Microsoft Defender XDR
General

Before you begin using Defender Experts MDR

In brief

The documentation adds Plan 2 prerequisites covering endpoint, email, identity, cloud workload protection, Sentinel ingestion and connectivity, access permissions, 90-day retention, and UEBA. It also updates data storage, retention, deletion, and GCC availability details.

What Defender admins need to know

Administrators onboarding or operating Plan 2 must verify that all listed security products, Sentinel configuration, permissions, retention, and UEBA requirements are met, and should review the updated data residency and retention terms.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Before you begin using Defender Experts MDR

Learn more about Microsoft's commercial licensing terms.

Access requirementsPlan 2 prerequisites

Work with your Commercial Executive to transact the Defender Experts MDR Plan 2 operates on the telemetry you collect in Microsoft Sentinel, so it has onboarding prerequisites and baseline criteria in addition to the requirements described earlier in this article. These prerequisites let the service detect and investigate reliably in the sources you want covered.

Plan 2 requires the following:

  • A supported endpoint detection and response (EDR) product deployed on all endpoints.
  • Supported email security and identity protection products deployed for all users. A basic identity and access management solution isn't sufficient. Assets without these products are considered uncovered.
  • A supported cloud-native application protection platform (CNAPP) or cloud workload protection platform (CWPP) solution deployed for any cloud or on-premises infrastructure to be monitored.
  • Data ingested through the built-in Microsoft Sentinel connectors into the standard Microsoft Sentinel tables.
  • Appropriate access granted to Defender Experts for Servers SKUs.the Microsoft Sentinel workspaces to be monitored.
  • Microsoft Sentinel connected to the Microsoft Defender portal. For more information, see Connect Microsoft Sentinel to the Microsoft Defender portal.
  • Baseline data configuration, including a 90-day Log Analytics retention period for data sources that require real-time detection and monitoring.
  • User and Entity Behavior Analytics (UEBA) enabled for supported data sources.

For the non-Microsoft sources that Plan 2 covers, see Third-party source coverage for Plan 2.

Access requirements

Defender Experts MDR and Defender Experts for Servers request for certain roles and permissions for you to fully access the service capabilities. Learn more

Data collection, usage, and retention

  • All data used for hunting from existing Defender services stayscontinues to reside in yourthe customer's original Microsoft Defender service storage location. Learn more.

  • Data generated for Defender Experts reports and other experiences in the Defender portal is stored in the customer's Microsoft Defender service storage location.
  • Defender Experts MDR Plan 1 for Gov operational data, such as case tickets and analyst notes, is generated and stored in Microsoft data centers in the US region for GCC customers.
  • Defender Experts MDR operational data, such as case tickets and analyst notes, areis generated and stored in a Microsoft data centercenters in the European UnionEU region for customers whose Defender data is in scope of EUEuropean Union data boundaryboundary.
  • Defender Experts MDR operational data, such as case tickets and analyst notes, is generated and stored in the US regionMicrosoft data centers worldwide for other customers, irrespective of thetheir Microsoft Defender service storage location. Data generated for the reporting dashboard is stored in your Microsoft Defender service storage location.
  • Reporting data and operational data arewill be retained for a grace period of no more than 90 days after youra customer's subscription expires. If you terminate yourthe customer terminates their subscription, data iswill be deleted within 30 days.

  • Microsoft experts hunt over advanced hunting logs in Microsoft Defender advanced hunting tables. The data in these tables dependdepends on the set of Defender services you enable (for example, Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, and Microsoft Entra ID). Experts also use a large set of internal threat intelligence data to inform their hunting and automation.

Availability

Defender Experts MDR follows Microsoft 365 and Office 365 international availability. The service is available for customers in our commercial public cloud. In addition, the Defender Experts MDR Plan 1 for Gov service is available to GCC customers who do not require FedRAMP authorization, such as many State & Local Government (SLG) customers. Defender Experts MDR is not available in government cloud (i.e. to GCC-H, DoD, etc. customers) and sovereign cloud at this time.

Language