Complete Guide to Microsoft Defender XDR Using AI Detection by Microsoft Press

Complete Guide to Microsoft Defender XDR Using AI Detection by Microsoft Press

5h 28mIntermediate2026-08-05

Authors

Microsoft Press

Microsoft Press

Microsoft

Course details

In this course, get a complete, practical walkthrough of Microsoft Defender XDR, focusing on how AI-powered threat detection is reshaping modern security operations. See how Defender XDR correlates signals across endpoints, identities, email, and cloud apps. Security, cloud, and system admins can utilize machine learning and automated analysis to uncover threats that traditional tools miss. As organizations face increasingly sophisticated attacks, understanding how to harness AI driven detection isn’t just helpful, it’s essential for staying ahead of adversaries. Find out how to navigate the Defender XDR portal, and automate investigations using AI driven Defender XDR.

Learning objectives
Describe the core architecture and capabilities of Microsoft Defender XDR, including how it unifies signals across endpoints, identities, email, and cloud applications.
Explain how AI powered detection works within Defender XDR and how to interpret machine generated incidents, alerts, and correlation insights.
Investigate threats end to end using the XDR portal, including alert triage, evidence analysis, and incident timelines.
Perform automated investigations, review response actions, and use orchestration features that streamline SOC operations.
Configure and operationalize Defender XDR in real world environments, including policy tuning, integration with Microsoft 365, and best practice security settings.
Apply Defender XDR workflows to common attack scenarios and modern threat patterns.

Concepts

Introduction

  • Complete guide to Microsoft Defender XDR using AI detection - Introduction

Introduction to Microsoft Defender XDR

  • Learning objectives
  • What Defender XDR is and why it matters
  • The evolution of threat detection and AI s role
  • Understanding the unified security operations platform
  • How Defender XDR utilizes endpoint detection and response

Core Architecture and Components

  • Learning objectives
  • How Defender XDR correlates signals across the Microsoft ecosystem
  • Endpoints, identities, email, and cloud app integration
  • Data flow, telemetry, and incident correlation
  • Examine how Defender XDR differs from security and event management using Microsoft Sentinel

Navigating the Microsoft Defender XDR Portal

  • Learning objectives
  • Dashboard overview
  • Alerts, incidents, and evidence panels
  • Work with the incident queue like a security operations center (SOC) analyst

Implementing Microsoft Defender XDR

  • Learning objectives
  • Deploy Microsoft Defender for Identity to protect Active Directory and cloud identities
  • Set up Microsoft Defender for Office 365 to protect against phishing and malware
  • Onboard Microsoft Defender for Endpoint to protect client devices
  • Set up protections for cloud applications from online threats
  • Use Microsoft Defender for Cloud to protect Windows servers
  • Use Microsoft Defender for Endpoint to protect Linux servers

AI Powered Detection and Analysis

  • Learning objectives
  • How AI and machine learning enhance threat detection
  • Understanding AI generated incidents and correlation rules
  • Practical examples of AI driven threat insights
  • Introduction to the SOC pipeline
  • SOC components, including collection, transformation, routing, and enrichment

Investigating Threats End to End

  • Learning objectives
  • Alert triage and prioritization
  • Deep dive incident investigation
  • Using timelines, entities, and evidence graphs

Automated Investigation and Response

  • Learning objectives
  • How automated investigations work
  • Running and reviewing automated actions
  • Reducing SOC workload through smart automation

Operationalizing Microsoft Defender XDR

  • Learning objectives
  • Policy configuration and best practices
  • Integrating with Microsoft 365 and Microsoft Entra ID
  • Tuning detection rules and reducing noise

Real World Attack Scenarios

  • Learning objectives
  • Common attack patterns and how Microsoft Defender XDR detects them
  • Hands on walk-throughs of network attacks
  • Using AI insights to accelerate response

Building a Modern SOC with Microsoft Defender XDR

  • Learning objectives
  • SOC workflows and role alignment
  • Reporting, metrics, and continuous improvement
  • Simulated incident investigation

Final Project and Next Steps

  • Learning objectives
  • Preparing for Microsoft security certifications
  • Operational readiness checklist
  • Career paths and skill development road map

Conclusion

  • Complete guide to Microsoft Defender XDR using AI detection - Summary
100,000 Toman