Microsoft Defender for Endpoint is Microsoft's EDR solution. It detects suspicious activity, records endpoint telemetry, investigates incidents and supports response actions.

The Microsoft Defender product comparison below was checked on ****. The specific product and license matter:

  • Microsoft Defender Antivirus is mainly an antivirus and next-generation protection product. It is not a complete standalone EDR platform.
  • Microsoft Defender for Endpoint provides endpoint detection and response.
  • Microsoft Defender XDR connects endpoint signals with identity, email and cloud application data. It includes EDR, but covers more than endpoint security.

Microsoft Defender Products Compared

Microsoft product Is it an EDR? Main function
Microsoft Defender Antivirus No, not by itself Malware prevention, real-time protection and antivirus detection
Microsoft Defender for Endpoint Plan 1 Limited EDR capabilities Endpoint protection, centralized management and restricted response actions
Microsoft Defender for Endpoint Plan 2 Yes Full endpoint detection, investigation, hunting and response
Microsoft Defender for Business Yes, for small businesses EDR and endpoint protection for organizations with up to 300 users
Microsoft Defender XDR Not only an EDR Detection and response across endpoints, identities, email, cloud apps and other Microsoft services

Microsoft's licensing documentation lists the full EDR capability set under Defender for Endpoint Plan 2. It also describes limited EDR capabilities and manual response actions for Plan 1 and Microsoft Defender for Business.

What Does Microsoft Defender for Endpoint Do?

Microsoft Defender for Endpoint provides the main functions expected from an endpoint detection and response platform:

  • Behavioral detection: It analyzes process activity, network connections, user logins, registry changes, file system activity and other endpoint signals.
  • Incident investigation: It groups related alerts into incidents so analysts can examine the wider attack.
  • Threat hunting: Security teams can query endpoint data to search for attacker behavior.
  • Response actions: Administrators can isolate devices, run antivirus scans, quarantine files and apply indicators. The available actions depend on the plan.
  • Automated investigation and remediation: Supported plans can investigate alerts and apply remediation actions automatically.
  • EDR in block mode: Plan 2 can remediate malicious artifacts detected by EDR when a non-Microsoft antivirus product is the primary antivirus.

Is Microsoft Defender Antivirus the Same as EDR?

No. Microsoft Defender Antivirus and Microsoft Defender for Endpoint are related, but they provide different functions.

Microsoft Defender Antivirus focuses mainly on preventing and blocking malware. Microsoft Defender for Endpoint adds endpoint telemetry, incident investigation, threat hunting and response.

A computer can run Microsoft Defender Antivirus without using the full Microsoft Defender for Endpoint EDR service. Enabling the built-in antivirus does not automatically provide the complete enterprise EDR service.

Does Microsoft Defender for Business Include EDR?

Yes. Microsoft Defender for Business includes an EDR capability for small and medium-sized businesses with up to 300 users.

Microsoft describes Defender for Business as a service based on Microsoft Defender for Endpoint. Its listed capabilities include EDR, automated investigation and remediation, attack surface reduction and vulnerability management.

Microsoft 365 Business Premium includes Microsoft Defender for Business.

Is Microsoft Defender XDR an EDR?

Microsoft Defender XDR includes EDR, but it is not limited to endpoint detection and response.

EDR monitors and responds to activity on endpoint devices such as Windows PCs, Macs and servers. Microsoft Defender XDR connects endpoint data with signals from Microsoft Entra ID, Microsoft Defender for Office 365, cloud applications and other Microsoft security products.

That cross-domain coverage is why Microsoft Defender XDR is classified as XDR, or extended detection and response.

How Can You Identify Which Microsoft Defender Product You Have?

Check the product or license name:

  • Windows Security or Microsoft Defender Antivirus: Antivirus protection, not necessarily EDR.
  • Microsoft Defender for Endpoint Plan 1: Endpoint protection with limited detection and response capabilities.
  • Microsoft Defender for Endpoint Plan 2: The full Microsoft EDR platform.
  • Microsoft Defender for Business: EDR for small and medium-sized businesses.
  • Microsoft 365 E5 or a security suite that includes Defender for Endpoint Plan 2: Usually includes the full EDR capability set, subject to the relevant license and deployment configuration.

Bottom Line

Microsoft Defender for Endpoint is an EDR platform. Microsoft Defender Antivirus alone is not a full EDR platform. Microsoft Defender for Business also includes EDR for organizations with up to 300 users, while Microsoft Defender XDR connects EDR with identity, email and cloud application security.

For enterprise threat hunting, automated investigation and wider response capabilities, Microsoft Defender for Endpoint Plan 2 is Microsoft's clearest EDR product.