Microsoft Defender for Endpoint (MDE)
Microsoft’s enterprise endpoint security platform. It provides antivirus, EDR (endpoint detection and response), threat intelligence and vulnerability management from one console — for Windows, macOS, Linux, iOS and Android.
What is Microsoft Defender for Endpoint?
Microsoft Defender for Endpoint (MDE) is Microsoft’s enterprise security platform for devices. It combines:
- Antivirus / Anti-Malware (Microsoft Defender Antivirus)
- Endpoint Detection & Response (EDR) — erkennt Angriffe in Echtzeit
- Threat & Vulnerability Management (TVM) — identifiziert Schwachstellen
- Attack Surface Reduction (ASR) — preventive hardening
- Auto-Investigation & Remediation (AIR) — automatic response to threats
- Threat Intelligence — from Microsoft’s global telemetry network
Do not confuse: “Microsoft Defender Antivirus” (included in Windows at no cost) versus “Microsoft Defender for Endpoint” (the commercial enterprise suite). MDE uses the same antivirus core but adds EDR, management and reporting.
MDE P1 vs. P2
MDE Plan 1 (P1)
- AntivirusMicrosoft Defender Antivirus
- Attack Surface ReductionJa
- Device controlBlocking USB and Bluetooth
- Web FilteringJa
- EDRNo (a critical difference)
- LicenceMicrosoft 365 E3, Business Premium
MDE Plan 2 (P2)
- Everything in P1plus
- EDREndpoint Detection & Response
- Threat and vulnerability managementVulnerability scans
- Automated investigationAutomatic remediation
- Threat IntelligenceDeep Threat Research
- Advanced huntingKQL queries across telemetry
- LicenceMicrosoft 365 E5, F5 Security, standalone
The decisive difference: P1 is focused on prevention (classic antivirus and more). P2 is detection and response — it detects attacks that got past the prevention layer.
The most important MDE features
Attack Surface Reduction (ASR)
A set of rules that block typical attack patterns:
- Office applications may not start child processes
- Blocking credential theft tools
- Blocking script execution from email attachments
- Blocking PowerShell-based downloads
Endpoint Detection & Response (EDR, nur P2)
It continuously collects process, network and file telemetry and analyses it for suspicious patterns. Alerts land in the Defender portal (formerly Microsoft 365 Defender, today Defender XDR).
Auto Investigation & Remediation
On an alert, MDE analyses automatically what happened and — depending on policy — carries out remediation: killing processes, quarantining files, removing scheduled tasks. It cuts the manual analysis burden on security teams drastically.
MDE for AVD and Windows 365
MDE works on AVD session hosts and Windows 365 Cloud PCs essentially as it does on physical devices — with a few multi-session quirks:
Multi-session AVD
- MDE is installed on the Session Host , not per user
- Alerts are attributed to the individual session user (correlation)
- For onboarding, Microsoft provides dedicated multi-session scripts
- Bei Non-Persistent VDI: VDI-Onboarding-Package verwenden — devices register dynamically
Windows 365
Cloud PCs are dedicated — MDE onboarding works exactly as on physical PCs. Particularly convenient: Intune can push MDE onboarding automatically.
Performance-Impact
MDE antivirus scans can affect multi-session performance. Recommended:
- Scheduled scans only during quiet hours (at night)
- Leave real-time scanning enabled (security comes first)
- An exclusion list for FSLogix VHDX files and certain VDI paths (Microsoft publishes an official list)
MDE-Integration in DaaS Maps
DaaS Maps shows MDE integration patterns for AVD and Windows 365. For security architecture discussion and MDE tuning, you will find me on LinkedIn.