It correlates signals only from the products you have licensed. Half a suite produces half a picture.
Defender XDR is the layer that joins endpoint, identity, email and cloud application signals into one incident, disrupts attacks automatically, and self-heals what it can. Microsoft states plainly that it correlates signals from the products you have licensed and provisioned, which is why the value depends on coverage rather than configuration.

- Eleven productsFeed the correlation layer
- One incidentInstead of alerts in separate consoles
- Auto disruptionContainment applied without a human
- 30 daysRaw signal available for hunting
How many of the eleven signal sources do you actually have?
Microsoft states Defender correlates signals from the products you have licensed and provisioned access to. That makes coverage, not configuration, the variable that decides what XDR is worth to you.
- The four most people think of are Defender for Endpoint, Defender for Office 365, Defender for Identity and Defender for Cloud Apps. Most UAE organisations we assess hold one or two of these and correlate accordingly, which produces a fraction of the cross-domain picture.
- The published list also includes Defender Vulnerability Management, Defender for Cloud, Microsoft Entra ID Protection, Data Loss Prevention, App Governance, Purview Insider Risk Management and Microsoft Security Exposure Management. Several of these are frequently already licensed through an enterprise subscription and simply never enabled.
- The practical consequence is that the first useful exercise is not configuring XDR, it is establishing which of the eleven you already hold, which are provisioned, and which are licensed but switched off. That list is usually longer than the security team expects.
- Attack disruption depends on this too. The published example, where a malicious file found on an endpoint is removed from every mailbox, requires both endpoint and email protection to be present. With one of the two, that behaviour simply does not occur.
Eight things Defender XDR does that the individual products do not.
The licensing caveat, which decides what you actually get
Microsoft states directly that Defender correlates signals from Microsoft security products you have licensed and provisioned access to. That single sentence is the most important thing on this page. An organisation with endpoint protection alone gets endpoint correlation. The cross-domain story that makes XDR worth having requires the domains to be covered, and most estates cover two or three of the eleven.
One incident, not alerts in four consoles
The combined incidents queue exists, in Microsoft words, to help security professionals focus on what is critical by ensuring the full attack scope, impacted assets and automated remediation actions are grouped together and surfaced in a timely manner. For a small team, the difference between one incident with a timeline and four unrelated alerts is the difference between responding and triaging.
Automatic attack disruption, with a concrete example
Microsoft describes correlating high-confidence signals from multiple workloads and automatically applying containment actions to stop in-progress attacks and limit lateral movement. The published example is precise: a malicious file detected on an endpoint causes Defender for Office 365 to scan and remove that file from all email messages, and it is then blocked on sight by the entire suite.
Self-healing across devices, identities and mailboxes
Microsoft describes using AI-powered automatic actions and playbooks to remediate impacted assets back to a secure state, leveraging the automatic remediation capabilities of the suite products so that all impacted assets related to an incident are remediated where possible. For teams without capacity for manual cleanup, this is where a meaningful share of the value sits.
Cross-product hunting, with a thirty day window
Microsoft states that Defender XDR provides query-based access to thirty days of historic raw signals and alert data from Defender for Endpoint, Defender for Office 365, Defender for Identity and Defender for Cloud Apps. Thirty days is generous for hunting and short for an investigation into something discovered late, which is precisely why Sentinel and longer retention exist alongside it.
Eleven contributing products, not four
Beyond the four Defender workloads people expect, the published list includes Defender Vulnerability Management, Defender for Cloud, Microsoft Entra ID Protection, Data Loss Prevention, App Governance, Purview Insider Risk Management and Microsoft Security Exposure Management. Several of those are capabilities organisations already hold and have never connected into the picture.
The narrative, which is what a report actually needs
Microsoft describes the layer as narrating the full story of the attack across product alerts, behaviours and context, by joining data on alerts, suspicious events and impacted assets into incidents. When somebody has to explain to a board or a regulator how an attack entered, what it reached and what was done, that narrative is the deliverable rather than a list of alerts.
Signal sharing that makes each product better
The cross-product layer helps protect against attacks and coordinate defensive responses through signal sharing and automated actions, so a detection in one workload strengthens the others rather than staying local to it. That compounding is the genuine argument for staying within one family, and it is also why partial coverage underdelivers relative to the marketing.
Four things that determine whether XDR delivers what it promises.
We map coverage against the eleven sources first
Because Microsoft states correlation only covers products you have licensed and provisioned access to. We establish which of the eleven you hold, which are provisioned, and which are licensed but never switched on. In most estates the third category is the surprise, and closing it costs nothing but configuration time.
We enable attack disruption deliberately, with the team briefed
It applies containment actions automatically to stop in-progress attacks and limit lateral movement, which is exactly what you want and also means the platform will act without asking. Knowing what it can do, who is told when it fires, and how an action is reviewed afterwards is a short conversation that prevents a long one.
We treat the thirty day window as a design input
Thirty days of raw signal is ample for hunting and short for an investigation into something discovered months later, which is the common case for a breach. Where your retention obligations or realistic discovery timelines exceed that, the answer is Sentinel and longer retention rather than hoping the window is enough.
We make sure somebody actually works the queue
A combined incident queue is a considerable improvement on four separate consoles and it still requires a person. We establish who triages, in what timeframe, and what happens outside working hours, because the single most common failure of a good detection platform is that nobody opened the incident it produced.
Six UAE situations where the correlation layer changes the outcome.
A phishing email that became an endpoint compromise
The most common shape of a real incident, and the one that separate consoles handle worst. With email and endpoint both feeding the correlation layer, that becomes a single incident with a timeline from the message to the device. With one of the two, it becomes two alerts that somebody has to connect by hand, if they notice at all.
A small team drowning in alerts
Two or three people covering endpoint, identity, email and cloud. The combined incident queue exists specifically to group full attack scope, impacted assets and automated remediation actions together, which is the difference between a team that responds to incidents and a team that spends its day deciding which alerts are related.
A regulated firm that has to narrate an incident
Where a regulator, an insurer or a board asks how an attack entered, what it reached and what was done about it. Microsoft describes the layer as narrating the full story across alerts, behaviours and context. That narrative is the artefact the question actually requires, and reconstructing it manually from separate products takes days.
An organisation with no out of hours coverage
Automatic attack disruption applies containment actions without waiting for a human, and self-healing remediates impacted devices, identities and mailboxes where possible. For an organisation whose security capacity is office hours, that automation is doing the work nobody is awake to do, which is a meaningful argument on its own.
An organisation on E5 using a fraction of it
The most common finding we make. Several of the eleven signal sources are already licensed and never provisioned, and each one connected widens the correlation for no additional spend. Establishing that list is a short exercise with an unusually good return relative to the effort.
A team that wants to hunt rather than only respond
Thirty days of query-based access to raw signals and alert data across endpoint, email, identity and cloud applications is a genuinely useful hunting surface. For teams ready to go looking rather than waiting to be told, this is where that starts, and it does not require Sentinel to begin.
How much of the attack story UAE organisations can actually see.
| Feature | Broad coverage | Two or three workloads | Endpoint only |
|---|---|---|---|
Endpoint detections | Yes | Yes | Yes |
Email entry point visible | Yes | Sometimes | No |
Identity movement visible | Yes | Rarely | No |
SaaS and cloud application activity visible | Yes | Rarely | No |
One incident with a full timeline | Yes | Partial | No |
Attack disruption across workloads | Yes | Limited | No |
Self-healing across devices, identities and mailboxes | Yes | Partial | Devices only |
Cross-product hunting available | Yes | Limited | No |
Attack narrative available for a report | Yes | Partial | No |
Frequency in the UAE market | Uncommon | Common | Common in SMEs |
Eleven products, and what each contributes to the picture.
| Product | What it contributes | |
|---|---|---|
| Defender for Endpoint | Device detections, and the endpoint half of almost every attack story | |
| Defender for Office 365 | Email and collaboration, usually the entry point | |
| Defender for Identity | On-premises and hybrid identity, reconnaissance and lateral movement | |
| Defender for Cloud Apps | SaaS activity, OAuth applications and data in third-party services | |
| Defender Vulnerability Management | What was exposed, and whether it was being exploited | |
| Defender for Cloud | Azure, AWS and GCP workload and posture signals | |
| Microsoft Entra ID Protection | Cloud identity risk, risky sign-ins and risky users | |
| Data Loss Prevention | Whether sensitive content moved during the incident | |
| App Governance | OAuth applications with standing permissions to your data | |
| Purview Insider Risk Management | Behavioural risk signals, where the actor may be internal | |
| Security Exposure Management | Attack paths and exposure context around the affected assets |
Five steps, and the first is an audit rather than a deployment.
- 1
Map coverage against the eleven signal sources
Which are licensed, which are provisioned, and which are licensed but switched off. Microsoft is explicit that correlation covers only what you hold and have provisioned, so this list defines the ceiling on everything that follows and it usually contains free wins.
- 2
Connect what is already paid for
Starting with the workloads that widen the picture most: email alongside endpoint, then identity, then cloud applications. Each addition improves correlation for every incident afterwards, and where the licence already exists the only cost is the configuration.
- 3
Enable attack disruption and self-healing with the team briefed
Understanding what containment actions can be applied automatically, who is notified when they fire, and how an action is reviewed afterwards. The automation is valuable precisely because it acts without asking, which makes the briefing part of enabling it rather than an optional extra.
- 4
Set up the response rhythm on the combined queue
Who triages, within what timeframe, and what happens out of hours. A single well-correlated incident queue is a large improvement and it is not self-operating, and the most common failure of good detection is an incident nobody opened.
- 5
Decide whether thirty days is enough
It is generous for hunting and short for an investigation into something found late. Where obligations or realistic discovery timelines exceed it, that is the point at which Sentinel and longer retention become the next conversation rather than an upsell.
What organisations ask about Defender XDR.
Fifteen questions worth answering first.
Coverage
- Which of the eleven products are licensed?Correlation only covers what you hold.
- Which are licensed but not provisioned?A common and free gap to close.
- Is email protection in place alongside endpoint?Attack disruption examples depend on both.
- Is identity covered, on-premises and cloud?Two separate products cover the two halves.
- Are cloud workloads feeding in?Defender for Cloud is on the list.
Automation
- Is automatic attack disruption enabled?It applies containment without a human.
- Is self-healing configured across the workloads?It uses each product remediation capability.
- Do you know what containment actions can be taken?Worth knowing before one fires.
- Who is notified when disruption acts?Somebody should know it happened.
- Is there a path to reverse an action?Decide before, not during.
Response
- Who works the combined incident queue?And within what timeframe.
- Is anybody hunting, or only responding?Thirty days of raw signal is available.
- Do you need retention beyond thirty days?That is a Sentinel conversation.
- Are incidents reaching a SIEM?Or is the portal the only place they exist.
- Is out of hours covered?Attacks correlate at three in the morning too.
The pages around this one.
Defender for Endpoint
The device workload, and usually the first of the signal sources an organisation holds.
Sentinel in the Defender portal
Where longer retention and non-Microsoft sources come in, and the 2027 deadline that applies regardless.
Microsoft Defender
The product family overview, covering what each individual Defender workload does on its own.
Count how many of the eleven signal sources you already own.
Correlation covers only what is licensed and provisioned, so that number is the ceiling on everything XDR can do for you. In most estates several are already paid for and switched off, which makes this the cheapest improvement available.
Related Services
Explore more solutions that work great with this service
KQL Threat Hunting
Hunting across Defender data, and turning it into detections
Defender for Endpoint
Business, Plan 1 or Plan 2, and what each actually gives you
Sentinel to the Defender Portal
Azure portal support for Sentinel ends 31 March 2027
Microsoft Defender
Advanced endpoint and email threat protection
Defender for Identity
Lateral movement and domain dominance, detected across AD and Entra
Defender for Office 365
Plan 1 versus Plan 2, and the ten second way to tell which you have
Defender for Cloud Apps
Shadow IT, SaaS posture and the OAuth apps already reading your mail
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own