Microsoft Defender is not a single product — it is a suite of overlapping security controls spanning email, endpoint, identity, cloud apps, and extended detection and response. Most organisations that subscribe to Microsoft 365 Business Premium or higher have some Defender capabilities but use only a fraction of what is available. The question is not whether Defender is licensed. It is whether it is actually configured to protect you.
M365Clarity's Defender AI Posture assessment analyses 15 signals from your Defender deployment and generates a plain-English risk narrative explaining what your specific configuration means for your organisation. Here is what it checks and why each one matters.
| Signal | What it checks | Why it matters |
|---|---|---|
| Microsoft Secure Score | Your current score vs maximum, improvement actions available | Baseline indicator of overall security posture |
| Defender for Endpoint (MDE) | Device onboarding count, real-time protection status | Endpoints not onboarded to MDE have no EDR coverage |
| Defender for Office 365 | MDO licence level (P1/P2), active status | P1 vs P2 determines access to AIR, Threat Tracker, Campaign Views |
| Defender for Identity (MDI) | Sensor deployment on domain controllers | Without MDI sensors, lateral movement and pass-the-hash attacks are invisible |
| XDR Active Incidents | Open incident count and severity | Active unresolved incidents represent live exposure |
| Alert Policies | Number of active alert policies across workloads | Without alert policies, security events go unnoticed |
| Vulnerability Management | Critical CVE count across enrolled devices | Unpatched critical CVEs are the most common ransomware entry point |
| Attack Surface Reduction Rules | ASR rules enabled vs 16 total available | ASR rules block the most common attack techniques at the OS level |
| Safe Attachments | Policy scope and detonation mode | Dynamic Delivery prevents zero-day attachment delivery |
| Safe Links | URL rewriting scope (email, Teams, Office apps) | Links rewritten only in email still allow phishing via Teams or docs |
| Advanced Anti-Phishing | Impersonation protection for executives and domains | Impersonation attacks account for 70%+ of BEC incidents |
| Attack Simulation Training | Whether simulations have been run in the last 90 days | Untested users are 3x more likely to click phishing links |
| Cloud App Security | Defender for Cloud Apps connection and policy status | Shadow IT and unsanctioned SaaS are invisible without MCAS |
| Adaptive Protection | Insider Risk Management integration status | Adaptive Protection ties user risk level to DLP enforcement |
| Defender for Business | Baseline policy deployment for SMB tenants | Defender for Business is included in Business Premium — gaps mean unused protection |
Individual signal scores tell you what is red or amber. The AI narrative tells you what the combination means. A tenant with Safe Attachments enabled but no ASR rules and 12 unpatched CVEs has a fundamentally different risk profile from one with ASR rules configured but no email protection. The narrative surfaces these interactions — it does not just list individual findings.
For MSPs: The Defender posture card is designed to be shown directly to clients. The language is board-level — it explains business impact, not technical configuration. "You have 2 active security incidents and no automated response rules" is immediately understandable to a non-technical MD in a way that "XDR incident count: 2" is not.
The AI assigns a risk level (low, medium, high, or critical) based on the combination of signals. A single red finding does not automatically mean high risk — it depends on which finding. An active XDR incident with no automated response is weighted more heavily than an unenabled ASR rule. The narrative explains the reasoning, so the risk level is not just a number.
The Defender AI Posture card appears at the bottom of the Security & Compliance → Defender XDR tab. It auto-loads from cache on tab open. The first generation takes 15–20 seconds. After that it loads instantly and is regenerated automatically after each rescan.
Assess your Defender posture
Scan your tenant and get an AI assessment of your full Defender coverage in under 2 minutes.
Run a free scan →