This matrix only covers the Microsoft Defender XDR module capabilities.
Understanding the Matrix
Legend
| Symbol | Meaning |
|---|---|
| ✓ | Capability fully available |
| ✓(1) | Requires Microsoft Entra ID connection |
| ✓(2) | Requires Microsoft Sentinel connection |
| ✓(3) | Requires Defender for Endpoint Plan 2 |
| ✓(4) | Requires Microsoft 365 Exchange license |
| — | Not available |
License Tiers
Business Premium
Small/medium business license with Defender for Business
Enterprise E3
Enterprise license with Defender for Endpoint P1
Enterprise E5
Full enterprise license with Defender for Endpoint P2
Incident Investigation
Core capabilities for investigating security incidents detected by Microsoft Defender XDR.Incident Management
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Bi-directional streaming of incidents | ✓ | ✓ | ✓ |
| Fetching incident entities | ✓ | ✓ | ✓ |
| Fetching incident evidence (logs) | ✓ | ✓ | ✓ |
| Incident alert timelines | ✓ | ✓ | ✓ |
| Incident investigation audit | ✓ | ✓ | ✓ |
Entity Enrichment & Triage
Capabilities for enriching entity data and correlating related incidents during investigation.User Insights
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Related incident search | ✓ | ✓ | ✓ |
| Sign-in logs | ✓(1) | ✓(1) | ✓(1) |
| Audit logs | ✓(1) | ✓(1) | ✓(1) |
| Entra ID profile | ✓(1) | ✓(1) | ✓(1) |
(1) User insights require Microsoft Entra ID to be connected to ContraForce. Consent the appropriate enterprise applications during onboarding.
IP Address Insights
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Sign-in log activity | ✓(2) | ✓(2) | ✓(2) |
| Related incidents | ✓(3) | ✓(3) | ✓ |
(2) IP sign-in activity requires Microsoft Sentinel connection (XDR + SIEM module).(3) Some IP insights require Defender for Endpoint Plan 2 on Business Premium and E3.
Device Insights
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Device info | ✓ | ✓ | ✓ |
| Device timeline | ✓(3) | ✓(3) | ✓ |
| Related incidents | ✓(3) | ✓(3) | ✓ |
(3) Device timeline and related incidents require Defender for Endpoint Plan 2 add-on for Business Premium and E3 licenses.
Email Insights
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Related incidents | ✓ | ✓ | ✓ |
| Email info | ✓(3) | ✓(3) | ✓ |
File Insights
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Related incidents | ✓ | ✓ | ✓ |
| File info | ✓ | ✓ | ✓ |
URL Insights
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Related incidents | ✓ | ✓ | ✓ |
| URL info | ✓(3) | ✓(3) | ✓ |
Log Search
Advanced hunting and log query capabilities.| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Log search (Advanced Hunting) | ✓(3) | ✓(3) | ✓ |
Endpoint Management
Capabilities for managing and monitoring endpoints through ContraForce.| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| View device list | ✓ | ✓ | ✓ |
| View device info | ✓ | ✓ | ✓ |
Gamebook Response Actions
Automated response capabilities organized by entity type.Endpoint Actions
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Isolate endpoint | ✓ | ✓ | ✓ |
| Anti-virus scan of endpoint | ✓ | ✓ | ✓ |
| Remove from isolation | ✓ | ✓ | ✓ |
Endpoint Gamebook actions require the Gamebooks for Microsoft Defender XDR enterprise application to be consented.
File Actions
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Quarantine file | ✓ | ✓ | ✓ |
User Actions
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Invalidate existing sessions | ✓(1) | ✓(1) | ✓(1) |
| Reset user password | ✓(1) | ✓(1) | ✓(1) |
| Lock out user | ✓(1) | ✓(1) | ✓(1) |
| Unlock user | ✓(1) | ✓(1) | ✓(1) |
(1) User Gamebook actions require Microsoft Entra ID connection and the Gamebooks for Identity enterprise application.
IP Address Actions
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Block IP (Azure NSG) | — | — | — |
IP blocking via Azure Network Security Groups is planned for future release.
Email Actions
| Capability | Business Premium | E3 | E5 |
|---|---|---|---|
| Soft delete email | ✓(4) | ✓(4) | ✓(4) |
(4) Email actions require a Microsoft 365 Exchange license and the Microsoft 365 Response enterprise application.
Dependencies Reference
Dependency (1): Microsoft Entra ID
Required for: User insights, User Gamebook actions How to enable:- During onboarding, consent the ContraForce enterprise applications
- The Gamebooks for Identity service principal must be consented for user response actions
- ContraForce API
- ContraForce Portal
- Gamebooks for Identity
Dependency (2): Microsoft Sentinel
Required for: IP sign-in activity How to enable:- Deploy the XDR + SIEM module instead of XDR-only
- Connect your Sentinel workspace during onboarding
Sentinel Onboarding
Complete Sentinel onboarding guide
Dependency (3): Defender for Endpoint Plan 2
Required for: Device timeline, IP/Email/URL detailed insights, Log search How to enable:- E5 licenses include Plan 2 natively
- Business Premium and E3 require the Defender for Endpoint Plan 2 add-on
| Base License | Add-on Required |
|---|---|
| Business Premium | Defender for Endpoint Plan 2 |
| Enterprise E3 | Defender for Endpoint Plan 2 |
| Enterprise E5 | Included |
Dependency (4): Microsoft 365 Exchange
Required for: Email Gamebook actions (soft delete) How to enable:- Ensure users have Exchange Online licenses
- Consent the Microsoft 365 Response enterprise application
M365 Response Application
Microsoft 365 Response enterprise application details
Complete Capability Summary
By License Tier
Quick Reference by Feature Area
| Feature Area | Dependencies | Notes |
|---|---|---|
| Incident Management | None | Full capability on all licenses |
| Endpoint Management | None | Full capability on all licenses |
| Endpoint Gamebooks | Gamebooks for Defender XDR | Full capability on all licenses |
| User Insights | Entra ID (1) | Same across all licenses |
| User Gamebooks | Entra ID (1) + Gamebooks for Identity | Same across all licenses |
| Device Timeline | Plan 2 (3) | Native on E5 |
| Log Search | Plan 2 (3) | Native on E5 |
| Email Actions | Exchange (4) + M365 Response | Same across all licenses |
| IP Sign-in Activity | Sentinel (2) | Requires XDR + SIEM module |
Maximizing Your Capabilities
Connect Entra ID for user capabilities
Connect Entra ID for user capabilities
User insights and user Gamebook actions are essential for identity-based investigations. Ensure you consent all identity-related enterprise applications during onboarding.
Consider E5 or Plan 2 add-on for full visibility
Consider E5 or Plan 2 add-on for full visibility
If you frequently need device timelines, advanced hunting, or detailed entity insights, the Defender for Endpoint Plan 2 capabilities are worth the investment.
Add Sentinel for comprehensive coverage
Add Sentinel for comprehensive coverage
The XDR + SIEM module adds Sentinel incidents, advanced threat hunting, CMS, and IP sign-in insights. Consider upgrading if you use Sentinel.
Consent all relevant enterprise applications
Consent all relevant enterprise applications
Many capabilities require specific enterprise applications. Review the Enterprise Applications Overview and consent all applications relevant to your needs.
Related Guides
Full Capabilities Matrix
Complete matrix including SIEM integrations
XDR Onboarding
Deploy the XDR module
Enterprise Applications
All service principals and permissions
Gamebooks
Response action capabilities
Questions about capabilities or licensing? Contact us at [email protected].