Microsoft Defender XDR
Fundamentals

What is Microsoft Defender Experts MDR?

In brief

The page now explains that Plan 1 covers Microsoft Defender workloads, while Plan 2 includes Plan 1 and extends expert-led detection, investigation, response, and threat hunting to selected non-Microsoft telemetry collected in Microsoft Sentinel.

What Defender admins need to know

Review the updated plan descriptions to determine which plan matches your organization's Microsoft and non-Microsoft security telemetry.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

What is Microsoft Defender Experts MDRMDR?

Applies to:

  • Microsoft DefenderMicrosoft Defender Experts MDR Plan 1
  • Microsoft Defender Experts MDR Plan 2

Microsoft Defender Experts MDR is a managed detection and response service. Microsoft security analysts manage your incident queue around the clock, triage and investigate incidents on your behalf, and either take action or guide your team through the response. The service augments your security operations center (SOC) rather than replacing it, so your team spends less time on alert volume and more time on the threats that affect your organization.

Defender Experts MDR is available in two plans. Plan 1 delivers managed detection and response for your Microsoft Defender workloads. Plan 2 includes everything in Plan 1 and extends the same expert-led detection, investigation, response, and threat hunting to selected non-Microsoft telemetry that you collect in Microsoft Sentinel.

Which plan is right for you

MicrosoftBoth plans deliver the same expert-led service model. They differ in the telemetry that Defender Experts MDRanalysts triage and investigate on your behalf.

  • Plan 1 is adelivers managed extended detection and response service that helps your security operations centers (SOCs) focus and accurately respond to incidents that matter. It provides extended detection and response for customers who use Microsoft Defender services: Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Entra ID.

    Defender Experts MDR augments your SOC by combining automation and Microsoft's security analyst expertise. This combination helps you detect and respond to threats with confidence and improve your security posture. With deep product expertise powered by threat intelligence, we're uniquely positioned to help you:

    • Focus on incidents that matter - Our experts prioritize incidents and alerts that matter, alleviate alert fatigue, and drive SOC efficiency for your team
    • Manage response your way - Our experts provide detailed, step-by-step, actionable guidance to respond to incidents with the option to act on your behalf as needed
    • Access expertise when you need it - Extend your team's capacity with access to Defender Experts for assistance on an investigation
    • Stay ahead of emerging threats - Our experts proactively hunt for emerging threats in your environment, informed by unparalleled threat intelligence and visibility

    Apart from the constantly updated research and intelligence tailored for the threats currently seen across the various Microsoft Defender signals, you also receive managed response from our security analysts and, if your service includes it, support from Microsoft's security-focused Security Delivery Experts (SDXs). This service lets you enjoy the following capabilities:

    • Managed detection and response - Expert analysts manage your Microsoft Defender incident queue and handle triage and investigation on your behalf; they partner with you and your team to take action or guide you to respond to incidentsworkloads. It's the choice for organizations whose security operations center primarily works inside Microsoft Defender.
    • Proactive threat huntingPlan 2 - Microsoft Defender Experts Huntingincludes everything in Plan 1 and extends the same expert-led service to selected non-Microsoft security telemetry that you collect in Microsoft Sentinel. It's designed for organizations that need visibility into both their Microsoft and non-Microsoft environments. Plan 2 requires Microsoft Sentinel.

    Defender Experts MDR Plan 1

    Plan 1 focuses on your Microsoft Defender telemetry. Expert analysts detect threats using Microsoft Defender security signals, manage your incident queue, and handle triage, investigation, and response guidance for your Microsoft Defender workloads.

    Plan 1 includes these capabilities:

    • Managed detection and response – Expert analysts manage your Microsoft Defender incident queue and handle triage and investigation on your behalf. They partner with you to take action or guide you through the response.
    • Proactive threat huntingMicrosoft Defender Experts Hunting is built in to extend your team's threat hunting capabilities and prioritize significant threatsthreats.
    • Ask Defender Experts - Select Ask Defender Experts in the Microsoft Defender portal to get expert advice about threats your organization is facing. You can ask for help on a specific incident, or about notifications related to a nation-state actor,actor or attack vector-related notificationsvector.
    • Live dashboards and reports - Transparent– Get a transparent, noise-free view of our operationsthe work done on your behalf and noise free, actionable view into what matters for you coupledbehalf, along with detailed analyticsanalytics.
    • Proactive check-ins for continuous security improvements - Periodic check-ins– Meet periodically with your named service delivery team to guide your Defender Experts MDR experience and improve your security postureposture.

    Plan 1 is the service previously offered as Defender Experts for XDR, which was later renamed Defender Experts MDR. The service is the same; only the name changed.

    For the Microsoft Defender products that Plan 1 covers and the licensing each one requires, see Service coverage prerequisites.

    Defender Experts MDR Plan 2

    Plan 2 includes everything in Plan 1 and maximizeextends the benefitssame expert-led detection, investigation, response, and threat hunting to selected non-Microsoft telemetry that you collect in Microsoft Sentinel. Microsoft Sentinel is a prerequisite for Plan 2.

    Attackers rarely stay within one technology stack. An investigation might begin on a Microsoft-secured endpoint, move through a non-Microsoft identity provider, reach a cloud platform, and generate events on a non-Microsoft firewall. Microsoft Sentinel provides the platform for collecting and correlating that telemetry, and Defender Experts delivers the expert-led investigation and response for it.

    In addition to everything in Plan 1, Plan 2 adds these capabilities:

    • Detection and investigation of this product suite. selected third-party telemetry – Expert analysts monitor alerts, and triage and investigate incidents, for your Microsoft Defender workloads and for supported third-party workloads in Microsoft Sentinel.
    • Expert-authored Microsoft Sentinel content – Defender Experts create analytics rules, automation rules, and security orchestration, automation, and response (SOAR) playbooks to detect, triage, and respond to suspicious activity, and apply suppression to reduce noise. This includes correlation detections that chain signals from identity, endpoint, cloud, network, and email to surface end-to-end attack scenarios rather than isolated alerts.
    • Response guidance for supported third-party products – For Microsoft Defender workloads, Defender Experts take action or provide guided response. For supported third-party products, Defender Experts provide guidance on the response actions to take.
    • Microsoft Sentinel health monitoring – Defender Experts monitor the health of built-in connectors and the Microsoft Sentinel content they deploy, and notify you when corrective action is needed to keep detection and monitoring operational.
    • Microsoft Sentinel cost optimization guidance – Defender Experts evaluate and advise on cost optimization measures, such as retention policies, data source selection, data collection rules, and built-in connectors, without sacrificing telemetry visibility.
    • A dedicated security delivery expert – Defender Experts assigns a security delivery expert who manages the overall service relationship, leads environment discovery, owns escalations, and delivers regular reporting and briefings.

    Reporting for Plan 2 is delivered through the existing Defender Experts reports and includes third-party hunting and operations data alongside your Microsoft Defender data.

    Next step

    Because Plan 2 operates on Microsoft Sentinel data, it requires a Microsoft Sentinel workspace and supporting configuration for the sources you want covered. For those requirements, see Before you begin using Defender Experts MDR.

    Third-party source coverage for Plan 2

    In addition to the Microsoft Defender coverage included with Plan 1, Plan 2 covers these non-Microsoft sources:

    Category Source
    Identity protection Okta
    Email security Proofpoint TAP
    Cloud infrastructure security AWS CloudTrail
    Cloud infrastructure security AWS GuardDuty
    Network security and firewalls Palo Alto PAN-OS next-generation firewall
    Network security and firewalls Cisco ASA/Meraki
    Network security and firewalls Zscaler ZIA/ZPA
    Network security and firewalls Fortinet FortiGate

    Defender Experts evaluate adding new sources case by case. Changes to scope are reflected in this documentation as they become available.

    Compare Plan 1 and Plan 2

    Use this comparison to see what each plan covers and where the two plans differ.

    Capability Plan 1 Plan 2
    Coverage
    Microsoft Defender workloads Included Included
    Third-party sources through Microsoft Sentinel Not included Included for supported sources
    Managed operations
    Alert monitoring Microsoft Defender workloads Microsoft Defender workloads and supported third-party workloads
    Incident triage and investigation Microsoft Defender workloads Microsoft Defender workloads and supported third-party workloads
    Managed response Microsoft Defender workloads: action or guided response Microsoft Defender workloads: action or guided response. Supported third-party workloads: response guidance
    Proactive threat hunting Included Included
    Ask Defender Experts Included Included
    Live dashboards and reports Included Included
    Microsoft Sentinel
    Microsoft Sentinel required No Yes
    Expert-authored Microsoft Sentinel content Not included Included
    Connector health monitoring and tuning guidance Not included Included
    Cost optimization guidance Not included Included
    Service engagement
    Onboarding Included Included
    Proactive check-ins Included Included
    Security delivery expert For qualified customers Included

    Service boundaries

    Knowing what the service doesn't do is as important as knowing what it does.

    Plan 2 isn't a managed security information and event management (SIEM) service. Defender Experts operates on the supported data in your Microsoft Sentinel workspace and on the detection content that Defender Experts authors. You continue to own your Microsoft Sentinel deployment, including:

    • Deploying and maintaining data connectors.
    • Building and running custom ingestion pipelines.
    • Migrating content from another SIEM.
    • Creating and maintaining your own analytics rules and other content.
    • Managing data quality, retention, permissions, and ingestion costs.

    Neither plan covers Microsoft Defender for Cloud workloads. Cloud workloads such as storage, containers, and databases aren't included in either plan. Plan 2 coverage of multicloud telemetry through Microsoft Sentinel is separate from cloud workload protection. Managed detection and response for hybrid and multicloud servers is available separately through Microsoft Defender Experts for Servers.

    Neither plan is an incident response engagement. Defender Experts MDR doesn't provide incident response services for an active compromise. For that, see Microsoft Defender Experts Cybersecurity Incident Response.

    Related content

    [!INCLUDE Microsoft Defender XDR rebranding]