Microsoft 365 Defender · Enterprise security
A managed response experience inside the Microsoft 365 Defender portal, connecting Microsoft's Defender Experts with customer SOC teams around contextual investigations and actionable tasks, reducing time-to-action on critical enterprise threats.
The problem: Microsoft's Defender Experts investigate threats on customers' behalf. But their findings left the product as emails and reports. Customer SOC teams lost time re-establishing context on exactly the incidents where minutes matter.
My role: end-to-end product designer for both sides of the experience. The Microsoft analyst who drafts a guided response mid-investigation, and the customer SOC analyst who acts on it inside the incident view. Partnered with PM, engineering, research, and the Defender Experts team.
One structure, two audiences. The format analysts author in is exactly what customers consume, so nothing is lost in translation.
The task card as the atomic unit. Plain-language description, status life cycle, one-click actions where possible, manual overrides for work done outside the portal.
Response lives inside the incident. Not a separate destination, so SOC analysts act with full context instead of switching tools at 2 a.m.
What research changed: the investigation summary moved to the top (analysts wanted to read it before acting), incident-list wayfinding was redesigned after the "Defender Experts" tag failed, and low-guidance actions gained deeper integration points.
Designed within Fluent to Microsoft's accessibility standards. Keyboard-first flows and screen-reader-legible task states, because SOC tooling is used under pressure, in every ability profile.
The authoring side: how a Defender Expert assembles evidence mid-investigation and drafts a guided response. For a single device, multiple devices, files, indicators and text-only tasks. Through to publishing.
The consumption side: task card anatomy and life cycle, the incident queue and side panel, and the action flows. Isolating a device, quarantining a file, remediating multiple instances.
Concept validation with 8 security analysts (Defender and non-Defender users), what worked, what didn't, the iteration that followed, and the impact on time-to-action.