Microsoft Defender XDR
Fundamentals

Defender Experts Overview

In brief

The overview now states that Plan 2 extends expert triage and investigation to supported third-party sources ingested through Microsoft Sentinel, in addition to Microsoft Defender workloads.

What Defender admins need to know

Administrators can use the updated plan description when assessing coverage for third-party data; no action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Service What it does Coverage
Defender Experts MDR Managed extended detection and response Microsoft Defender environmentworkloads, and supported third-party sources through Microsoft Sentinel
Defender Experts Hunting Proactive threat hunting Endpoints, Microsoft 365, cloud apps, identity, and servers
Defender Experts for Servers Managed detection and response for servers Azure, AWS, and GCP via Defender for Cloud
Defender Experts Threat Intelligence Curated threat briefings and proactive threat alerts Your industry, geography, and environment

Microsoft Defender Experts MDR is a managed extended detection and response service that helps your SOC focus and accurately respond to incidents that matter. It provides coverage for customers who use Microsoft Defender services, including Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Entra ID.

The service is available in two plans. Plan 1 covers your Microsoft Defender workloads. Plan 2 includes everything in Plan 1 and extends expert triage and investigation to supported third-party sources that you ingest through Microsoft Sentinel.

Key capabilities:

  • Focus on incidents that matter – Experts prioritize incidents and alerts, alleviate alert fatigue, and drive SOC efficiency for your team.