<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Microsoft-Defender-Xdr-(Microsoft-365-Defender) on Ru Campbell MVP</title>
    <link>https://campbell.scot/tags/microsoft-defender-xdr-microsoft-365-defender/</link>
    <description>Recent content in Microsoft-Defender-Xdr-(Microsoft-365-Defender) on Ru Campbell MVP</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Fri, 16 Feb 2024 17:13:38 +0000</lastBuildDate>
    <atom:link href="https://campbell.scot/tags/microsoft-defender-xdr-microsoft-365-defender/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>[Updated Feb 2024] Ultimate Comparison of Defender for Endpoint Features by OS</title>
      <link>https://campbell.scot/feb-2024-ultimate-comparison-of-defender-for-endpoint-features-by-os/</link>
      <pubDate>Fri, 16 Feb 2024 17:13:38 +0000</pubDate>
      <guid>https://campbell.scot/feb-2024-ultimate-comparison-of-defender-for-endpoint-features-by-os/</guid>
      <description>&lt;p&gt;Finally, it&amp;rsquo;s time for a refresh.  It&amp;rsquo;s been a while!  Due to personal circumstances, I haven&amp;rsquo;t been able to keep the Ultimate Comparison of MDE by OS updated.  I&amp;rsquo;ve had time to dive into the changes since v5 and it&amp;rsquo;s really been amazing to see MDE grow in scope.&lt;/p&gt;
&lt;h2 id=&#34;what-is-mde-and-why-do-we-need-an-ultimate-comparison&#34;&gt;What is MDE and why do we need an &amp;lsquo;ultimate comparison&amp;rsquo;?&lt;/h2&gt;
&lt;p&gt;Microsoft Defender for Endpoint (MDE) is a massive stack of endpoint protection and endpoint detection and response (EDR) capabilities.  It integrates with the broader Microsoft Defender XDR and is available for almost any OS you&amp;rsquo;ll find in an enterprise.  This cross-platform nature of MDE makes it difficult to understand and track what features and capabilities are available on each OS.  It&amp;rsquo;s not always intuitive, and you may be in for some surprises.  Hence by I began the &lt;strong&gt;Ultimate Comparison of Defender for Endpoint Features by OS&lt;/strong&gt; up to date to keep you aware of what you&amp;rsquo;re getting and what you need to go start implementing if you haven&amp;rsquo;t already.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exchange Online Protection &amp; Defender for Office 365 - Common Microsoft 365 Security Mistakes Series</title>
      <link>https://campbell.scot/exchange-online-protection-defender-for-office-365-common-microsoft-365-security-mistakes-series/</link>
      <pubDate>Tue, 19 Dec 2023 08:26:45 +0000</pubDate>
      <guid>https://campbell.scot/exchange-online-protection-defender-for-office-365-common-microsoft-365-security-mistakes-series/</guid>
      <description>&lt;p&gt;Exchange Online Protection (EOP) and Microsoft Defender for Office 365 (MDO) are the email and collaboration security services native to Microsoft 365. EOP is included at all levels of licensing for Exchange Online, with MDO bringing additional security capabilities to license levels such as Business Premium, Microsoft 365 E3, and Microsoft 365 E5.&lt;/p&gt;
&lt;p&gt;In this blog, I&amp;rsquo;ll review five of the most common security mistakes I see in tenants regarding EOP and MDO. Realistically, this list could go to fifty mistakes, but I&amp;rsquo;ll focus on ones I think you can quickly convert into quick wins or just may have never crossed your mind.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Improves and Simplifies Defender for Endpoint Management Capabilities</title>
      <link>https://campbell.scot/microsoft-improves-and-simplifies-defender-for-endpoint-management-capabilities/</link>
      <pubDate>Mon, 10 Jul 2023 20:47:03 +0000</pubDate>
      <guid>https://campbell.scot/microsoft-improves-and-simplifies-defender-for-endpoint-management-capabilities/</guid>
      <description>&lt;p&gt;In one of the biggest changes to Microsoft Defender for Endpoint (MDE) in its product history, you no longer need a separate management engine to configure endpoint settings.&lt;/p&gt;
&lt;p&gt;In this blog, we&amp;rsquo;ll look at what that change is, why it was necessary, initial impressions, and what you might want to do next.&lt;/p&gt;
&lt;h2 id=&#34;historic-management-architecture-needed-simplifying&#34;&gt;Historic management architecture needed simplifying&lt;/h2&gt;
&lt;p&gt;MDE (and it&amp;rsquo;s Windows client, Microsoft Defender Antivirus (MDAV)) always stood out from the crowd of endpoint protection platforms as being, well, a bit &lt;em&gt;weird&lt;/em&gt; in terms of management architecture. With most platforms, you get a central admin console which pushes out endpoint settings. Think scan schedules, quarantine rules, exclusions, CPU throttling, etc. MDE/MDAV, on the other hand, instead relied on an external management tool such as Intune (MDM), Configuration Manager, or Group Policy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>[Feb 2023] Ultimate Comparison of Defender for Endpoint Features by OS</title>
      <link>https://campbell.scot/mde-comparison-feb-2023/</link>
      <pubDate>Sun, 19 Feb 2023 15:46:12 +0000</pubDate>
      <guid>https://campbell.scot/mde-comparison-feb-2023/</guid>
      <description>&lt;p&gt;Microsoft Defender for Endpoint (MDE) is a massive stack of endpoint protection and endpoint detection and response (EDR) capabilities.  It integrates with Microsoft 365 Defender (the broader XDR platform) and is available for almost any OS you&amp;rsquo;ll find in an enterprise.  This cross-platform nature of MDE makes it difficult to understand and track what features and capabilities are available on each OS.  It&amp;rsquo;s not always intuitive, and you may be in for some surprises.  I try to keep this &lt;strong&gt;Ultimate Comparison of Defender for Endpoint Features by OS&lt;/strong&gt; up to date to keep you aware of what you&amp;rsquo;re getting and what you need to go start implementing if you haven&amp;rsquo;t already.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ultimate Comparison of Defender for Endpoint Features by OS [Updated August 2022]</title>
      <link>https://campbell.scot/mde-comparison-august-2022/</link>
      <pubDate>Fri, 26 Aug 2022 07:32:32 +0000</pubDate>
      <guid>https://campbell.scot/mde-comparison-august-2022/</guid>
      <description>&lt;p&gt;This is the updated &amp;ldquo;matrix&amp;rdquo; of OS supported for the almost 80 features, services, and important components that make up Microsoft Defender for Endpoint. This follows up on my March 2022 release of the comparison.&lt;/p&gt;
&lt;p&gt;What&amp;rsquo;s new?&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Now available in Excel format, which was the biggest request :)&lt;/li&gt;
&lt;li&gt;Added the new Microsoft Defender Vulnerability Management capabilities (add-on license required)&lt;/li&gt;
&lt;li&gt;Added macOS tamper protection support&lt;/li&gt;
&lt;li&gt;Added macOS network and web protection&lt;/li&gt;
&lt;li&gt;Added iOS and Android&amp;rsquo;s mobile network protection&lt;/li&gt;
&lt;li&gt;Added Linux cloud-delivered protection support&lt;/li&gt;
&lt;li&gt;Added Windows troubleshooting mode&lt;/li&gt;
&lt;li&gt;Added macOS, iOS, and Android support for network indicators of compromise&lt;/li&gt;
&lt;li&gt;Updated host firewall reporting supported OSs&lt;/li&gt;
&lt;li&gt;Updated attack surface reduction (ASR) rule supported Windows and Windows Server versions&lt;/li&gt;
&lt;li&gt;Updated block at first sight (BAFS) supported OSs (thanks Polle Vanhoof + Thomas Verheyden)&lt;/li&gt;
&lt;li&gt;Updated Windows Server support for indicators of compromise (thanks Polle Vanhoof + Thomas Verheyden)&lt;/li&gt;
&lt;li&gt;Removed preview references for the unified agent for Windows Server 2012 R2 and 2016&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Obligatory disclaimers:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Updated March 2022: Ultimate Comparison of Defender for Endpoint Features by Operating System</title>
      <link>https://campbell.scot/march-22-defender-for-endpoint-feature-comparison/</link>
      <pubDate>Tue, 29 Mar 2022 07:27:18 +0000</pubDate>
      <guid>https://campbell.scot/march-22-defender-for-endpoint-feature-comparison/</guid>
      <description>&lt;p&gt;It&amp;rsquo;s been about 5 months since I last updated my comparison of Defender for Endpoint features by OS.  This is a &amp;ldquo;matrix&amp;rdquo; of the &lt;em&gt;tons&lt;/em&gt; of features, services, and important components that make up Microsoft Defender for Endpoint.&lt;/p&gt;
&lt;p&gt;Three months later, it&amp;rsquo;s overdue an update.  So here it is :)  I&amp;rsquo;ve also decided to rename it to The Ultimate Comparison of MDE Features by OS&amp;hellip; because renaming&amp;rsquo;s what we do, right?&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
