Cybersecurity

11 mins

Defender Experts vs Third-Party MDR: How to Decide 2026

Last Updated
August 31, 2026

Key Takeaways

  • Microsoft Defender Experts MDR is Microsoft's own managed detection and response service, covering Microsoft Defender workloads in Plan 1 and supported non-Microsoft sources through Microsoft Sentinel in Plan 2.
  • Plan 1 covers High and Medium severity incidents on Windows, Linux and macOS only, so iOS and Android devices sit outside the service entirely.
  • Plan 2 is Microsoft's only route to non-Microsoft telemetry, and it starts at 1,500 licensed seats, which puts it out of reach for most mid-market estates.
  • Defender Experts MDR is sold separately from every Defender product, so Microsoft 365 E5 is a prerequisite, not an entitlement.
  • Microsoft analysts act inside Microsoft Defender but only advise on third-party products, which is the line that decides whether native coverage is enough.
  • Native and third-party coverage can run together, in four splits set out below.

You are running Microsoft Defender across the estate and deciding whether Microsoft's own managed service is enough. If Defender XDR is the whole environment, Defender Experts MDR Plan 1 covers it; anything outside Microsoft, including a second endpoint detection and response (EDR) product, operational technology, or a non-Microsoft firewall, falls outside Plan 1 and is only covered by Plan 2, which Microsoft prices from 1,500 seats. Below that threshold the choice is Plan 1 or a third party.

Which MDR Model Fits a Microsoft Defender Estate

Which MDR model fits is decided by two things: what your estate contains that Microsoft Defender does not cover, and who needs authority to take action inside your tenant. Those two questions sort every option into five models, and they also rule out the model most Microsoft-heavy buyers assume they are choosing between.

Model Fits when What you give up Risk
Microsoft Defender Experts MDR Plan 1 Every device runs Windows, Linux or macOS and every signal is a Microsoft Defender workload Coverage of iOS and Android, low-severity incidents, and anything outside Defender No route to non-Microsoft telemetry, since Plan 2 starts at 1,500 seats
Microsoft-native third-party MDR Defender XDR and Microsoft Sentinel are the estate, but you want a named team and data resident in your own tenant Multi-vendor telemetry, independent second opinion Weak fit if another endpoint detection and response product stays in the environment
Independent MDR on Defender telemetry Defender stays, but you want non-Microsoft eyes on it Single-vendor accountability Verify response actions and raw log access before signing
MSP-delivered MDR Small estate, or already managed by a provider Enterprise SIEM ownership Usually weaker for raw-query access
MDR plus incident response retainer Regulated, or previously breached Cost and procurement speed Custom scope, slower procurement

The table sorts models. It does not price them, and it does not tell you whether you can run two at once. Defender Experts MDR Plan 1 and an independent MDR provider are not mutually exclusive: Microsoft covers its own workloads while a third party covers what Plan 1 excludes. The two sections on when each side is the right answer take that in turn.

What Defender Experts Covers, and What It Doesn't

What Microsoft manages, and where its responsibility stops

Microsoft's analysts manage your Defender incident queue, triage and investigate on your behalf, and either take action in your tenant or guide your team through the response. Coverage runs to High and Medium severity incidents on Windows, Linux and macOS devices only. Incidents on iOS and Android sit outside the service, as do Compliance, Data Loss Prevention and Custom Detections incidents. For an Intune-managed estate, that means the phones in your fleet are in scope for you and out of scope for Microsoft, work that falls to your own team or to whoever runs managed Defender for Endpoint across mobile devices.

Microsoft states three further boundaries outright. Neither plan covers Microsoft Defender for Cloud workloads, so storage, containers and databases are excluded from both. Neither plan is an incident response engagement, and Defender Experts MDR does not respond to an active compromise. Plan 2 is not a managed SIEM service: you continue to own connector deployment, custom ingestion, your own analytics rules, and data quality, retention, permissions and ingestion costs, which is the ongoing work of running Microsoft Sentinel as a monitored SIEM rather than a log store.

Plan 1, Plan 2, and third-party MDR side by side

Capability Plan 1 Plan 2 Typical third-party MDR
Microsoft Defender workloads Included Included Included
Non-Microsoft telemetry Not included 8 named sources via Sentinel Usually broader, verify per provider
Response in Microsoft Defender Action or guided response Action or guided response Varies, verify before signing
Response in third-party products Not applicable Guidance only, no direct action Varies, some take direct action
iOS and Android devices Out of scope Out of scope Varies by provider
Low-severity incidents Out of scope Out of scope Varies by provider
Operational technology and IoT Out of scope Out of scope Rarely standard, usually an add-on
Microsoft Sentinel required No Yes Varies
Minimum seats None published 1,500 Varies
Incident response for active compromise Not included Not included Varies, often a separate retainer

Plan 1 vs Plan 2 side by side

Plan 1 is the only plan most mid-market Microsoft estates can buy. Plan 2 extends coverage to non-Microsoft telemetry, but Microsoft gates it behind Microsoft Sentinel and a seat floor that sits above the size of a typical 50 to 500 employee organisation.

Plan 1 Plan 2
Minimum licensed seats None published 1,500
Microsoft Sentinel required No Yes
Non-Microsoft sources covered None Okta, Proofpoint Targeted Attack Protection, AWS CloudTrail, AWS GuardDuty, Palo Alto PAN-OS, Cisco ASA and Meraki, Zscaler ZIA and ZPA, Fortinet FortiGate
Sentinel ingestion and retention costs Not applicable Yours, not Microsoft's
Log Analytics retention required Not applicable 90 days for real-time detection sources
Third-party network signal enrichment Deprecated, closed to new enablement Not applicable

If you run any of the eight named sources and have fewer than 1,500 seats, Microsoft has no plan that covers them. That is the condition that decides whether a third party is required, and it is settled before capability comparison begins.

Licensing Prerequisites

Defender Experts MDR is not included with Microsoft 365 E5. Microsoft sells it separately from every Defender product, and the licences you already hold are prerequisites for eligibility rather than an entitlement to the service.

What you need in place before Microsoft will onboard you:

  1. Microsoft Entra ID P1 across the tenant. This is the eligibility floor. Entra ID P2 is required if you want identity incidents covered.
  2. At least one covered workload, licensed and deployed in active mode. Microsoft Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity, Defender for Cloud Apps, or Entra ID P2.
  3. Active mode, not passive. Products running passively may be non-actionable. Microsoft can still give guided response, but it will not remediate on your behalf.
  4. A Defender for Endpoint for Server licence for each covered server. Microsoft counts a server as a user account for billing.
  5. For Plan 2 only: Microsoft Sentinel connected to the Defender portal, 90-day Log Analytics retention on real-time detection sources, and a supported endpoint detection and response product on every endpoint.

Before you contact Microsoft, check which Defender products are in passive mode and confirm your Entra ID tier.

When Microsoft-Native Is Genuinely the Right Answer

Some organisations should buy Defender Experts MDR Plan 1 and stop there, including organisations that would otherwise be a good fit for a managed provider like CyberQuell. The test is not whether Microsoft's service is good. It is whether everything you need watched falls inside the boundaries Microsoft publishes, and whether you have someone able to act on what it sends you.

Native is the right answer when all five of these are true:

  1. Every device you need monitored runs Windows, Linux or macOS. Microsoft covers High and Medium severity incidents on those three. If your fleet is Intune-managed iOS and Android, those devices are outside the service in both plans, and nobody is watching them for you.
  2. Every signal you care about is a Microsoft Defender workload. Plan 1 covers no non-Microsoft telemetry at all. A firewall, an identity provider or a cloud platform outside the Defender estate produces nothing the service will look at.
  3. You have no operational technology or IoT to monitor. Microsoft names Defender for IoT as not covered and puts IoT devices outside scope. This one is worth checking rather than assuming: it is also uncovered by most of the third-party field, so it does not automatically point elsewhere.
  4. Your team can action guided response. Microsoft's analysts act inside Microsoft Defender where you grant the roles, and advise everywhere else. Guidance nobody has time to execute is not coverage.
  5. You accept that low-severity incidents and an active breach are yours. Low severity sits outside scope. So does incident response: Defender Experts MDR does not respond to a live compromise, which is a separate engagement.

Score yourself honestly. Five out of five and Microsoft's own service is the correct purchase. Two or more failures and the conditions below are the ones that apply.

When a Third-Party MDR Earns Its Cost

Invert the test. A third party earns its cost when something you need watched sits outside Microsoft's published boundaries, and no plan you can buy brings it back in. For most 50 to 500 employee estates that turns on one thing: Plan 2 is the only route to non-Microsoft telemetry, and it starts at 1,500 licensed seats.

A third-party MDR earns its cost when any of these are true:

  1. You run a second endpoint product, a non-Microsoft firewall, or an identity provider outside Entra. Plan 1 sees none of it. Plan 2 covers eight named sources, and only above 1,500 seats. Below that threshold, where Microsoft's stack needs third-party cover is the whole gap.
  2. Nobody on your side can action guided response at 2am. Microsoft advises outside Defender and acts inside it only where you grant roles. If the guidance lands in an unattended inbox, coverage exists on paper only.
  3. Low-severity incidents matter to you. Microsoft covers High and Medium. Precursor activity that never escalates on its own is a real category, and it is uncovered in both plans.
  4. You need evidence output Microsoft's reporting does not produce. Named auditable detail per incident, on your retention schedule, in your tenant. Worth confirming what your framework actually demands before assuming either side clears it.
  5. You want a second opinion on Microsoft's own detections. A single vendor building the platform, writing the detections and grading its own response has no independent check in it.

None of these is a reason to leave Defender. They are reasons to put someone on top of it, which is what managed XDR across mixed estates describes. Which kind of provider fits comes next.

Before you decide, it is worth knowing where the configuration gaps sit in your current environment. CyberQuell runs a security assessment against CIS benchmarks that returns findings ranked by severity and specific remediation steps, whether or not you end up hiring anyone.

How Defender-Compatible MDR Providers Differ

Providers that work with Microsoft Defender sort into four operating models, and the model tells you more than the brand does. It decides who owns the SIEM, who can take action inside your tenant, and what you are buying alongside detection. The MDR Providers directory groups 82 Defender-compatible providers this way. Microsoft's own service appears in none of them, because the directory does not profile it.

Operating model Named in the directory What it means for your tenant
Microsoft-native Ontinue, Quorum Cyber, Bridewell, CyberOne Built for Defender and Sentinel estates. Weak fit if a second endpoint product stays in the environment
Independent MDR Expel, Red Canary, eSentire, Binary Defense Non-Microsoft eyes on Microsoft telemetry. Confirm response actions, threat hunting and raw log access
MSP-led or SMB-focused Huntress, Blackpoint Cyber, Barracuda, ConnectWise Fits smaller or already-managed estates. Usually weaker on SIEM ownership and raw-query access
Enterprise or incident-response-led Secureworks, Kroll, Mandiant, Sygnia Depth for regulated or previously breached organisations. Custom scope, higher cost, slower procurement

Two things the model does not settle. Whether a provider ingests your existing Defender telemetry or expects its own agent varies by contract rather than by brand, and several vendors do both depending on what you buy. Operational technology is covered as standard by four of the 82. Both are questions to put to a shortlist rather than assumptions to carry into one. Groupings from the MDR Providers directory, retrieved 31 August 2026, which notes its listings come from public sources and may contain errors.

What to Verify Before Signing With a Third Party

Put these eight questions to any provider in writing before you sign. Each is answerable in a sentence, and the answers differ enough between providers to decide a shortlist.

  1. Does the service run on our existing Defender agent, or do you deploy your own? Both are valid. Only one of them adds a second endpoint product to your estate.
  2. Which Microsoft Entra roles will your analysts hold in our tenant, and which response actions can they take without asking us first?
  3. How do you price, per seat, per endpoint or per environment, and what is excluded from that figure? Microsoft prices Defender Experts MDR per seat on top of licences you already hold. Third-party models vary enough that the unit matters more than the rate.
  4. Who pays Microsoft Sentinel ingestion and retention? Ask for it in writing. It is the cost most often assumed away on both sides.
  5. Do we get raw Kusto Query Language access to our own logs, or only your console?
  6. What is the log retention period, and in which region does our data sit?
  7. What is the escalation path out of hours, and who is the named contact?
  8. What happens to coverage if we add a second endpoint product or an operational technology environment?

A provider that will not answer these in writing has told you something.

Can You Run Both? The Hybrid Model

Yes. Hybrid means Microsoft's service and a third party covering different parts of the same estate, and it is worth the coordination overhead when the uncovered surface is small and well-defined. When it is neither, pick one provider.

  • Defender Experts for Microsoft workloads, a third party for what Plan 1 excludes. Microsoft holds the Defender queue. The third party takes mobile, low-severity activity, and any non-Microsoft source you run below the 1,500-seat Plan 2 threshold. Cleanest split, because the boundary is Microsoft's own and both sides can read it.
  • Native detection, independent threat hunting. Microsoft runs detection and response. A separate provider hunts across the same telemetry with its own detections. Buys a second opinion on Microsoft's own grading without duplicating the response function.
  • Native monitoring, external incident response retainer. Neither plan responds to an active compromise. The retainer sits unused until it is needed and covers the boundary Microsoft states outright.
  • Managed service provider fronting, Microsoft underneath. One provider owns the relationship, escalation and reporting; Microsoft's service runs beneath it. Fits estates already managed by a provider.

Splitting by what Plan 1 excludes fits mixed estates under 1,500 seats. Adding an external incident response retainer fits regulated or previously breached organisations, and it stacks with any of the others. Where MDR and SIEM divide the work shapes the first and fourth patterns in particular.

Final Thoughts

The decision comes down to what sits outside Microsoft's boundaries and whether anyone on your side can act on what lands in the queue. If every device runs Windows, Linux or macOS, every signal is a Defender workload, and your team can action guided response, buy Plan 1 and stop reading. If you run a second endpoint product, a non-Microsoft firewall, or an identity provider outside Entra, and you are below 1,500 seats, Microsoft has no plan that covers it and a third party is doing that work or nobody is.

CyberQuell is a Microsoft-native provider in the first of those four operating models, running managed detection and response on Microsoft Defender and Microsoft Sentinel for organisations in exactly that gap. If you want to talk through where your coverage currently stops, book a call with our team.

Last Updated:
August 31, 2026

FAQs

Find answers to commonly asked questions about our cybersecurity solutions and services.

Does Defender Experts MDR cover AWS or Google Cloud?

Not as workloads. Defender Experts MDR covers Microsoft Defender workloads, and Plan 2 adds AWS CloudTrail and AWS GuardDuty as sources ingested through Microsoft Sentinel, which is log coverage rather than workload protection. Google Cloud is not on the supported source list. Multi-cloud workload coverage is Microsoft Defender Experts for Servers, a separate service.

Who takes response action, Microsoft or my team?

Both, split by product. Microsoft's analysts act inside Microsoft Defender using the roles you grant them, and take remediation actions agreed with your team in advance. For third-party sources they provide recommendations and guidance but do not act directly in those products. Anything they cannot action, your team does.

Can a third-party MDR provider use Defender telemetry?

Yes. Providers connect to the Defender APIs and ingest alerts and telemetry without replacing your endpoint agent. Some deploy their own agent instead or alongside, which is a per-contract question rather than a per-brand one. Ask before signing which model a provider is proposing.

Does Defender Experts MDR replace Microsoft Sentinel or a SIEM?

No. Plan 1 does not require Sentinel at all. Plan 2 requires it, and Microsoft states that Plan 2 is not a managed SIEM service: you continue to own connector deployment, custom ingestion, analytics rules, retention, permissions and ingestion costs.

What happens to my coverage if I add a non-Microsoft endpoint product?

Nothing is covered on it. Plan 1 covers Microsoft Defender workloads only, so a second endpoint product produces telemetry the service does not look at. Plan 2 covers eight named non-Microsoft sources through Sentinel and requires a minimum of 1,500 licensed seats.

Which MDR providers work with Microsoft Defender?

Dozens. One published directory lists 82 and sorts them into four operating models: Microsoft-native providers including Ontinue, Quorum Cyber, Bridewell and CyberOne; independent providers including Expel, Red Canary and eSentire; MSP-led providers including Huntress and Blackpoint Cyber; and enterprise or incident-response-led providers including Secureworks, Kroll and Mandiant.

Protect Your Business from Cyber Threats

Get in touch with our cybersecurity experts to discuss your security needs and solutions.