SOAR / MDR / Microsoft

Defender Experts MDR

Defender Experts MDR is Microsoft-staffed managed detection and response that augments a customer security operations center. It was renamed from Defender Experts for XDR. Neither plan is an incident-response engagement, and Plan 2 is not managed SIEM.

Managed detection and responseResearch reviewed

What you are evaluating

Plan 1 covers Microsoft Defender workloads, hunting, and Ask Experts. Plan 2 extends selected third-party sources in Microsoft Sentinel and provides response guidance for those third parties. Defender products are sold separately.

A useful evaluation context

Evaluation is for operations already living in Defender, with Plan 2 only if Sentinel is owned and in-region.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Plan 1 monitoring and hunting on Microsoft Defender workloads, plus Ask Experts.
  • Plan 2 selected third-party sources in Microsoft Sentinel with expert-authored Sentinel content.
  • Response guidance for those third-party products rather than Microsoft executing third-party containment as managed SIEM.

Where it fits in the work

  1. Onboard Defender workloads for Plan 1, and confirm Sentinel is owned and in-region before considering Plan 2.
  2. Investigate expert findings and apply guidance; customer teams still execute many third-party actions.
  3. Hand declared incidents that exceed MDR to a separate incident-response process, because neither plan is an IR engagement.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

In an authorized Defender test tenant, raise a harmless simulated phishing detection the service supports, then record acknowledge, hunt notes, and whether the experts executed or only guided the next action.

Evidence to look for

The case shows Plan coverage used, guidance versus execution, and that production mailboxes outside the test tenant were not changed.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which Defender workloads are in Plan 1, and which Defender for Cloud workloads remain out of scope?
  2. Does Plan 2 only add selected Sentinel third-party sources, not a managed SIEM service?
  3. Who declares an incident, and which IR team takes over when this MDR is not an engagement?

Names you may encounter: Defender Experts for XDR. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.