Defender Experts Overview
In brief
The overview now states that Plan 2 extends expert triage and investigation to supported third-party sources ingested through Microsoft Sentinel, in addition to Microsoft Defender workloads.
What Defender admins need to know
Administrators can use the updated plan description when assessing coverage for third-party data; no action is specified.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
| Service | What it does | Coverage |
|---|---|---|
| Defender Experts MDR | Managed extended detection and response | Microsoft Defender |
| Defender Experts Hunting | Proactive threat hunting | Endpoints, Microsoft 365, cloud apps, identity, and servers |
| Defender Experts for Servers | Managed detection and response for servers | Azure, AWS, and GCP via Defender for Cloud |
| Defender Experts Threat Intelligence | Curated threat briefings and proactive threat alerts | Your industry, geography, and environment |
Microsoft Defender Experts MDR is a managed extended detection and response service that helps your SOC focus and accurately respond to incidents that matter. It provides coverage for customers who use Microsoft Defender services, including Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Entra ID.
The service is available in two plans. Plan 1 covers your Microsoft Defender workloads. Plan 2 includes everything in Plan 1 and extends expert triage and investigation to supported third-party sources that you ingest through Microsoft Sentinel.
Key capabilities:
- Focus on incidents that matter – Experts prioritize incidents and alerts, alleviate alert fatigue, and drive SOC efficiency for your team.
@@ -13,8 +13,8 @@ ms.topic: overview ms.custom: - cx-ti - cx-dex-- msecd-doc-authoring-1012-ms.date: 06/29/2026+- msecd-doc-authoring-1018+ms.date: 07/27/2026 ai-usage: ai-assisted --- @@ -26,7 +26,7 @@ The suite offers the following services tailored to different security needs: | Service | What it does | Coverage | |---|---|---|-| [Defender Experts MDR](#defender-experts-mdr) | Managed extended detection and response | Microsoft Defender environment |+| [Defender Experts MDR](#defender-experts-mdr) | Managed extended detection and response | Microsoft Defender workloads, and supported third-party sources through Microsoft Sentinel | | [Defender Experts Hunting](#defender-experts-hunting) | Proactive threat hunting | Endpoints, Microsoft 365, cloud apps, identity, and servers | | [Defender Experts for Servers](#defender-experts-for-servers) | Managed detection and response for servers | Azure, AWS, and GCP via Defender for Cloud | | [Defender Experts Threat Intelligence](#defender-experts-threat-intelligence) | Curated threat briefings and proactive threat alerts | Your industry, geography, and environment |@@ -39,6 +39,8 @@ The suite offers the following services tailored to different security needs: **Microsoft Defender Experts MDR** is a managed extended detection and response service that helps your SOC focus and accurately respond to incidents that matter. It provides coverage for customers who use Microsoft Defender services, including Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Entra ID. +The service is available in two plans. Plan 1 covers your Microsoft Defender workloads. Plan 2 includes everything in Plan 1 and extends expert triage and investigation to supported third-party sources that you ingest through Microsoft Sentinel.+ Key capabilities: - **Focus on incidents that matter** – Experts prioritize incidents and alerts, alleviate alert fatigue, and drive SOC efficiency for your team. 