Looking for Microsoft Defender for Endpoint-specific capability details by license tier (Business Premium, E3, E5)? See the Microsoft Defender Capability Matrix.
Legend
Supported Integrations
Incident Management
Unified incident queue with cross-workspace handling, bidirectional sync, and analyst assignment.Entity Enrichment & Triage
Contextual intelligence for users, devices, IPs, files, emails, and URLs during investigations.User Insights
Device Insights
IP Address Insights
Email, File & URL Insights
(1) Requires Microsoft Entra ID connection.(2) Requires Defender for Endpoint — included with E5 or available as an add-on for Business Premium and E3.
Log Search
Direct query access to log data for deep investigation and threat hunting.Gamebook Response Actions
Automated response playbooks for endpoint, file, identity, and email threats.Endpoint Actions
File Actions
User Actions
Email Actions
(1) Requires Microsoft Entra ID connection and the Gamebooks for Identity enterprise application.(2) Requires Defender for Endpoint — Sentinel gamebook actions execute through Defender for Endpoint.(3) Requires Microsoft 365 Exchange license and the Microsoft 365 Response enterprise application.
Endpoint Management
View and manage devices across your customer environments.Content Management System (CMS)
Deploy and manage detection rules across workspaces.CMS requires the XDR + SIEM module. Microsoft Sentinel must be connected to use CMS.
Incident Notifications
Email notifications when new incidents arrive.Incident email notifications require the XDR + SIEM module. Email notifications for Gamebook activity are available across all modules.
Related Guides
Microsoft Defender Capability Matrix
XDR capabilities by Microsoft 365 license tier
Defender Module Deployment
Deploy the Defender for Endpoint module
Sentinel Module Deployment
Deploy the XDR + SIEM module
Enterprise Applications
Service principal permissions reference
Questions about capabilities or integrations? Contact us at support@contraforce.com.