulnerability ManagementWhat was exposed, and whether it was being exploited
Defender for CloudAzure, AWS and GCP workload and posture signals
Microsoft Entra ID ProtectionCloud identity risk, risky sign-ins and risky users
Data Loss PreventionWhether sensitive content moved during the incident
App GovernanceOAuth applications with standing permissions to your data
Purview Insider Risk ManagementBehavioral risk signals, where the actor may be internal
Security Exposure ManagementAttack paths and exposure context around the affected assets
How an engagement runs

Five steps, of which the first is an audit rather than any kind of deployment.

Three to six weeks in most cases. The correlation layer needs enabling rather than building from scratch. Where the value comes from is what you connect into it.
  1. 1

    Map coverage against the eleven signal sources

    We establish which are licensed, which are provisioned, and which are licensed while sitting switched off. Since correlation is documented as covering only what you hold and have provisioned, this list sets the ceiling on everything afterwards. It also, reliably, contains a few wins that cost nothing.

  2. 2

    Connect what is already paid for

    We begin with whichever workloads widen the picture furthest, which usually means email joining endpoint, then identity, then cloud applications. Every addition improves the correlation on every incident that follows it, and where the license already exists the only cost involved is configuration time.

  3. 3

    Attack disruption and self-healing go on, with the team briefed first

    Everybody understands which containment actions can be applied automatically, who gets notified when one fires, and how that action is reviewed afterwards. The automation is valuable specifically because it acts without asking permission, which makes briefing people part of enabling it rather than an optional extra afterwards.

  4. 4

    Set up the response rhythm on the combined queue

    Three things get settled: who triages, within what timeframe, and what happens outside working hours. A single well-correlated incident queue is a large improvement and it does not operate itself, and the most common failure of good detection remains an incident nobody ever opened.

  5. 5

    Decide whether thirty days is enough

    The window is generous for hunting and short for investigating anything found late. Where your obligations or your realistic discovery timelines run past it, that is precisely the point at which Sentinel and longer retention become the next genuine conversation rather than an upsell somebody is pushing.

Straight answers

What organizations ask about Defender XDR.

Not the full benefit, and the reason is documented. Correlation covers the Microsoft security products you have licensed and provisioned access to. Hold endpoint alone and what you get is endpoint detection with endpoint correlation. The cross-domain story that makes this worth having, along with the published attack disruption examples, requires those other domains to actually be there.

It correlates high-confidence signals arriving from several workloads, then applies containment actions automatically to stop an attack in progress and limit lateral movement. The example published alongside it is concrete: a malicious file detected on an endpoint causes Defender for Office 365 to scan for and remove that file from every email message, after which the whole suite blocks it on sight.

The published list runs to eleven: Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, Defender Vulnerability Management, Defender for Cloud, Microsoft Entra ID Protection, Microsoft Data Loss Prevention, App Governance, Microsoft Purview Insider Risk Management and Microsoft Security Exposure Management. A number of those are commonly licensed and never once provisioned.

Thirty days, and no more. Query-based access covers thirty days of historic raw signals and alert data drawn from Defender for Endpoint, Defender for Office 365, Defender for Identity and Defender for Cloud Apps. That makes a good hunting window and a short investigation window, and the gap between those two is precisely what Sentinel and longer retention exist to fill.

AI-powered automatic actions and playbooks bring the affected assets back to a secure state, covering compromised devices, user identities and mailboxes alike, by drawing on the automatic remediation capabilities inside each suite product so that every impacted asset tied to an incident gets remediated wherever possible. For any team with no capacity for cleanup work, that accounts for a substantial share of the value.

Each individual product detects and responds inside its own domain and stops there. The XDR layer is what stitches them together: one combined incident queue instead of separate alerts, signal sharing so a detection in one workload strengthens every other, automated containment reaching across workloads, self-healing spanning different asset types, and hunting across all four data sets simultaneously. It augments those components rather than replacing any of them.

It depends on retention, on non-Microsoft sources, and on whether you need a full SIEM. Defender XDR gives you thirty days of raw signal across the Defender workloads. Sentinel adds long-term retention, ingestion from sources outside the Microsoft estate, and the wider security operations tooling. Many organizations run both, and increasingly do so in the same portal.

It acts without asking anybody, and that is entirely the intent. Containment gets applied automatically whenever high-confidence signals correlate across workloads. Preparing properly means three things: knowing which actions are possible, making sure a person is notified when one fires, and agreeing in advance how each action gets reviewed afterwards. Skip that briefing and your team experiences the first disruption as an outage rather than as a defense working correctly.

Licensing requirements have to be satisfied before the service can be enabled in the Defender portal at all. Past that, the practical prerequisite is coverage. The more of those eleven signal sources you have licensed and provisioned, the more raw material the correlation layer has to work with. We audit that before anything else, because it determines what enabling this will actually produce for you.

Arguably it is designed for exactly that situation. The combined incident queue exists to ensure the full attack scope, the impacted assets and the automated remediation actions arrive grouped and surfaced together, and that is precisely the problem facing a team of two or three. Add automatic disruption and self-healing on top and a meaningful share of the work happens whether or not anybody is available.

It can. Defender for Cloud appears among the eleven listed signal sources, covering workloads and posture across Azure, AWS and Google Cloud Platform, so a cloud resource compromise can surface in the same incident as the endpoint and identity activity surrounding it. Identity arrives as two separate sources rather than one: Defender for Identity handles on-premises Active Directory signals while Microsoft Entra ID Protection handles cloud identity risk. Most attacks worth worrying about cross between those two, which is why holding one without the other produces exactly the half-picture that makes an incident so difficult to scope.

Three to six weeks for most businesses. The coverage audit takes a few days and frequently produces the most valuable output of the whole engagement. Connecting sources that are licensed but unprovisioned is configuration work. Briefing your team on the automation takes about an hour. What takes longest is establishing a response rhythm somebody genuinely keeps to. Commercially, each engagement is scoped on how many signal sources need connecting and whether you want the incident queue worked on an ongoing basis. At no charge in the first conversation we will map which of the eleven sources your current licensing already covers, because in most estates several are paid for and sitting switched off.
Before relying on it

Fifteen questions worth answering first.

Group one is coverage, and coverage sets the ceiling on everything else. Group two governs what the automation is permitted to do on your behalf. Group three asks whether anybody acts, because a beautifully correlated incident that nobody opens remains an unopened incident.

Coverage

  • Which of the eleven products are licensed?
    Correlation only covers what you hold.
  • Which are licensed but not provisioned?
    A common and free gap to close.
  • Is email protection in place alongside endpoint?
    Attack disruption examples depend on both.
  • Is identity covered, on-premises and cloud?
    Two separate products cover the two halves.
  • Are cloud workloads feeding in?
    Defender for Cloud is on the list.

Automation

  • Is automatic attack disruption enabled?
    It applies containment without a human.
  • Is self-healing configured across the workloads?
    It uses each product's remediation capability.
  • Do you know what containment actions can be taken?
    Worth knowing before one fires.
  • Who is notified when disruption acts?
    Somebody should know it happened.
  • Is there a path to reverse an action?
    Decide before, not during.

Response

  • Who works the combined incident queue?
    And within what timeframe.
  • Is anybody hunting, or only responding?
    Thirty days of raw signal is available.
  • Do you need retention beyond thirty days?
    That is a Sentinel conversation.
  • Are incidents reaching a SIEM?
    Or is the portal the only place they exist.
  • Is out of hours covered?
    Attacks correlate at three in the morning too.
Related reading

The pages around this one.

Defender for Endpoint

The device workload, and normally the first of these signal sources any business acquires.

Learn more

Sentinel in the Defender portal

Where longer retention and non-Microsoft sources come in, and what the portal convergence means for your operation.

Learn more

Microsoft Defender

An overview of the product family, covering what each individual Defender workload does by itself.

Learn more
Next step

Work out how many of those eleven signal sources you already own.

Since correlation reaches only what is licensed and provisioned, that number is the ceiling on everything this can do for you. In most estates a few of them are already paid for and switched off, which makes closing that gap the cheapest improvement on the table.

Book an XDR coverage reviewSee the Microsoft security stack

Related Services

Explore more solutions that work great with this service

Microsoft Defender for Endpoint Services

EDR plan selection, onboarding and zero-gap AV migration

Learn more

Microsoft Defender for Identity Services

Identity threat detection for Active Directory and Entra

Learn more

Microsoft Defender for Office 365 Services

Anti-phishing, Safe Links and Safe Attachments done right

Learn more

Microsoft Sentinel Transition to the Defender Portal

Sentinel transition planning and delivery for US organizations ahead

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more

SOC-as-a-Service

24/7 security operations delivered as a service

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA