Microsoft Defender XDR Onboarding Checklist
Retrospective: this article looks back at events from September 2020, written in 2026 with the benefit of hindsight.
Owning Microsoft Defender licenses isn't the same as being protected. Use this checklist to onboard the Defender XDR products properly.
Defender for Endpoint
- All devices onboarded (Intune, Group Policy or scripts) — including servers via Defender for Servers.
- Tamper protection enabled.
- Attack surface reduction rules in audit, then block mode.
- EDR in block mode enabled where another antivirus is primary.
- Automated investigation and remediation level set.
Defender for Office 365
- Standard or Strict preset security policies applied.
- Safe Links and Safe Attachments enabled for email, Teams and Office apps.
- Impersonation protection configured for executives and domains.
- User-reported message settings configured.
Defender for Identity
- Sensors installed on all domain controllers, AD FS and AD CS servers.
- Directory service account configured.
- Health alerts reviewed and cleared.
Defender for Cloud Apps
- Microsoft 365 app connector enabled.
- Cloud discovery fed by Defender for Endpoint.
- App governance enabled for OAuth apps.
Defender XDR
- Roles assigned using unified RBAC.
- Incident notifications configured for high severity.
- Automatic attack disruption enabled where available.
- Sentinel connected if you use it.
Operations
- Someone reviews the incident queue daily.
- Monthly review of Secure Score and exposure management recommendations.