M365Clarity · Defender XDR

Microsoft 365 Defender XDR — what's actually enabled in your tenant

M365Clarity · 24 June 2026

← All articles

The gap between licensed and configured

Microsoft Defender XDR is included in Microsoft 365 E5 and available as an add-on for E3. It brings together endpoint protection, email security, identity threat detection, and cloud app security into a single extended detection and response platform. The problem is that licensing it and configuring it are two entirely separate things — and most tenants that have the licence haven't done the configuration work.

The result is a tenant that shows Defender XDR in its licence inventory but is effectively unprotected by it. Attack Surface Reduction rules are not enabled. Safe Attachments covers some but not all mailboxes. Defender for Identity has no sensors on domain controllers. The Secure Score sits below 50 percent with dozens of improvement actions untouched.

What Defender XDR actually covers

Defender XDR is not a single product — it is a coordination layer across four separate protection pillars:

The most common Defender XDR configuration gaps

Across real tenants scanned by M365Clarity, these are the gaps that appear most frequently in Defender XDR configuration:

Safe Attachments not covering all mailboxes

Safe Attachments is configured per policy. Many tenants create one policy targeting specific groups or domains and leave everyone else uncovered. Every mailbox in your organisation should be in scope for Safe Attachments with Dynamic Delivery enabled.

Safe Links limited to email only

Safe Links can rewrite URLs in email, Teams messages, and Office 365 apps (Word, Excel, PowerPoint). Most tenants enable it for email but leave Teams and Office app URL rewriting unconfigured — leaving a significant attack surface open.

Attack Surface Reduction rules partially enabled

Windows 10 and 11 devices support 16 ASR rules covering common attack techniques — Office macro abuse, credential theft, process injection, and others. Most tenants enable 2 or 3 rules at most and leave the rest in audit mode or disabled entirely.

No Defender for Identity sensors deployed

MDI requires sensors installed on every domain controller. It's not agentless — it requires an active deployment step. Tenants that have MDI licensed but no sensors deployed get no hybrid identity threat detection whatsoever.

Attack simulation never run

Attack Simulation Training in Defender for Office 365 P2 lets you run simulated phishing campaigns against your own users. Microsoft recommends running at least one simulation per quarter. Most tenants that have the licence have never run a single simulation.

Licence note: Full Defender XDR requires Microsoft 365 E5 or the Microsoft Defender XDR add-on for E3. Defender for Business (included in Business Premium) covers endpoint and email protection for organisations with up to 300 users but does not include Defender for Identity or Cloud Apps.

What M365Clarity checks in the Defender XDR tab

The Defender XDR tab in M365Clarity runs 17 configuration checks across all four Defender pillars. It shows active incident count and severity, your current Microsoft Secure Score percentage, Safe Attachments and Safe Links coverage, ASR rule status, MDI sensor deployment, attack simulation history, and Cloud Apps governance policy configuration. Each finding includes plain-English explanation and a direct link to the relevant Microsoft admin centre to fix it.

See your Defender XDR configuration in 30 seconds

Connect your tenant and M365Clarity will scan 17 Defender XDR checks and show you exactly what is configured, what is missing, and what to fix first.

Free scan — no agents required →

Related articles