Skip to content

4. Microsoft Defender for Endpoint (MDE)

MDE (Microsoft Defender for Endpoint)

Ways of working

Defender for Endpoint is for Endpoints, Servers actually belong in "Defender for Cloud": https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/migrating-mde-server-to-cloud

Enable Telemetry

Validate and Test

Migration

Enable Reporting

Consider consolidating All reporting below into Workbooks in Sentinel, this can typically be provided by a Partner, part of an MSSP process, or you can roll your own?

Review and Improve as needed

Troubleshooting

M365 RBAC

Released late Dec 2022

MDE using ASR stand-alone (E3)

Handy tips and shortcuts for those that might still be trying to improve based on M365 E3 Licensing - apologies but this is not my focus, but when I do come across useful tips and links I'll add here: