Clarification on whether Microsoft Defender is operating as AV or EDR

Amara, Hany 20 Reputation points
2026-08-17T08:39:54.5633333+00:00

Could you please help determine whether Microsoft Defender deployment is functioning only as an Antivirus (AV) solution, or whether it is also operating with Endpoint Detection and Response (EDR) capabilities enabled?

Specifically, we would like to understand:

  1. how to verify whether a device is onboarded to Microsoft Defender for Endpoint,
  2. which features or indicators confirm EDR functionality,
  3. and how to distinguish an AV-only configuration from one with full EDR capabilities.

Does the Defender have cartelized console same as EDR when it comes to "Incidents" tab? if yes, are the incidents generated from the AV shown on "Incidents" tab?

If useful, please also advise where in the Defender portal or endpoint settings we can validate this.

Microsoft 365 and Office | Microsoft 365 Defender | Other | Windows
0 comments No comments

Answer accepted by question author
Marcin Policht 103.7K Reputation points MVP Volunteer Moderator
2026-08-17T11:11:14.4966667+00:00

The term “Microsoft Defender” by itself is ambiguous because Microsoft uses it for several related products. Microsoft Defender Antivirus (AV) is the endpoint antivirus component. Microsoft Defender for Endpoint (MDE) provides endpoint security and EDR capabilities. Microsoft Defender XDR is the broader security platform that correlates signals and incidents across products such as Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps.

To verify whether a device has MDE/EDR, you would typically use the Microsoft Defender portal at https://security.microsoft.com and select Assets > Devices. If the device is listed there with current telemetry and MDE information, it is onboarded to Defender for Endpoint. On the endpoint, the Microsoft Defender for Endpoint Service (Sense) should also be present and running.

The important distinction is that Defender Antivirus can operate without MDE/EDR. AV provides malware and real-time protection and can generate detections. MDE adds the endpoint telemetry, EDR alerts, device timeline, investigation capabilities, and advanced hunting capabilities.

The Incidents tab is part of the broader Microsoft Defender XDR experience, so its presence does not prove that EDR is enabled. Incidents can contain alerts from multiple Defender products, including Defender Antivirus/MDE. Therefore, an AV detection can appear in an XDR incident even though the existence of that incident alone does not establish that EDR is deployed.

So, in short, Defender AV = antivirus, Defender for Endpoint = endpoint security/EDR, and Defender XDR = cross-product detection, correlation, investigation, and incident response platform. To establish that EDR is actually functioning, verify the device's MDE onboarding and sensor/telemetry status, rather than relying on the existence of an Incidents tab or AV detections.


If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

hth

Marcin

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.