| Attack Surface, Pre- and Post-Execution |
| Attack surface reduction, with multiple technologies for web protection, application control, and device control that eliminate attack vectors and protect against data loss | Fully provided | Partially provided |
| Defenses that automatically adapt to human-led attacks | Fully provided | Partially provided |
| Automated Account Health Check to maintain a strong security posture | Fully provided | Fully provided |
| Security Heartbeat to share health and threat intelligence information between multiple products | Fully provided | Partially provided |
| Exploit Mitigations |
| Mitigations enabled by default in Windows operating system | 7 | 7 |
| Mitigations enabled by default in product | 60 | 0 |
| Mitigations off by default requiring manual configuration | 0 | 32 |
| Ransomware detection with automatic document rollback | Fully provided | Partially provided |
| Remote ransomware blocking and rollback | Fully provided | Not provided |
| Feature parity across Windows, macOS, and Linux | Partially provided | Partially provided |
| Management, Investigation, and Remediation |
| Single management console for managing and reporting | Fully provided | Not provided |
| Alert triage and assistance | Fully provided | Fully provided |
| Extensive threat-hunting and investigation capabilities | Fully provided | Fully provided |
| Suitable for customers without an in-house SOC | Fully provided | Partially provided |
| Suitable for large enterprise organizations with a full in-house SOC | Fully provided | Fully provided |
| Threat Hunting and Response |
| Endpoint detection and response (EDR) functionality | Fully provided | Fully provided (E5 required) |
| Integrated extended detection and response (XDR) enables analysts to hunt for and respond to threats across your environment, correlate information, and pivot between endpoint, server, network, mobile, email, public cloud, and Microsoft 365 data | Fully provided | Fully provided (E5 required) |
| MDR service provides 24/7 threat hunting, detection, and unlimited remediation to organizations of all sizes, with support available over the phone or through email | Fully provided | Fully provided |
| Incident reponse included in top MDR tier | Fully provided (Optional IR Retainer for lower MDR tiers) | Not provided |
| Integration with third-party security controls to leverage your existing security investments and provide full visibility into your environment and detections and alerts to your team and the MDR team | Fully provided | Fully provided (Requires additional purchase and does not apply to MDR) |
| Encrypted network traffic analysis (NDR) | Fully provided | Not provided |