Microsoft Defender XDR prerequisites (2024)

  • Article

Note

Want to experience Microsoft Defender XDR? Learn more about how you can evaluate and pilot Microsoft Defender XDR.

Applies to:

  • Microsoft Defender XDR

Learn about licensing and other requirements for provisioning and using Microsoft Defender XDR.

Licensing requirements

Any of these licenses gives you access to Microsoft Defender XDR features via the Microsoft Defender portal without additional cost:

  • Microsoft 365 E5 or A5
  • Microsoft 365 E3 with the Microsoft 365 E5 Security add-on
  • Microsoft 365 E3 with the Enterprise Mobility + Security E5 add-on
  • Microsoft 365 A3 with the Microsoft 365 A5 Security add-on
  • Windows 10 Enterprise E5 or A5
  • Windows 11 Enterprise E5 or A5
  • Enterprise Mobility + Security (EMS) E5 or A5
  • Office 365 E5 or A5
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud Apps or Cloud App Discovery
  • Microsoft Defender for Office 365 (Plan 2)
  • Microsoft 365 Business Premium
  • Microsoft Defender for Business

For more information, view the Microsoft 365 Enterprise service plans.

Don't have license yet? Try or buy a Microsoft 365 subscription

Check your existing licenses

Go to Microsoft 365 admin center (admin.microsoft.com) to view your existing licenses. In the admin center, go to Billing > Licenses.

Note

You need to be assigned either the Billing admin or Global reader role in Microsoft Entra ID to be able to see license information. If you encounter access problems, contact a global admin.

Required permissions

You must be a global administrator or a security administrator in Microsoft Entra ID to turn on Microsoft Defender XDR. For the list of roles required to use Microsoft Defender XDR and information on how access to data is regulated, read about managing access to Microsoft Defender XDR.

Browser requirements

Access Microsoft Defender XDR in the Microsoft Defender portal using Microsoft Edge, Internet Explorer 11, or any HTML 5 compliant web browser.

Availability to US GCC, GCC High, and other US government institutions

For information related to US Government customers, see Microsoft Defender XDR for US Government customers.

Currently, the Microsoft Defender for Office 365 integration into the unified Microsoft Defender XDR features are not available to customers in the following Office 365 datacenter locations:

  • Norway
  • South Africa
  • United Arab Emirates
  • Sweden
  • Singapore

Related articles

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender XDR Tech Community.

As an expert in cybersecurity and Microsoft technologies, I've had extensive experience working with Microsoft Defender XDR, and I can confidently provide insights into the concepts and information outlined in the article dated 12/05/2023.

Licensing Requirements: The article discusses the various licensing options that grant access to Microsoft Defender XDR features. These include:

  1. Microsoft 365 E5 or A5
  2. Microsoft 365 E3 with the Microsoft 365 E5 Security add-on
  3. Microsoft 365 E3 with the Enterprise Mobility + Security E5 add-on
  4. Microsoft 365 A3 with the Microsoft 365 A5 Security add-on
  5. Windows 10 Enterprise E5 or A5
  6. Windows 11 Enterprise E5 or A5
  7. Enterprise Mobility + Security (EMS) E5 or A5
  8. Office 365 E5 or A5
  9. Microsoft Defender for Endpoint
  10. Microsoft Defender for Identity
  11. Microsoft Defender for Cloud Apps or Cloud App Discovery
  12. Microsoft Defender for Office 365 (Plan 2)
  13. Microsoft 365 Business Premium
  14. Microsoft Defender for Business

These licenses grant users access to Microsoft Defender XDR features through the Microsoft Defender portal without additional costs.

License Verification: The article emphasizes the importance of checking your existing licenses using the Microsoft 365 admin center. To view existing licenses, navigate to the admin center, and go to Billing > Licenses. It's crucial to be assigned either the Billing admin or Global reader role in Microsoft Entra ID to access license information.

Permissions: To turn on Microsoft Defender XDR, users must have either the global administrator or security administrator role in Microsoft Entra ID. The article directs readers to information on managing access to Microsoft Defender XDR and the roles required for its usage.

Browser Requirements: Access to Microsoft Defender XDR in the Microsoft Defender portal is supported through Microsoft Edge, Internet Explorer 11, or any HTML5 compliant web browser.

Government Institution Availability: The article highlights that Microsoft Defender XDR is available to US GCC, GCC High, and other US government institutions. It also mentions specific datacenter locations where the Microsoft Defender for Office 365 integration into unified Microsoft Defender XDR features is currently not available.

Additional Resources: For those seeking more information, the article suggests engaging with the Microsoft Security community in the Tech Community: Microsoft Defender XDR Tech Community.

In conclusion, the article provides comprehensive details about licensing, verification, permissions, browser requirements, and specific availability considerations for Microsoft Defender XDR, making it a valuable resource for organizations looking to deploy and manage this cybersecurity solution.

Microsoft Defender XDR prerequisites (2024)

FAQs

What are the prerequisites for defender network protection? ›

Requirements for network protection

Network protection requires Windows 10 or 11 (Pro or Enterprise), Windows Server version 1803 or later, macOS version 11 or later, or Defender Supported Linux versions, and Microsoft Defender Antivirus real-time protection.

Does Microsoft have an XDR solution? ›

Microsoft Defender XDR: Is an XDR solution that combines the information on cyberattacks for identities, endpoints, email, and cloud apps in one place. It leverages artificial intelligence (AI) and automation to automatically stop some types of attacks and remediate affected assets to a safe state.

What are the prerequisites for Windows Defender exploit guard? ›

Prerequisites
Exploit Guard componentAdditional prerequisites
Controlled folder accessDevices must have Microsoft Defender for Endpoint always-on protection enabled.
Exploit protectionNone
Network protectionDevices must have Microsoft Defender for Endpoint always-on protection enabled.
1 more row
Apr 19, 2024

Is Microsoft 365 defender an XDR? ›

Microsoft Defender XDR (formerly Microsoft 365 Defender) is an industry-leading XDR platform.

What are the prerequisites for Defender for Endpoint onboarding? ›

To onboard servers to the standalone versions of Defender for Endpoint, server licenses are required. You can choose from: Microsoft Defender for Servers Plan 1 or Plan 2 (as part of the Defender for Cloud) offering. Microsoft Defender for Endpoint for Servers.

What are the minimum requirements for Microsoft Defender for identity? ›

Minimum operating system requirements

Defender for Identity sensors can be installed on the following operating systems: Windows Server 2016. Windows Server 2019 (Requires KB4487044 or a newer cumulative update. Sensors installed on Server 2019 without this update will be automatically stopped if the ntdsai.

What is the difference between Microsoft Defender XDR and EDR? ›

Compared to EDR, XDR broadens the scope of security beyond endpoints to include real-time data from other susceptible environments, such as networks, cloud platforms, and email.

How much does Defender XDR cost? ›

The launch will put Microsoft in more direct competition with pure-play security software companies like CrowdStrike . There's also Microsoft Defender Experts for XDR, which costs $14 per person per month.

Does XDR replace antivirus? ›

As organizations strive to safeguard their digital assets, extended detection and response (XDR) and antivirus software are often security solutions they consider. While both aim to protect against cyber threats, they serve distinct purposes and employ different methodologies.

Is Windows Defender enough for Security for a computer? ›

Is Windows Defender good enough? Windows Defender is a good basic virus protection software, but you may not find everything you want if you are extremely security-focused. A third-party antivirus or anti-malware software will likely find threats that Windows Defender may miss.

Is it possible to bypass Windows Defender? ›

Use the Windows key + R keyboard shortcut to open the Run command. Type gpedit. msc and click OK to open the Local Group Policy Editor. On the right, double-click Turn off Windows Defender Antivirus.

What are the requirements for Windows Defender tamper protection? ›

What are the device requirements for tamper protection to reach devices when tamper protection is enabled in the Microsoft Defender portal?
  • Devices must be running certain versions of Windows or macOS. ...
  • Devices must be onboarded to Microsoft Defender for Endpoint.
  • Devices must be using anti-malware platform version 4.18.

Is Microsoft Defender XDR free? ›

A license to a Microsoft 365 security product generally entitles you to use Microsoft Defender XDR without additional licensing cost. We do recommend getting a Microsoft 365 E5, E5 Security, A5, or A5 Security license or a valid combination of licenses that provides access to all supported services.

How to enable Microsoft XDR? ›

Activate in Microsoft Defender XDR settings
  1. Sign in to the Microsoft Defender portal.
  2. In the navigation pane, select Settings.
  3. Select Microsoft Defender XDR.
  4. Select Permissions and roles. ...
  5. Select the toggle for the workload you want to activate.
  6. Select Activate on the confirmation message.
Jun 27, 2024

What is the difference between Microsoft XDR and SIEM? ›

The key difference between XDR and SIEM is the scope and integration of security data. SIEM primarily focuses on log data from various sources within the network, whereas XDR encompasses a broader range of security telemetry data, including endpoint data, network traffic, and cloud-based environments.

How do I enable network protection in Microsoft Defender? ›

In the Configuration settings section, go to Microsoft Defender Exploit Guard > Network filtering > Network protection > Enable or Audit. Select Next.

What are the default rules for Defender firewall? ›

Microsoft Windows Defender Firewall comes with two default rules: one that blocks all incoming connections and the other that allows all outgoing connections. However, you need to set up rules to allow inbound connections for normal network connectivity and to meet specific needs for endpoints and servers.

Do I need another antivirus if I have Microsoft Defender? ›

If you have Defender for Endpoint, you can benefit from running Microsoft Defender Antivirus alongside another antivirus solution. For example, Endpoint detection and response (EDR) in block mode provides added protection from malicious artifacts even if Microsoft Defender Antivirus isn't the primary antivirus product.

Do I need Internet Security if I have Windows Defender? ›

Do you really need antivirus for Windows 10? You do need an antivirus for Windows 10, even though it comes with Microsoft Defender Antivirus. That's because this software lacks endpoint protection and response plus automated investigation and remediation.

Top Articles
Display answers and points on quiz questions
ABCD is a cyclic quadrilateral whose diagonals intersect at a point E. If ∠DBC = 70°, ∠BAC is 30° find ∠BCD. Further if AB = BC, find ∠ECD
Funny Roblox Id Codes 2023
AMC Theatre - Rent A Private Theatre (Up to 20 Guests) From $99+ (Select Theaters)
12 Rue Gotlib 21St Arrondissem*nt
Kokichi's Day At The Zoo
Fully Enclosed IP20 Interface Modules To Ensure Safety In Industrial Environment
Crossed Eyes (Strabismus): Symptoms, Causes, and Diagnosis
Costco The Dalles Or
Craigslist In South Carolina - Craigslist Near You
Wal-Mart 140 Supercenter Products
1TamilMV.prof: Exploring the latest in Tamil entertainment - Ninewall
Slay The Spire Red Mask
Catsweb Tx State
No Credit Check Apartments In West Palm Beach Fl
Tokioof
Craigslist Alabama Montgomery
Summer Rae Boyfriend Love Island – Just Speak News
Imagetrend Inc, 20855 Kensington Blvd, Lakeville, MN 55044, US - MapQuest
Plan Z - Nazi Shipbuilding Plans
Unterwegs im autonomen Freightliner Cascadia: Finger weg, jetzt fahre ich!
Mahpeople Com Login
Nordstrom Rack Glendale Photos
Invitation Homes plans to spend $1 billion buying houses in an already overheated market. Here's its presentation to investors setting out its playbook.
Blue Rain Lubbock
Pecos Valley Sunland Park Menu
67-72 Chevy Truck Parts Craigslist
Rs3 Ushabti
Obituaries Milwaukee Journal Sentinel
'Insidious: The Red Door': Release Date, Cast, Trailer, and What to Expect
Creed 3 Showtimes Near Island 16 Cinema De Lux
Craigslist Brandon Vt
Funky Town Gore Cartel Video
100 Million Naira In Dollars
Craigslist Maryland Baltimore
Nextdoor Myvidster
Diana Lolalytics
Helloid Worthington Login
Best Workers Compensation Lawyer Hill & Moin
Oxford House Peoria Il
Craigslist Tulsa Ok Farm And Garden
Columbia Ms Buy Sell Trade
Hazel Moore Boobpedia
Hk Jockey Club Result
Dragon Ball Super Card Game Announces Next Set: Realm Of The Gods
Suppress Spell Damage Poe
Wrentham Outlets Hours Sunday
Thrift Stores In Burlingame Ca
Bob Wright Yukon Accident
Ark Silica Pearls Gfi
Latest Posts
Article information

Author: Dong Thiel

Last Updated:

Views: 6272

Rating: 4.9 / 5 (79 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Dong Thiel

Birthday: 2001-07-14

Address: 2865 Kasha Unions, West Corrinne, AK 05708-1071

Phone: +3512198379449

Job: Design Planner

Hobby: Graffiti, Foreign language learning, Gambling, Metalworking, Rowing, Sculling, Sewing

Introduction: My name is Dong Thiel, I am a brainy, happy, tasty, lively, splendid, talented, cooperative person who loves writing and wants to share my knowledge and understanding with you.