Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeGlossaryEndpoint Detection and Response (EDR)
Glossary

Endpoint Detection and Response (EDR)

Endpoint detection and response (EDR) is software that records activity on computers and servers, detects attacker behavior and isolates a device remotely.

Definition

What is Endpoint Detection and Response?

Endpoint detection and response (EDR) is a category of security software installed on laptops, desktops and servers that continuously records what happens on the device, analyzes that record for signs of attack, and gives a responder tools to investigate and contain the machine from a distance. It grew out of the limits of antivirus, which checks files against known signatures. EDR watches behavior instead: a Word document spawning PowerShell, or a process encrypting thousands of files in a minute.

The agent on each endpoint collects process launches, network connections, file changes, registry edits and user logins, then sends that telemetry to a cloud console. Detection logic, much of it built on the MITRE ATT&CK catalog of attacker techniques, scores the activity and raises alerts. A responder can then open a timeline of the incident, see the full chain from the phishing attachment to the malicious process, and act: isolate the device so it can only talk to the console, stop the process, quarantine the file, or run a live investigation on the machine. Microsoft Defender for Endpoint and Defender for Business are the EDR products most small businesses already license through Microsoft 365.

For a small business EDR matters because modern ransomware and credential theft do not look like a virus. They use legitimate tools already on the computer, so a signature scanner sees nothing. EDR is also the raw material for MDR: without an EDR agent on every device there is nothing for a security team to monitor. Cyber insurers now ask specifically whether EDR is deployed on all endpoints.

NetSys deploys Microsoft Defender for Endpoint or Defender for Business on every managed device through Intune, tunes the policies, and monitors the alerts as part of its managed detection and response service. The console is watched 24/7 by NetSys engineers, and the same team handles containment and cleanup.

Why it matters for a small business

The computers your staff use every day are where attacks start, usually with a link someone clicked. Traditional antivirus catches the crude attempts and misses the ones that use built-in Windows tools. EDR sees those, and it lets a responder cut an infected laptop off from the network within minutes instead of driving to the office. If you carry cyber insurance, expect the application to ask whether EDR is on every device; if you do not have it, that answer can cost you coverage.

Common Questions

Endpoint Detection and Response (EDR): FAQs

Is EDR the same as antivirus?

No. Antivirus compares files against signatures of known malware and blocks matches. EDR records behavior on the device, detects patterns that indicate an attack even when no known malware is involved, and gives responders remote tools to isolate and clean the machine. Most EDR products include antivirus as one component, so a business that deploys EDR does not need a separate antivirus product. Microsoft Defender for Endpoint is an example: it includes next-generation antivirus, EDR and vulnerability data in one agent.

Does Microsoft 365 Business Premium include EDR?

Yes. Microsoft 365 Business Premium includes Defender for Business, which provides EDR for Windows, macOS, iOS and Android devices, with automated investigation and response. Business Standard and Business Basic do not include it. Defender for Business must be deployed and configured; the license alone does nothing until the agent is onboarded on each device and policies are set. NetSys handles that onboarding through Intune as part of its managed service.

Do we need EDR on servers too?

Yes, and arguably more than on laptops. Servers hold the file shares, databases and backups that ransomware targets, and attackers often move to them after gaining a foothold on a workstation. Defender for Endpoint supports Windows Server and Linux, and Defender for Business covers servers through an add-on license. Leaving servers out because they sit in a locked room is a common gap; the attacker reaches them over the network, not through the door.

Reading this because of a questionnaire or a renewal?

Get the controls, not just the definition.

A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.