Microsoft Defender Learning Hub
Microsoft Defender is Microsoft’s security portfolio for protecting identities, endpoints, email, cloud apps, and cross-domain incidents. Use this Learning Hub to build a practical path from core concepts to implementation, governance, and continuous improvement.
Start your Microsoft Defender learning path
- Microsoft Defender for Office 365 — protect email, collaboration, and phishing-prone users.
- Microsoft Defender for Endpoint — prevent, detect, investigate, and respond on devices.
- Microsoft Defender for Identity — detect identity-based threats across hybrid environments.
- Microsoft Defender for Cloud Apps — discover, govern, and protect SaaS usage.
- Microsoft Defender XDR — investigate incidents across security domains in one experience.
- Microsoft Secure Score — prioritize measurable security improvements.
- Attack Simulation Training — test awareness and improve user resilience.
- Microsoft Defender Licensing Guide — understand edition and capability planning.
- Microsoft Defender Best Practices — turn product capabilities into an operating model.
How to use this hub
Begin with the workload that represents your most immediate risk, then connect it to identity, endpoints, cloud apps, and incident response. For a broad rollout, start with Secure Score, establish ownership for each improvement action, and use the workload paths to implement changes without losing sight of the wider XDR picture.
Recommended podcast episodes
- Microsoft Defender for Office 365 — Simply Explained
- Microsoft Defender for Endpoint — Simply Explained
- Microsoft Defender for Identity — Simply Explained
- Microsoft Defender for Cloud Apps — Simply Explained
- Microsoft Secure Score — Simply Explained
Next learning step
Return to the M365.fm Learning Hub to continue with another Microsoft technology domain.
Last reviewed: July 2026.
Microsoft Defender learning path
Foundation: start with Defender for Office 365, Endpoint, Identity, and Cloud Apps. Operations: bring signals together in Defender XDR and use Secure Score to prioritize improvement. Resilience: validate people and processes with Attack Simulation Training.
Frequently asked question
Where should a new Defender team begin?
Begin with the workload that creates the highest current risk, then use the related Defender product path. Avoid treating each portal as an isolated tool: detections, identity, data, and response need an operating model.