Article

What Microsoft Defender Actually Does

·By Mathew Chewing

There are five different products called Defender and they do very different jobs. Here is what each one covers, and which your business is probably already paying for.

What Is Microsoft Defender for Individuals & What Does It Do?

Microsoft has attached the name Defender to at least five separate products, and the result is a genuine mess. Businesses regularly believe they are protected because "Defender is on," when the Defender they mean is the free antivirus built into Windows and the Defender they need is a licensed product sitting unconfigured in their tenant.

Untangling the names is worth ten minutes, because the gap between them is where real incidents happen.

The five things called Defender

Microsoft Defender Antivirus. Built into every copy of Windows, free, on by default. Real-time malware scanning for the machine it runs on. It is genuinely decent — independent testing has rated it competitive with paid consumer products for years — and for a home PC it is sufficient.

Microsoft Defender for Individuals. A consumer app bundled with Microsoft 365 Personal and Family. It provides a dashboard across your family devices, some identity-theft monitoring and a VPN, depending on region. It is a consumer product. It is not a business security control, and it should not be the answer when a client asks what protects your network.

Microsoft Defender for Endpoint. This is the business one. Rather than just scanning files, it records what happens on a device — processes, network connections, script execution — and detects suspicious behaviour. It also lets someone investigate an incident remotely and isolate a compromised machine from the network with a click.

Microsoft Defender for Office 365. Protects the mail flow. Safe Links rewrites URLs so they are checked at the moment of clicking rather than only at delivery. Safe Attachments detonates files in a sandbox before they reach the mailbox. Anti-phishing policies catch display-name impersonation of your own executives.

Microsoft Defender for Cloud Apps. Watches what SaaS applications are connected to your tenant and what data moves through them — closely related to the consent and integration risks we covered in our guide to vetting third-party apps.

The distinction that matters: antivirus versus EDR

This is the heart of it, and it explains why "we have antivirus" is no longer a sufficient answer.

Traditional antivirus asks one question of a file: do I recognise this as malicious? If yes, block it. That works well against known malware and poorly against everything else — and increasingly, attacks do not involve a malicious file at all.

The modern pattern is to use tools already present on the machine. PowerShell, legitimate remote access software, built-in Windows utilities. There is no virus to detect because nothing malicious was installed. An attacker who has stolen a valid password and signs in normally has not triggered a single antivirus rule.

Endpoint detection and response asks a different question: is this behaviour normal? A finance workstation suddenly running PowerShell that downloads a script, creates a scheduled task and starts touching hundreds of files in the space of a minute has not necessarily run any known malware — but the pattern is unmistakable, and EDR is built to notice patterns.

What your business probably already has

Licensing determines this, and most businesses are not using what they hold.

  • Microsoft 365 Business Basic or Standard. Windows Defender Antivirus on the endpoints, and basic mail filtering. No EDR, no Safe Links.
  • Microsoft 365 Business Premium. Includes Defender for Office 365 Plan 1 and Defender for Business — genuine EDR. Most Business Premium subscribers we audit have neither switched on.
  • Enterprise plans. More again, depending on tier.

If you are on Business Premium, you are already paying for endpoint detection and response and mail-link protection. Turning them on is a configuration exercise, not a purchase — which makes it the best-value security work available to most small businesses.

The part the software cannot do

Here is the honest limitation, and it is the one vendors gloss over. EDR generates alerts. Alerts require a human to read, interpret and act on them, and the alert that matters will arrive at 11pm on a Saturday.

A tool that detects a ransomware precursor at 2am and emails an unmonitored inbox has not protected anything. It has documented the beginning of the incident for you to read on Monday.

This is the difference between owning the technology and having the capability. Either someone in your business genuinely monitors and responds around the clock, or that function is outsourced to a team that does — which is exactly what managed detection and response is: the tooling plus the humans who act on it.

What to do this week

  1. Find out which licence you actually hold. Not which one you think you bought.
  2. Check whether Defender for Business is deployed to devices, or merely included in the licence and never onboarded.
  3. Turn on Safe Links and Safe Attachments if you have Defender for Office 365. This is minutes of work against the most common attack route.
  4. Configure anti-phishing impersonation protection with your real executive names and domain.
  5. Decide who responds to an alert, and what happens outside business hours. Write the answer down.
  6. Confirm no machine is still running third-party antivirus that has quietly disabled Defender without replacing its capability.

Steps one and two catch the majority of the problem. A cyber security assessment answers both quickly, and our cyber security team handles the configuration if the licence is there and unused.

Local IT and cyber security support across NSW

Chewing IT runs managed IT and cyber security for small and mid-sized businesses from our Wyong and Hornsby offices, covering the Central Coast, Newcastle, Lake Macquarie and Hornsby.

Not sure whether the Defender you have is the Defender you need? Ask us to check your tenant — it is usually a configuration gap, not a purchase.

Want this handled for you?

Chewing IT looks after IT, cloud and cyber security for businesses across the Central Coast, Newcastle and Sydney. Free, no-pressure consultation — no contracts, no jargon.