← Back to home Onboarding · Adoption · Behavior-driven UX

Defender Navigation Onboarding

Helping users discover and adopt Search and Favorites (pinning) in Defender's new navigation. The features already worked — adoption didn't. The answer was a behavior-driven onboarding that surfaces value at the moment of need, instead of another tour nobody reads.

Role
Product Designer — concept & interaction
Team
PM · Engineering · Research
Surface
Defender global navigation
Focus
Feature discovery & adoption

What this case demonstratesHorizontal product work that turns adoption data into focused action.

This case combines product discovery, behavioral data, UX strategy, and hands-on prototyping across a shared enterprise surface. I treated onboarding as a product problem to diagnose, not a tour to decorate.

Project type

Horizontal adoption strategy

A cross-product onboarding and discovery effort for global navigation capabilities used across Microsoft Defender experiences.

My approach

Triangulate, then prioritize

I brought together customer insight, usage-data exploration, and competitive analysis, then owned UX requirements alongside PM and mapped the solution space.

Why hire me for this

I connect strategy to testable product

I can find the behavioral leverage point, align horizontal stakeholders, and use rapid prototyping and vibe coding to compare ideas before teams invest deeply.

Process: Customer insight → data exploration → competitive analysis → UX/PM requirement ownership → solution mapping → prioritization → vibe-coded experiments and rapid prototypes → focused adoption strategy.

ProblemStrong features, almost no discovery.

The new navigation shipped two genuinely useful capabilities — global Search and Favorites (pinning). Both convert well when used. The catch: almost nobody found them. When the problem is "nobody finds it," the fix is surfacing, not redesign.

4.6%Favorites adoption across ~671K new-navigation tenants — 1.6% at the user level
1 in 3Search results that convert to a click (~32%) — the feature already delivers value
<1% → 2×Adoption jumps from under 1% to double digits once users explore more of the product

InsightAdoption is a behavior, not a demographic.

Pinning turned out to be a power-user behavior: the more distinct pages someone visits, the more likely they are to pin. Casual users (1–2 pages) almost never adopt; exploratory users adopt many times more. That inflection is where onboarding should intervene.

Interactive · hover the behavior bands

Casual

1–2 pages · pins almost never (~0.5%).

Exploring

3–10 pages · adoption climbs (8.5–14.2%). The nudge fires here.

Power user

10+ pages · pins the most (17.3–35.4%).

Rarely pinsAlways pins

Adoption is a behavior. The more distinct pages someone visits, the more likely they pin — so onboarding intervenes at the 3-page inflection, exactly where adoption leaves the floor.

  • Low — 1–2 pages: ~0.5% adoption
  • Moderate — 3–10 pages: 8.5–14.2% adoption
  • High — 10+ pages: 17.3–35.4% adoption

Design decision. Trigger the active nudge once a user crosses 3 distinct pages — the exact point where adoption leaves the floor.

PrincipleEvidence-based, Jobs-to-be-Done onboarding.

Onboarding should fire on observed behavior, not assumptions, and frame everything around what the user is trying to get done — activities, not RBAC roles. Roles vary across organizations and add ambiguity; intent doesn't. It also stays deliberately lightweight: no Copilot chats, access validation, upsell, or background processes in the flow.

Design decisionsPromote the value — don't rebuild it.

  • Promote, don't rework. The features already convert; lead with "here's how to pin and search," not new UI.
  • Value before effort. Silently pre-seed a conservative set of default Favorites mapped to the user's job, so the payoff exists with zero effort — inverting the discovery problem.
  • Ambient discoverability. A hover-visible pin star on the real page, not a modal tour.
  • One just-in-time hint. A single teaching bubble bound to the actual page at the 2nd–3rd visit ("Pin Devices?"), that disappears after use.
  • Surface Search passively for everyone — it already converts ~1 in 3.

Micro-interactionsTeaching inside the real product.

Instead of a modal tour, discovery lives in context — a hover-visible pin star, a single just-in-time hint, and lightweight prompts that surface only when behavior warrants it.

  • Just-in-time pin hintSurfaces on a frequently visited page — pin it in one click.
  • Pin from searchPin a search result straight into Favorites.
  • Organize by what you doA nudge to reorganize favorites when workflows shift.

Core flowIntent in, personalized navigation out.

The setup asks what you're trying to get done, maps that to the right pages behind the scenes, and pre-pins them — so a personalized navigation is waiting on first load.

Core flow · Intent → Personalized nav
01 · Intent"What are you trying to get done?"
02 · MappingActivity → relevant pages, invisible to the user
03 · PinningPages become starting Favorites, ready on first load

Intent in, personalized navigation out. "Let's set up Defender, your way" — a free-text or activity-based setup that pre-pins a starting set of pages, so the payoff exists before any effort.

Six triggersBehavior-driven, never interruptive.

Every teaching moment is bound to an observed behavior — and each can be tuned or switched off. Six triggers span the journey from first visit to power use:

  • 1 · Navigation explorationA one-line teaching bubble on the pin star that disappears after first use.
  • 2 · Successful searchAn animated pin pulse on results, with a toast after repeated searches.
  • 3 · High-frequency pageA recommendation to pin pages the user visits often.
  • 4 · Workflow misalignmentA nudge to customize navigation around what they actually do.
  • 5 · Pin churnAn offer to help organize favorites when pins change frequently.
  • 6 · Empty favoritesA subtle personalization hint when nothing is pinned yet.

Constraints & guardrailsKeep it honest and reversible.

  • Ten-pin cap. Favorites max out at 10; overflow affects visibility — and ~11.8K users already hit that ceiling, so seeding has to be careful.
  • Removable by design. Seeded favorites must be visible and easily removable, validated by a default-favorite retention metric.
  • Accessibility & privacy respected throughout.
  • Performance wasn't the lever. Median navigation load is sub-second; onboarding ships on top of it.

Outcome & learningSurface value at the moment of need.

↑ SearchMore users discovering and using global search
↑ PinningMore Favorites adoption and customized navigation
↑ TimeFaster time-to-destination, fewer roundabout menu trips

The lesson was clear: when a feature works but nobody finds it, the answer isn't a redesign — it's surfacing at the moment of need. Pre-seed value, keep discovery ambient, and teach once, in context. The MVP stays tight: default favorites, passive search discovery, ambient pinning discovery, and a single contextual teaching moment.

One-line takeawaySurface, don't redesign.

When a feature works but nobody finds it, don't redesign it — surface it at the moment of need. Pre-seed value, keep discovery ambient, and teach once, in context.

Next case study

Advanced Hunting →