11.3 Reviewing Defender XDR Reports
Key Takeaways
- The Microsoft Defender portal Reports section provides dashboards covering threat protection summary, device health, threat analytics, and workload-specific summaries for email, endpoint, identity, and cloud apps
- Threat analytics is a feed of emerging threats and campaigns with associated detections, affected assets, and mitigation recommendations specific to the organization
- Device health and health monitoring reports surface devices that are not reporting, have stale signatures, or are in an impaired sensor state so administrators can remediate coverage gaps
- Reports are the primary tool for identifying trends, recurring issues, and posture gaps such as unremediated alerts and emails with malware getting through
- Microsoft Defender Experts is an optional managed hunting service; it is not required for Defender XDR reporting and is licensed separately
Quick Answer: The Reports section of the Microsoft Defender portal gives MS-102 administrators dashboards that summarize threat protection status, device health, threat analytics, and per-workload activity. Use reports to spot trends, recurring issues, and coverage gaps — and use threat analytics to track emerging threats that are actively relevant to your organization.
What Lives in the Reports Section
The Microsoft Defender portal consolidates reporting from every Defender workload under Reports > Analytics (and related per-workload dashboards). The exact navigation labels shift as Microsoft updates the portal, but the core dashboards the exam expects you to know are stable:
- Threat protection summary — an at-a-glance view of alerts, incidents, and active threats across the tenant, typically with trend lines so you can see whether volume is rising or falling.
- Device health / health monitoring — which devices are reporting to Defender for Endpoint, which have impaired or passive sensor states, which have stale or disabled antivirus definitions, and which are not onboarded at all.
- Threat analytics — a curated feed of emerging threats and campaigns, each with a profile, affected assets in your tenant, detections, and mitigation recommendations.
- Email protection reports — mail flow, malware and phishing detections, spam verdicts, and threat delivery status from Defender for Office 365.
- Endpoint reports — malware detections, remediation status, and endpoint detection and response (EDR) alerts.
- Identity reports — risky sign-ins, compromised credentials, and Defender for Identity detections.
- Cloud app reports — app usage, risky OAuth apps, and Defender for Cloud Apps policy alerts.
Using Reports to Find Gaps
Reports are not just for status updates — they are how an MS-102 administrator finds problems that alerts alone won't surface. Three gap patterns to watch for:
1. Devices not reporting or impaired
The device health dashboard lists devices whose sensor is impaired, offline, or whose definitions are stale. A device that stopped reporting to Defender for Endpoint is a silent coverage gap — it will not generate alerts even if it is compromised. Remediation is to re-onboard or fix the sensor, not to wait for an alert.
2. Emails with malware getting through
The email protection reports break delivery down by verdict. If the count of messages delivered to the inbox with a malware or phishing verdict is non-zero, mail-flow rules or allowed/safe-list configurations are letting threats through. That is a configuration problem, not a one-off alert, and it is only visible in the report.
3. Unremediated or recurring alerts
The threat protection summary shows whether alert and incident volume is trending up, and whether the team is keeping up with resolution. A growing backlog of unremediated alerts indicates a staffing, triage, or detection-tuning problem — not a single attacker.
Threat Analytics
Threat analytics is the most important reporting feature to understand for the exam. It is a feed of emerging threats and campaigns, each published as a report with:
- A profile of the threat actor or campaign, including targeted industries and regions.
- MITRE ATT&CK techniques observed in the campaign.
- Detections — whether Defender XDR products in your tenant have observed indicators of this threat.
- Affected assets — a list of devices, users, or mailboxes in your organization that have triggered detections tied to this threat.
- Mitigation recommendations — specific configuration or hunting guidance to reduce exposure.
Because threat analytics entries are scoped to your tenant's telemetry, they are the fastest way to answer the question "are we exposed to this emerging threat right now?" Administrators should review threat analytics regularly and whenever a major new campaign is published.
Microsoft Defender Experts (optional)
Microsoft Defender Experts is a managed hunting service that supplements in-house teams with Microsoft threat hunters who proactively hunt in the tenant's telemetry and notify the customer of threats they find. It is licensed separately and is not required for Defender XDR reporting. For the MS-102 exam, know that Defender Experts exists as an optional layer above the built-in reports — the reports themselves are available to every Defender XDR licensed tenant.
Turning Reports Into Action
A repeatable reporting cadence for an MS-102 administrator:
- Daily — review the threat protection summary and any new threat analytics entries with org detections.
- Weekly — review device health for impaired sensors and endpoint coverage; review email protection for verdict trends.
- Monthly — review identity and cloud app reports for risky OAuth apps, stale access, and detection tuning opportunities; reconcile posture trends with the Secure Score and Exposure Management initiatives.
This cadence is how "review and respond to issues identified in Microsoft Defender XDR reports" is operationalized — and it is the behavior the exam is validating.
What is the purpose of the threat analytics feed in the Microsoft Defender portal?
An MS-102 administrator notices the device health report lists several devices whose Defender for Endpoint sensor is impaired. What is the correct interpretation and response?
Which statement about Microsoft Defender Experts is correct for the MS-102 exam?