In its latest Digital Defense Report, Microsoft’s telemetry data reveals a staggering surge in ransomware attacks which have increased by over 200% since September 2022. Notably, 40% of ransomware encounters are now attributed to human-driven assaults, often orchestrated by ransomware-as-a-service affiliates, whose numbers have grown by 12% in the past year. A significant shift in attack tactics has been observed, with a sharp rise in remote encryption during human-operated ransomware incidents, emphasizing attackers’ efforts to minimize their digital footprints.
To counter these hacking techniques, which are growing in variety and complexity, Microsoft made significant investments in its extended detection and response (XDR) solution, Microsoft Defender XDR (formerly known as Microsoft Advanced Threat Protection). Defender XDR has evolved a lot from its beginnings and is now a centralized platform for many security products that Microsoft provides, including:
As the platform expands, its licensing schemes become increasingly complicated. To help make sense of Microsoft’s licensing models, in this article, we walk you through Defender XDR and its components, emphasizing the differences among them and how their additional security features can enhance your company’s overall security.
Component/concept | Description |
---|---|
Microsoft Defender for Endpoint (MDE) |
MDE enhances endpoint protection against threats and enables security teams to perform incident response centrally. |
Microsoft Defender for Identity (MDI) | MDI enables monitoring and protection of the Active Directory environment. |
Microsoft Defender for Cloud Apps (MDCA) | MDCA helps detect Shadow IT as well as protect and monitor all cloud traffic. |
Microsoft Defender for Office 365 (MDO) | MDO protects and monitors Exchange Online traffic and user interaction with suspicious emails. |
Complementary solutions for enhancing security | While Microsoft Defender provides a solid solution, most of its products can be enhanced with other solutions on the market. |
Microsoft Defender XDR is Microsoft’s attempt to create a unified platform for the security of an organization that allows control over everything from a single place. By integrating several Defender products, such as MDE, MDO, MDI, and MDCA, Microsoft Defender XDR provides a single portal that gathers, filters, analyzes, and reacts to threats all across the organization’s digital estate.
Microsoft Defender XDR functionality (source)
In the sections below, we look at what these products provide and how they are licensed.
MDE is a product that helps detect, prevent, and respond to advanced threats on endpoint devices in Windows, Linux, or MacOS. Split into two different plans, it offers different security features to ensure that devices are protected from any threat within the network or from outside.
The figure below provides an overview of MDE Plan 1.
Microsoft Defender for Endpoint Plan 1 capabilities highlighted in green (source)
Notable functionality:
Licensing model: MDE Plan 1 is available in the following subscription bundles:
MDE Plan 2 is an enhanced alternative to MDE Plan 1 that provides additional security functions. Its AI-driven capabilities, together with the cloud infrastructure that analyzes trillions of security signals monthly, create a shield around your endpoints.
Defender for Endpoint Plan 2 capabilities (source)
Upgrades from Plan 1:
Licensing model: Defender for Endpoint can be found in several subscriptions, such as:
Formerly known as Azure Advanced Threat Protection, MDI is the Microsoft solution for monitoring and reacting to threats within your Active Directory environment. By analyzing the traffic, you can detect and respond to various attack scenarios, like Kerberoasting, pass-the-hash attacks, lateral movements, and password sprays. It also creates a baseline of normal user behaviors to then spot anomalies in users’ activities and alert security teams.
Microsoft Defender for Identity Architecture (source)
Notable functionality:
Licensing model: Microsoft Defender for Identity is available via:
MDCA is a rather unique security product with plays several roles in your cloud security, such as discovering shadow IT, protecting information in M365 cloud apps (Sharepoint, Teams, etc.), blocking or allowing other cloud providers, and analyzing how users interact with these cloud apps.
Microsoft Defender for Cloud Apps capabilities (source)
Notable functionality:
Licensing model: MDCA is only available through:
MDO safeguards your organization’s email through preset email security policies, email logs, email quarantine, real-time reports, and phishing simulation functionality. It also includes incident response capabilities, such as blocking email senders or malicious URLs. The features of Microsoft Defender for Office (MDO) vary by subscription level, with distinct offerings in Plan 1 and Plan 2. Let's delve into the specifics of what each plan includes.
Microsoft Defender for Office 365 capabilities (source)
Upgrading from Exchange Online Protection to MDO Plan 1 elevates your security from a prevention-focused approach to a detection-focused approach. This means that we start looking into possible threat actors that might come with links or zero-day attacks.
Notable functionality:
Licensing model: MDO Plan 1 is only available as a standalone license. Microsoft 365 E3 does not contain this license.
Prerequisite: Exchange Online Protection license (contained in Exchange Online Plan 1 and Plan 2).
MDO Plan 2 builds upon Plan 1 to bring you investigation and response capabilities on top of what you have enabled using EOP and MDO. By enabling automated investigation and response (AIR) and Threat Explorer, you get a comprehensive view of the threats your organization faces.
Differences from Plan 1:
Licensing model: You can find this license in the following bundles:
If your current subscription choices don’t meet all your needs and you're looking to extend protection to email traffic without incurring high costs for additional features, consider leveraging a comprehensive solution like IRONSCALES. This platform enhances cybersecurity awareness among your employees through targeted security awareness training campaigns, phishing simulations, and in-depth reporting, all customized to your organization's specific requirements.
Recommended training campaigns in the Ironscales portal (source)
Together with its Crowdsourced Threat Intelligence capabilities that connect you with a network of over 20,000 security experts, you can ensure that your organization is protected from advanced and never-seen-before email threats.
Microsoft Defender XDR is a unified platform for securing an organization’s digital estate. It includes several Defender products, each with its own licensing model and security functionalities. By controlling everything from a single platform, organizations can ensure the safety of their digital assets.
To bring email security to the next level, companies can also benefit from additional security solutions such as IRONSCALES, an AI-powered anti-phishing and email security solution that integrates effortlessly with M365.