Microsoft Security Solutions

Explore Microsoft Security

Choose a solution, find practical articles and continue with Microsoft’s official documentation.

Published guide collections

Information Protection

Sensitivity labels and information protection guides.

Browse articles →

Data Loss Prevention

Explore the existing DLP articles.

Browse articles →

Data Classification

Sensitive information types and trainable classifiers.

Browse articles →

Lifecycle & Records

Retention, lifecycle management and records articles.

Browse articles →

Defender for Identity

Browse the identity threat protection archive.

Browse articles →

Defender for Office 365

Browse email and collaboration threat protection articles.

Browse articles →

Solution overviews

These summaries link to official documentation. Detailed blog coverage is still being developed for some areas.

Microsoft Agent 365

Observe, govern and secure AI agents through centralized inventory, lifecycle management and security oversight. Agent 365 brings together Microsoft Entra identity controls, Microsoft Purview data protection and Microsoft Defender threat protection.

Identity and access · Data security and AI protection · Threat investigation and response

Microsoft Learn: Agent 365 overview →

Data Security Posture Management

Microsoft Purview DSPM helps identify sensitive data risks and brings related protection insights together, including risks involving AI applications.

Official Microsoft documentation →

Insider Risk Management

Identify and investigate potentially risky activity involving sensitive data, using authorized workflows and privacy controls.

Official Microsoft documentation →

eDiscovery & Audit

eDiscovery supports content preservation and legal investigations. Audit provides activity records for security and compliance investigations.

Official Microsoft documentation →

Defender for Endpoint

Endpoint prevention, detection, investigation and response. Device signals contribute to incidents and investigations in Defender XDR.

Official Microsoft documentation →

Defender for Cloud Apps

Visibility and security controls for SaaS applications, with activity monitoring and threat signals integrated into Defender XDR.

Official Microsoft documentation →

XDR Investigation & Response

Correlate signals across endpoints, identities, email and applications. Investigate incidents, hunt for threats and coordinate response actions.

Official Microsoft documentation →

Microsoft Entra ID

Identity and access management for users, applications and workloads. Explore authentication, Conditional Access and secure access design.

Official Microsoft documentation →

Entra ID Protection

Identify identity risks and support risk-based access decisions to help protect users and sign-ins.

Official Microsoft documentation →

Entra ID Governance

Manage identity lifecycles and access through access reviews, entitlement management and privileged identity management.

Official Microsoft documentation →

Entra Internet & Private Access

Identity-centric access controls for internet traffic and private applications. These products extend Zero Trust access beyond traditional network boundaries.

Official Microsoft documentation →

Microsoft 365 Copilot Security

Secure Copilot adoption through identity controls, data protection, permissions and collaboration governance. Microsoft 365 security spans several products.

Official Microsoft documentation →

Email & Collaboration Security

Protect Exchange, Teams, SharePoint and OneDrive through coordinated threat protection, access controls and data protection policies.

Official Microsoft documentation →

Microsoft Security Copilot

AI assistance for security and IT teams across Microsoft Defender, Sentinel, Entra, Intune and Purview. Security Copilot supports investigations and other security workflows; it is a separate solution from Microsoft 365 Copilot.

Microsoft Learn: Security Copilot overview →

Sentinel Analytics & Hunting

Use centralized security telemetry to support detection, investigation and threat hunting across Microsoft and third-party sources.

Official Microsoft documentation →

Defender for Cloud

Microsoft Defender for Cloud combines cloud security posture management (CSPM), workload protection and DevSecOps security across multicloud and hybrid environments. Coverage includes servers, containers, storage and AI workloads. It integrates with security operations but has a distinct scope from Defender XDR.

Microsoft Learn: Defender for Cloud overview →

Microsoft Sentinel guide collection · All articles