Microsoft Defender XDR
General

Enriching Defender Experts MDR with third-party network signals

In brief

The capability is deprecated effective September 1, 2026, closed to new enablement, and existing coverage ends at the organization’s next renewal. Microsoft Defender Experts MDR Plan 2 is the stated replacement.

What Defender admins need to know

Organizations using enrichment should review their next renewal and plan a transition to MDR Plan 2 to maintain coverage.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Enriching Defender Experts MDR with third-party network signals

Microsoft Defender Experts lets you incorporate third-party network signals from Palo Alto Networks, Fortinet, and Zscaler for enrichment. By enriching Microsoft Defender incidents with these network signals, our security analysts not only gain a more comprehensive view of an attack's path that allows for faster and more thorough detection and response, they could also provide you with a more holistic view of the threat in your environment.

This enrichment has the following benefits:

  • Faster response: Automate and streamline response actions across different security platforms.
  1. Response: Once Defender Experts confirmed malicious access, they initiated a coordinated response across identity, network, and device domains. They revoked active tokens, isolated affected devices, and hardened mobile policy configurations to enforce Conditional Access more strictly.

Ingesting third-party network signals for enrichment

This capability is closed to new enablement. If you're a Microsoft Defender customer, reach out to your Security Delivery Expert if you're interested in enabling the third-party network signal enrichment.enrichment is already enabled for your organization, reach out to your Security Delivery Expert with questions about your existing coverage.

Prerequisites

Do Defender Experts analysts investigate alerts generated by third-party network products?

TheNot as part of network signal enrichment. Enrichment coverage is only for network signal use and doesn't include the triage or investigation of incidents and alerts generated by third-party network solutions. Defender Experts MDR Plan 2 does include triage and investigation of approved third-party and multicloud sources. Learn more about the Defender Experts MDR plans.

We initiate investigations with Microsoft Defender and Microsoft Defender for SeversServers incidents. Upon joining a network signal with these incidents, we conduct thorough investigations on the network alerts or events that are related to the threat. Incorporating these related network signals allows us to present a more comprehensive attack chain to our customers.

What is the pricing for third-party network signal enrichment