Differences between Microsoft Defender XDR and Sentinel

mara7 161 Reputation points
2023-12-12T06:56:53.72+00:00
  1. I wonder differences between Microsoft Defender XDR and Sentinel
  • I understand that Microsoft Defender XDR consolidates security alerts (including Cloud Defender, Identity Defender, Endpoint Defender, etc.).
  • While Sentinel can use various connectors for security analysis and correlations, does XDR just connect Defenders? or does they also can analysis correlation?

Is it accurate to say that XDR cannot perform correlation analysis and only provides a dashboard for a quick overview of security alerts?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,040 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
{count} votes

Accepted answer
  1. Clive Watson 5,951 Reputation points MVP
    2023-12-12T09:11:43.31+00:00

    Hello, The new unified portal, Microsoft Defender XDR when enabled, does show a consolidated view of all Alerts from any Defnder product + Microsoft Sentinel.

    You can then use Advanced Hunting to correlate / join the data from Microsoft Defender based sources with Microsoft Sentinel for example.


0 additional answers

Sort by: Most helpful