Domain 2 of 4 · Chapter 1 of 3

Configure Protections in Microsoft Defender

Unlock the complete study guide + 1,040 practice questions across 16 full exams.

Bundled into the existing Microsoft Certified: Security Operations Analyst Associate premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • Pick the workload that owns the asset
  • Defender for Office 365: Safe Attachments, Safe Links, presets
  • Defender for Endpoint: ASR rules and modes
  • Defender for Cloud: CSPM baseline vs paid plans
  • Defender for Cloud Apps: access, session, OAuth
  • Exam pattern recognition

Which Defender protection for which asset

Defender workloadAsset it protectsPrimary protection controlsFree baseline vs paid
Defender for Office 365Email and collaboration (Exchange, Teams, SharePoint, OneDrive)Safe Attachments, Safe Links, anti-phishing, preset security policiesAdds to free EOP baseline; Plan 1/Plan 2 are paid
Defender for Cloud AppsSaaS apps and OAuth app consentAccess policies, session policies (Conditional Access App Control), file/activity policies, App GovernanceLicensed add-on; no free protection tier
Defender for EndpointDevices (Windows, macOS, Linux, mobile)Next-gen antivirus, ASR rules, controlled folder access, network protectionPlan 1/Plan 2 paid; ASR rules need Defender AV active
Defender for CloudCloud workloads (VMs, storage, SQL, containers) across Azure, AWS, GCPPer-resource Defender plans for runtime threat protectionFree CSPM (recommendations) baseline; Defender plans are paid (alerts)

Decision tree

Email or Teams message?phishing, malware attachmentDefender for Office 365Safe Links, Safe AttachmentsYesSaaS app or OAuth app?in-session control, consentNoDefender for Cloud Appssession / access policy, App GovernanceYesEndpoint device?laptop, server, phoneNoDefender for EndpointASR rules (Audit then Block)YesDefender for Cloudenable per-resource planNo (cloud workload)Always: free CSPM gives recommendations; a paid Defender plan gives alerts

Cheat sheet

  • Pick the Defender workload that owns the attacked asset
  • Defender for Office 365 adds detonation and time-of-click on top of free EOP
  • Safe Links rechecks URLs at click time, not just at delivery
  • Use Safe Attachments Block to stop files; Dynamic Delivery to avoid delay
  • Apply the Standard or Strict preset for Microsoft's recommended baseline
  • Office 365 policy precedence: Strict beats Standard beats custom beats Built-in
  • Deploy ASR rules in Audit first, then promote to Block
  • ASR rules run in one of four modes, including Warn for user override
  • ASR rules need Microsoft Defender Antivirus as the active AV
  • ASR is one slice of Defender for Endpoint's wider attack surface reduction set
  • ASR rule conflicts: non-conflicting settings merge, conflicting ones are dropped
  • Defender for Cloud: free CSPM gives recommendations, a paid plan gives alerts
  • Enable the matching Defender plan to protect each cloud resource type
  • Paid Defender CSPM is a separate upgrade from free foundational CSPM
  • Defender for Cloud spans Azure, AWS, and GCP via native connectors
  • Defender for Servers integrates Defender for Endpoint onto VMs automatically
  • Access policy decides the sign-in; session policy controls actions inside the app
  • Session policies use Conditional Access App Control, a reverse proxy
  • File and activity policies cover data at rest and logged behaviour in SaaS
  • Use App Governance to catch malicious or overprivileged OAuth apps
  • Match the configuration surface to the product to confirm an answer
  • Just-in-time VM access needs Defender for Servers Plan 2, ARM deployment, and an NSG or Azure Firewall
  • Agentless scanning, JIT VM access, and file integrity monitoring are Defender for Servers Plan 2 only

Unlock with Premium — includes all practice exams and the complete study guide.

Also tested in

References

  1. Why do I need Microsoft Defender for Office 365?
  2. Microsoft Defender for Cloud Apps overview
  3. Microsoft Defender for Endpoint
  4. Microsoft Defender for Cloud Overview
  5. Built-in security features for all cloud mailboxes
  6. Safe Attachments
  7. Complete Safe Links overview for Microsoft Defender for Office 365
  8. Preset security policies
  9. Configuration analyzer for threat policies
  10. ASR rules overview
  11. ASR rules deployment guide
  12. Attack surface reduction in Microsoft Defender for Endpoint
  13. What is Cloud Security Posture Management (CSPM)
  14. Cloud Secure Score in Microsoft Defender for Cloud
  15. Connect your AWS Account
  16. Connect your GCP Project
  17. Create access policies
  18. Create session policies
  19. Conditional Access app control
  20. Create activity policies
  21. File policies in Microsoft Defender for Cloud Apps
  22. App governance in Microsoft Defender for Cloud Apps and Microsoft Defender XDR