MSSecurity ReferenceLocal field manual
HomeProductsLicensingLicense CompareSentinel CostTablesSchemasFieldsCompareSentinel SetupData LakeIaCAPIsAPI WorkflowsAPI PermissionsSearch
product

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint is an enterprise endpoint security platform used to prevent, detect, investigate, and respond to advanced threats.

productsMDECurrent

Relationships

Microsoft Defender for Endpoint P1
Required or related license
license
Microsoft Defender for Endpoint P2
Required or related license
license
Attack Surface Reduction
Capability
capability
Endpoint Detection and Response
Capability
capability
Automated Investigation and Response
Capability
capability
Advanced Hunting
Capability
capability
Threat and Vulnerability Management
Capability
capability
DeviceProcessEvents
Produced or queried table
table
DeviceEvents
Produced or queried table
table
DeviceFileEvents
Produced or queried table
table
DeviceNetworkEvents
Produced or queried table
table
DeviceRegistryEvents
Produced or queried table
table
DeviceLogonEvents
Produced or queried table
table
DeviceImageLoadEvents
Produced or queried table
table
DeviceInfo
Produced or queried table
table
Microsoft Defender for Endpoint APIs
Related API
api
Microsoft Defender for Endpoint Indicators API
Related API
api
Microsoft Graph Security API
Related API
api
Legacy Microsoft Defender XDR APIs
Related API
api

Reference

Stable ID
defender-for-endpoint
Path
/entities/products/defender-for-endpoint/
Last verified
2026-08-10

Official Sources

Microsoft Defender for Endpoint documentationOpen