is the product that watches what your laptops and servers are doing, notices when one of them starts behaving like a machine an attacker is using, and can cut it off from the network before the damage spreads. It is not the antivirus that came with Windows, although it works with it. It is the layer above: the one that catches the attack the antivirus let through.
That is the plain-English version. The rest of this page explains what it actually does day to day, which of the four products called Defender you have, what it does not do, and how it maps to the , without the vocabulary.
Four products share the name
| Name | What it is | Who has it |
|---|---|---|
| Microsoft Defender Antivirus | The antivirus built into Windows. Scans files against known bad and blocks them. | Every Windows machine. |
| Microsoft Defender for Endpoint | The enterprise product: behaviour monitoring, investigation, device isolation, attack surface rules and vulnerability findings across enrolled devices. Sold as Plan 1 and Plan 2, and included in Microsoft 365 E5. | Larger organisations and anyone who buys it separately. |
| Microsoft Defender for Business | The same engine packaged for organisations up to 300 users, included in Microsoft 365 Business Premium. | Most Australian small and medium businesses on Business Premium, whether they know it or not. |
| Microsoft Defender XDR | The console that joins the endpoint signals with email, identity and cloud app signals so one attack shows up as one story rather than four alerts. | Anyone with the products above and the licence to see them together. |
The distinction that matters for most readers is the second and third rows. If you pay for Business Premium, you already own Defender for Business. Whether it is switched on and whether your devices are enrolled in it is a separate question, and the honest answer in many of the tenants we see is no.
What it does, in five jobs
It watches behaviour, not just files
Antivirus asks whether a file matches something known to be bad. Defender for Endpoint also asks whether a process is doing something an attacker would do: a Word document launching PowerShell, a login at 3am from a machine that never works nights, a tool that is copying every file on the share. The attack that arrives as a brand-new piece of gets past the first question and caught by the second.
It can pull the plug on one machine
When Defender decides a device is compromised, it can isolate it: the machine keeps talking to Defender and to nothing else. The user's files stay where they are, the attacker's foothold stops being useful, and the incident goes from spreading to contained while a person works out what happened. Whether that happens automatically or after a human clicks depends on how it is configured.
It investigates and cleans up
For the common cases, Defender runs its own investigation: which process started it, what it touched, which other machines saw the same thing, and what needs to be quarantined or reversed. Automated investigation and remediation is the feature name. In practice it means a lot of the routine incidents resolve themselves and the alert arrives with the work already done.
It closes the doors attackers walk through
are a list of things that ordinary software should never need to do and attackers rely on: Office creating child processes, Office writing executable content, scripts launched from email, from the Windows security subsystem. Turning them on blocks whole categories of attack rather than individual samples. They are also, nearly word for word, several of the Essential Eight's user application hardening requirements.
It tells you what is unpatched
Every enrolled device reports its installed software and versions, so Defender keeps a running list of vulnerable applications and operating systems with the fix for each. That list is the input the Essential Eight's two patching controls expect you to have: you cannot patch within 48 hours something you did not know was installed.
What it does not do
It covers the devices you enrol. A laptop nobody enrolled, a contractor's own machine, a printer, a network switch: invisible. Enrolment is a project, not a setting.
It does not protect the login itself. An attacker who has a user's password and a way past their signs in normally, and normal sign-ins are not what an endpoint product watches. Identity protection is a separate layer, covered by and , and the two only make sense together.
It does not act on its own alerts, beyond what it is configured to automate. Somebody has to look at the console, decide what the alert means and do something within hours rather than weeks. Without that, the detection has happened and nothing has changed. This is the gap a managed security service fills, and it is the reason a licensed but unattended Defender is one of the most common findings in our reviews.
How it maps to the Essential Eight
| Essential Eight control | What Defender contributes |
|---|---|
| User application hardening | Attack surface reduction rules cover the Level 2 requirements that Microsoft Office is blocked from creating child processes, creating executable content and injecting code into other processes, and that PDF software is blocked from creating child processes. |
| Patch applications and patch operating systems | The vulnerability list is the asset discovery and vulnerability scanning the model requires at every level, for enrolled devices. |
| Central logging (required under four controls from Level 2) | Endpoint events are collected centrally. The model also requires those logs to be protected and analysed in a timely manner, which is the part a product cannot do for you. |
| Application control, macros, admin privileges, MFA, backups | Little or nothing directly. Defender can report on them, and its identity and email siblings cover more, but these controls are configured elsewhere. |
Every requirement in that table is in 's own words in our Essential Eight Maturity Level 2 checklist.
Frequently asked questions
Is Microsoft Defender for Endpoint an antivirus?
It includes one, Microsoft Defender Antivirus, and adds behaviour monitoring, investigation, device isolation, attack surface rules and findings on top. The antivirus is the part that blocks known bad files. The rest is what catches the attack the antivirus missed.
Is Defender for Endpoint included in Microsoft 365 Business Premium?
Business Premium includes Defender for Business, which is the same engine packaged for organisations up to 300 users. Defender for Endpoint Plan 1 and Plan 2 are the enterprise editions, sold separately or included in Microsoft 365 E5.
Do we still need a separate EDR product?
If Defender for Business is in a licence you already pay for, usually not. The money is better spent enrolling every device, turning the attack surface rules on and paying someone to watch the alerts. A separate product makes sense where a specific capability is needed that Defender lacks, or where the fleet is not Microsoft-centred.
Does Defender replace a security operations centre?
No. It produces the alerts a works from. Automated investigation handles the routine cases; the unusual ones, and the decision to isolate a server that runs the business, still need a person who is awake.
Is Defender for Endpoint Essential Eight compliant?
No product is compliant on its own; the is assessed against the organisation. Configured properly, Defender satisfies several user application hardening and patching requirements and provides the endpoint logging the model expects. The other controls, and the analysis of those logs, are separate work.
Where to start
If you are on Business Premium, the first step is finding out whether Defender is actually enrolled and configured, which takes an afternoon and usually changes the conversation about buying anything else. That check is part of our Microsoft 365 security review. If you want the alerts watched as well as generated, that is what Fortify is for.



