[MDR 3] Microsoft Defender Experts: The First-Party Answer

Microsoft operating Microsoft is the baseline case every other provider is implicitly priced against. What Defender Experts declines to cover is the fastest way to work out what you actually need from anyone else.


If you are running a Microsoft estate, Defender Experts is the offer every other provider is implicitly priced against, whether or not it appears on your shortlist. Microsoft operating Microsoft is the baseline case: no second agent, no second console, no telemetry leaving your tenant. Understanding what it does and, more usefully, what it declines to cover is the fastest way to work out what you actually need from anyone else.

The service has been through a naming shift that causes confusion in procurement. The documentation now describes it as Defender Experts MDR while the subscription family is still sold as Defender Experts for XDR. Both names are current and refer to the same service. There is also a bundled Defender Experts Suite, generally available since the start of 2026, which wraps the managed detection service together with Microsoft Incident Response and designated engineering support, available through enterprise agreements only.


The entry requirement is lower than most people believe

There is a persistent belief that this service requires full E5. It does not, and the correction matters because it changes who can realistically buy it. The documented floor is Entra ID P1 for all users plus at least one Defender product licensed and deployed in active mode: Defender for Endpoint, Defender for Office Plan 2, Defender for Identity, or Defender for Cloud Apps. Any one of those satisfies the requirement.

What that floor buys you, though, is eligibility rather than coverage. The depth of what the experts can see and do scales directly with what you have running in active mode. An organisation that qualifies on Defender for Endpoint alone gets an endpoint service. Identity-plane coverage depends on Entra ID P2 signal being present, so P1 gets you through the door and P2 is what makes the identity half of the service meaningful. This is worth modelling honestly before the conversation with your account team, because the licensing uplift required to make the service worth having is frequently larger than the service itself.


Authority as a permission rather than a clause

This is the part of the service I find architecturally cleanest, and it is the standard I hold the commercial providers to in the rest of this series. Response authority here is not a contract annex or a sales conversation. It is a role assignment, and you control it.

Grant the experts Security Reader, which is the default, and they investigate, triage and conclude, then leave the required response actions in a managed response panel inside your own portal for your team to execute. The incident carries a status indicating it is waiting on you. Nothing happens to a machine or an account unless someone on your side does it. Grant Security Operator instead, which is what Microsoft recommends, and the same analysts execute those actions themselves, with each completed action logged in the incident record and anything still outstanding flagged separately. You can also exclude specific device or user groups from remediation entirely, which is the mechanism I would use to fence production servers or executive accounts.

Authority you can grant, scope and withdraw from your own console is a fundamentally different risk posture from authority written into a services agreement.

The access model underneath is worth knowing because it is unusually tight. The experts reach your tenant through granular delegated admin privileges combined with cross-tenant access policies and cross-tenant role assignment, provisioned just-in-time at least privilege. Compare that to the pattern you will see repeatedly in the commercial profiles that follow, where the integration lands as an application registration holding a long-lived client secret with response-grade API permissions. Both work. Only one of them leaves you with a credential to rotate and review.

One caveat from watching Microsoft’s own walkthrough material rather than the documentation: even under Security Operator, several identity-plane actions have historically surfaced as awaited customer actions rather than completed expert ones. Creating a blocking indicator, resetting a password and revoking sessions have all appeared on the customer side of the line in demonstrations. Native account-disable and password-reset controls arrived in the portal in late May 2026, which may well move that boundary. If the division of identity response matters to your design, and it should, get the current answer in writing during onboarding rather than inferring it.


What it does not cover, said plainly

This is the section that should shape your evaluation, and it is the one nobody puts on a comparison slide. The service covers high and medium severity incidents on Windows, Linux and macOS. Outside that scope, and stated as such in the product documentation, are incidents categorised as compliance, data loss prevention, or custom detections, and anything affecting internet of things devices, iOS or Android.

Read that mobile exclusion twice if you have spent the last year building out a mobile estate. Your enrolled iPhones and Android devices, your app protection policies, the whole bring-your-own-device layer that a great deal of modern endpoint work goes into, sit outside this service. So do the custom detection rules your team wrote, which is a particular irony: the more mature your own detection engineering, the more of your alert surface falls outside the managed service. And data loss prevention incidents, increasingly where the interesting insider and exfiltration signal lives, are likewise out.

None of this makes the service bad. It makes it specific. The gap it leaves is precisely the space the commercial providers sell into, and knowing the shape of that gap is what lets you evaluate them on something other than vibes.


Where the data lives, and what happens when you leave

Telemetry residency is the lock-in question in this market and almost nobody answers it publicly. Microsoft does. Reporting data stays in your own Defender service storage location. It is retained through a ninety day grace period after the subscription expires, and deleted within thirty days of termination.

That is the lowest exit cost of any provider in this series, and it is structural rather than generous: there is nowhere else for the data to go, because the service operates inside your tenant rather than shipping your signal to a provider cloud. When you stop paying, the analysts stop working your queue and everything else stays where it was. Hold that comparison in mind through the profiles that follow, where retention windows and exit terms are almost universally contract-only.


Cost, and the thing that changed underneath it

Microsoft does not publish a price for either the standalone service or the bundled suite. Both are quoted. The suite carried a substantial promotional discount through 2026, expressed as a percentage off an unpublished list price, which is not a number you can plan against without a quote in hand.

What did change, and what belongs in any cost model built this year, is the underlying licence. E5 moved from fifty seven to sixty dollars per user per month on the first of July 2026, and the increase brought Security Copilot capacity, Intune Endpoint Privilege Management, Enterprise Application Management and Cloud PKI inside the bundle. If you have been treating any of those as separate add-on spend in your planning, that assumption is now wrong in your favour, and the arithmetic on stepping up to E5 in order to make a managed service worthwhile has shifted accordingly.

The overlap question that dominates every other profile in this series does not arise here. There is no second stack, no duplicated agent, no parallel console. You are paying for hours and expertise applied to software you already licensed. Whether those hours are worth their price is a judgement about your own team’s depth and coverage, which is at least an honest question rather than an accounting one.


The zero trust contribution, and the honest limit

Defender Experts contributes operations, not architecture. It adds no enforcement point, no policy plane and no new control surface. What it does is staff the security operations function that your zero trust design assumes exists, reading the signal your identity and device controls produce and acting on it. In the maturity models that is the cross-cutting capability layer rather than a pillar, and it is the layer most mid-sized organisations quietly do not have.

That is also its limit. It cannot compensate for a weak conditional access design, it will not tell you your device compliance policy is theatre, and it does not govern what your users do with generative AI, which is a separate stack of Purview and Defender for Cloud Apps capability entirely. It watches the estate you built. Build a poor one and you will have well-informed analysts describing your incidents accurately as they unfold.

The reason to start any evaluation here is not that Microsoft will win it. It is that this service defines the shape of the problem: the coverage you get for free from proximity to the platform, and the four specific holes, mobile, data loss prevention, custom detections and third-party telemetry, that any competing provider needs to justify its price by filling.


MDR
‹ Previous: [MDR 2] Arctic Wolf: The Concierge and the Open Platform
Next: [MDR 4] CrowdStrike Falcon Complete: The Second Stack, Fully Operated