Eight providers, one set of questions, and the answers do not line up the way the marketing suggests they should. What follows is the comparison itself: where the real differences sit, which published numbers mean anything, what an E5 organisation ends up paying for twice, and how to run an evaluation that produces a decision rather than a shortlist.
The authority spectrum
Across these eight, response authority spans a genuine range, and the range is the most decision-relevant finding in this series. At one end, Microsoft’s own service defaults to investigating and handing you the action to perform, with execution enabled only if you grant an operator role you can withdraw, and with the entire audit trail landing in your own console. Next along, Expel licenses each automated action individually and attaches customer-defined exclusion lists to each, with a hard prohibition on acting against privileged accounts that cannot be configured away. Red Canary sells hands-on remediation as a separate annual purchase scoped to endpoint groups you nominate. Arctic Wolf configures it per playbook at onboarding. Huntress turns identity isolation on by default with a per-account opt-out. Critical Start executes response bidirectionally in the tools you already own, with two-person verification before a critical disposition. Palo Alto operates the platform on your behalf under a full-cycle remediation model whose boundaries are not published and should be established in writing. CrowdStrike’s analysts remediate directly within an agreed scope without waiting for approval.
None of those positions is wrong. They serve different buyers with different tolerance for delegation. What is wrong is signing one of them without knowing which one you signed, and the fact that this spectrum exists at all is not visible from any vendor’s website. Ask the question directly, get the answer written into the agreement, and make sure the person who owns your incident response has read it.
Six of these eight can act inside your tenant tonight without asking you first. You should be able to name the two that cannot.
Two structural points cut across the whole spectrum. The first is credentials: every commercial provider here reaches your tenant through an application registration holding a long-lived secret with response-grade permissions. Microsoft’s own service uses delegated privileges provisioned just in time instead. If you engage a commercial provider, that registration is a privileged identity and belongs in your privileged access governance, with an owner, a rotation schedule and a periodic scope review. Almost nobody does this. The second is reversibility: some documented actions cannot be undone, and the vendor most explicit about that in its own documentation is the one I would trust most on everything else.
Why you cannot compare the published times
Every provider publishes a number and almost none of them measure the same interval. One publishes just over seven minutes to open a ticket, which is signal to written record and says nothing about containment. One publishes thirteen minutes without defining the endpoints of the measurement. One publishes median time to contain, which is the full cycle and the only figure that answers the question buyers think they are asking. Two publish no response commitment at all. One replaces the commitment entirely with an insurance-backed warranty of up to two million dollars, and another carries a three million dollar warranty inside its top bundle.
Put those side by side in a procurement spreadsheet and you produce nonsense. The only defensible approach is to ask each provider what event starts their clock and what event stops it, to write the answer down, and to treat any number whose definition they will not give you as marketing.
One provider demonstrates that the vagueness is a choice rather than an industry constraint. Critical Start publishes a measurement that starts when an alert is ingested by their platform and stops when an analyst documents a disposition, running around the clock rather than in business hours, tiered so that the depth of commitment rises with the service level, and backed by service credits when they miss. That is a defined clock, a documented methodology and a remedy, which is what a commitment actually looks like. Service credits are a modest instrument and nobody is made whole by a month of fees during a breach, but the discipline of publishing the definition is the part that matters, because it forces the vendor to state what they do. Use it as the benchmark for everyone else, ask the same four questions, and put the answers in the contract, because a figure on a web page is not an obligation.
Incident response is a separate axis and it is frequently assumed rather than checked. One provider includes a retainer covering exactly one incident per year. One sells incident response as an entirely separate engagement. One bundles it into a suite. Two do not offer it at all, which means an incident that exceeds routine remediation sends you looking for a firm you have no relationship with, on the worst day of your year.
What an E5 organisation pays for twice
The overlap picture sorts cleanly by architecture. Microsoft’s own service produces no duplication because it operates the stack you licensed. Huntress and Expel produce almost none, because they operate that stack too. Critical Start produces almost none, on the same operate-your-stack basis. Palo Alto is the unusual case: it leaves your endpoint stack in place and displaces the layer above, so the overlap lands on Sentinel and your log retention rather than on your agents. Red Canary produces little on telemetry, though the platform side of its parent overlaps the network access capability Entra now offers. Arctic Wolf produces real duplication if you take their endpoint agent and very little if you use their Defender integration instead, which makes it a negotiable rather than fixed cost. CrowdStrike produces the maximum: their sensor duplicates Defender for Endpoint, their identity product overlaps Defender for Identity and Entra ID Protection and part of your conditional access design, their SIEM overlaps Sentinel, their data protection overlaps Purview.
Duplication is not automatically a reason to walk away. Buying a coherent single-vendor platform and accepting that you will underuse your E5 entitlement is a legitimate decision when the platform is genuinely better for your threat model. What is not legitimate is making that decision without doing the arithmetic, including the licensing you will continue to pay for and stop using.
One input to that arithmetic changed in July 2026. E5 moved to sixty dollars per user per month and the increase brought Security Copilot capacity, Intune Endpoint Privilege Management, Enterprise Application Management and Cloud PKI inside the bundle. If your cost model treats any of those as separate spend, it is now wrong, and the case for consolidating on the Microsoft stack is stronger than it was six months ago.
Where your telemetry lives when the contract ends
This is the lock-in question and the public record is thin, which is itself the finding. Microsoft’s service keeps reporting data in your own tenant, with a documented ninety day grace period after expiry and deletion within thirty days of termination. For the six commercial providers whose platforms hold your signal, retention windows and exit terms are contract matters and are not published anywhere I could verify them. The Palo Alto case is the sharpest, because the platform holding your signal is the security data platform itself rather than a vendor console standing alongside the one you own.
So put it in the contract. Ask what you get on exit, in what format, over what period, and what happens to detection history and case records. The answer determines whether changing provider in three years is an administrative task or a data loss event, and it is far easier to negotiate before signature than during a transition.
The two AI claims, separated
Every provider in this market now talks about artificial intelligence, and the word covers two entirely different propositions that should never be evaluated together.
The first is whether they help you govern your users’ AI usage. On this the field is thin. Four of the eight have nothing at all, and I have recorded that as an absence in each profile rather than letting silence imply capability. CrowdStrike blocks sensitive data reaching AI tools through endpoint enforcement. Zscaler’s platform, behind Red Canary, does it inline on the network path, which is the more complete architecture and also the one that requires platform licensing rather than a detection contract. Palo Alto sits the same way, with the inline capability belonging to the network platform rather than to the detection engagement you are contracting for. Microsoft’s own answer is neither of those and is worth knowing: an E5 tenant already has discovery of unsanctioned AI applications with risk scoring, the ability to mark them unsanctioned and enforce the block through Defender for Endpoint on managed devices, prompt-level data controls for Copilot through Purview, and network-based discovery through Entra’s secure access capability. That is more than most organisations realise they own. What it does not cover is inline inspection of arbitrary third-party AI tools on unmanaged devices or off-network traffic, which is precisely the gap the inline vendors sell into and is narrower than a demonstration makes it look.
The second claim is AI inside the provider’s own operations, and here the rule I applied throughout is simple: a mechanism, or it is marketing. CrowdStrike documents a triage system with a stated human validation gate before remediation. Red Canary documents investigation agents trained on their own case history with an analyst reviewing every alert. Arctic Wolf publishes figures for what its triage layer removed from the human queue. Those three attach mechanism. The others assert AI assistance without publishing much of substance, and I have said so rather than filling the gap. Beyond this shortlist, the trend worth watching is autonomous investigation sold as metered consumption, which converts analyst work into a per-unit charge and deserves a hard look at what happens to your bill during a bad month.
Identity is where the spread is widest
The received wisdom is that managed detection is endpoint-mature and identity-thin. That is no longer accurate and the spread across these eight is wide enough to be a primary selection criterion.
At one pole, CrowdStrike sits inline in the Entra authentication flow making live access decisions, which is depth bought at the price of a second policy plane in front of the one you built. In the middle, Huntress and Expel both built their identity response specifically for the Microsoft identity plane and both independently engineered a guard against directory synchronisation re-enabling a disabled hybrid account, which tells you that failure is real and that your own runbook probably has the same hole. Microsoft’s own service covers identity natively but its depth depends on Entra ID P2 signal being present. Arctic Wolf treats identity as a telemetry source with response hooks rather than as a discipline.
If most of your incidents start with a credential, and for most organisations they do, this axis should carry more weight in your scoring than endpoint detection quality, which is broadly comparable across the field.
How to run the evaluation
Start with your own tenant rather than with vendors. Establish what you actually collect and retain, because every provider inherits your logging gaps on day one and the difference between a well-instrumented and a poorly-instrumented engagement dwarfs the difference between any two providers on this list. That work is the subject of the build sheet that follows this article.
Then decide the architecture question before you take a single demonstration: are you buying a second stack, operators for the one you own, or a provider who leaves your sensors where they are and replaces the data platform above them. That answer eliminates most of the field immediately and turns an eight-way comparison into a shortlist of two or three.
Then ask each survivor the same questions in the same order. What may you do in my tenant without asking. What does your published number measure. Where does my telemetry live and what do I get on exit. What is your identity coverage in a hybrid estate, specifically. Is incident response included, and what is the scope cap. What of this do I already own and am I paying twice. And on AI, which of the two claims are you making, and what is the mechanism.
The provider who answers those cleanly, in writing, is telling you something about how they will behave at three in the morning. The one who deflects to a demonstration is telling you something too.
MDR
‹ Previous: [MDR 9] Palo Alto Unit 42 Managed XSIAM: Buying a Security Data Platform With Operators Attached
Next: [MDR 10.1] Build Sheet: MDR Readiness in Your Own Tenant ›




