M365Clarity Blog · 6 July 2026 · Defender Security MSP

Microsoft Defender Posture Assessment: What M365Clarity Analyses

Microsoft Defender is not a single product — it is a suite of overlapping security controls spanning email, endpoint, identity, cloud apps, and extended detection and response. Most organisations that subscribe to Microsoft 365 Business Premium or higher have some Defender capabilities but use only a fraction of what is available. The question is not whether Defender is licensed. It is whether it is actually configured to protect you.

M365Clarity's Defender AI Posture assessment analyses 15 signals from your Defender deployment and generates a plain-English risk narrative explaining what your specific configuration means for your organisation. Here is what it checks and why each one matters.

The 15 signals assessed

SignalWhat it checksWhy it matters
Microsoft Secure ScoreYour current score vs maximum, improvement actions availableBaseline indicator of overall security posture
Defender for Endpoint (MDE)Device onboarding count, real-time protection statusEndpoints not onboarded to MDE have no EDR coverage
Defender for Office 365MDO licence level (P1/P2), active statusP1 vs P2 determines access to AIR, Threat Tracker, Campaign Views
Defender for Identity (MDI)Sensor deployment on domain controllersWithout MDI sensors, lateral movement and pass-the-hash attacks are invisible
XDR Active IncidentsOpen incident count and severityActive unresolved incidents represent live exposure
Alert PoliciesNumber of active alert policies across workloadsWithout alert policies, security events go unnoticed
Vulnerability ManagementCritical CVE count across enrolled devicesUnpatched critical CVEs are the most common ransomware entry point
Attack Surface Reduction RulesASR rules enabled vs 16 total availableASR rules block the most common attack techniques at the OS level
Safe AttachmentsPolicy scope and detonation modeDynamic Delivery prevents zero-day attachment delivery
Safe LinksURL rewriting scope (email, Teams, Office apps)Links rewritten only in email still allow phishing via Teams or docs
Advanced Anti-PhishingImpersonation protection for executives and domainsImpersonation attacks account for 70%+ of BEC incidents
Attack Simulation TrainingWhether simulations have been run in the last 90 daysUntested users are 3x more likely to click phishing links
Cloud App SecurityDefender for Cloud Apps connection and policy statusShadow IT and unsanctioned SaaS are invisible without MCAS
Adaptive ProtectionInsider Risk Management integration statusAdaptive Protection ties user risk level to DLP enforcement
Defender for BusinessBaseline policy deployment for SMB tenantsDefender for Business is included in Business Premium — gaps mean unused protection

What the AI narrative adds

Individual signal scores tell you what is red or amber. The AI narrative tells you what the combination means. A tenant with Safe Attachments enabled but no ASR rules and 12 unpatched CVEs has a fundamentally different risk profile from one with ASR rules configured but no email protection. The narrative surfaces these interactions — it does not just list individual findings.

For MSPs: The Defender posture card is designed to be shown directly to clients. The language is board-level — it explains business impact, not technical configuration. "You have 2 active security incidents and no automated response rules" is immediately understandable to a non-technical MD in a way that "XDR incident count: 2" is not.

How the risk level is determined

The AI assigns a risk level (low, medium, high, or critical) based on the combination of signals. A single red finding does not automatically mean high risk — it depends on which finding. An active XDR incident with no automated response is weighted more heavily than an unenabled ASR rule. The narrative explains the reasoning, so the risk level is not just a number.

Where to find it

The Defender AI Posture card appears at the bottom of the Security & Compliance → Defender XDR tab. It auto-loads from cache on tab open. The first generation takes 15–20 seconds. After that it loads instantly and is regenerated automatically after each rescan.

Assess your Defender posture

Scan your tenant and get an AI assessment of your full Defender coverage in under 2 minutes.

Run a free scan →