Key Takeaways
- Microsoft Defender Experts MDR is Microsoft's own managed detection and response service, covering Microsoft Defender workloads in Plan 1 and supported non-Microsoft sources through Microsoft Sentinel in Plan 2.
- Plan 1 covers High and Medium severity incidents on Windows, Linux and macOS only, so iOS and Android devices sit outside the service entirely.
- Plan 2 is Microsoft's only route to non-Microsoft telemetry, and it starts at 1,500 licensed seats, which puts it out of reach for most mid-market estates.
- Defender Experts MDR is sold separately from every Defender product, so Microsoft 365 E5 is a prerequisite, not an entitlement.
- Microsoft analysts act inside Microsoft Defender but only advise on third-party products, which is the line that decides whether native coverage is enough.
- Native and third-party coverage can run together, in four splits set out below.
You are running Microsoft Defender across the estate and deciding whether Microsoft's own managed service is enough. If Defender XDR is the whole environment, Defender Experts MDR Plan 1 covers it; anything outside Microsoft, including a second endpoint detection and response (EDR) product, operational technology, or a non-Microsoft firewall, falls outside Plan 1 and is only covered by Plan 2, which Microsoft prices from 1,500 seats. Below that threshold the choice is Plan 1 or a third party.
Which MDR Model Fits a Microsoft Defender Estate
Which MDR model fits is decided by two things: what your estate contains that Microsoft Defender does not cover, and who needs authority to take action inside your tenant. Those two questions sort every option into five models, and they also rule out the model most Microsoft-heavy buyers assume they are choosing between.
The table sorts models. It does not price them, and it does not tell you whether you can run two at once. Defender Experts MDR Plan 1 and an independent MDR provider are not mutually exclusive: Microsoft covers its own workloads while a third party covers what Plan 1 excludes. The two sections on when each side is the right answer take that in turn.
What Defender Experts Covers, and What It Doesn't
What Microsoft manages, and where its responsibility stops
Microsoft's analysts manage your Defender incident queue, triage and investigate on your behalf, and either take action in your tenant or guide your team through the response. Coverage runs to High and Medium severity incidents on Windows, Linux and macOS devices only. Incidents on iOS and Android sit outside the service, as do Compliance, Data Loss Prevention and Custom Detections incidents. For an Intune-managed estate, that means the phones in your fleet are in scope for you and out of scope for Microsoft, work that falls to your own team or to whoever runs managed Defender for Endpoint across mobile devices.
Microsoft states three further boundaries outright. Neither plan covers Microsoft Defender for Cloud workloads, so storage, containers and databases are excluded from both. Neither plan is an incident response engagement, and Defender Experts MDR does not respond to an active compromise. Plan 2 is not a managed SIEM service: you continue to own connector deployment, custom ingestion, your own analytics rules, and data quality, retention, permissions and ingestion costs, which is the ongoing work of running Microsoft Sentinel as a monitored SIEM rather than a log store.
Plan 1, Plan 2, and third-party MDR side by side
Plan 1 vs Plan 2 side by side
Plan 1 is the only plan most mid-market Microsoft estates can buy. Plan 2 extends coverage to non-Microsoft telemetry, but Microsoft gates it behind Microsoft Sentinel and a seat floor that sits above the size of a typical 50 to 500 employee organisation.
If you run any of the eight named sources and have fewer than 1,500 seats, Microsoft has no plan that covers them. That is the condition that decides whether a third party is required, and it is settled before capability comparison begins.
Licensing Prerequisites
Defender Experts MDR is not included with Microsoft 365 E5. Microsoft sells it separately from every Defender product, and the licences you already hold are prerequisites for eligibility rather than an entitlement to the service.
What you need in place before Microsoft will onboard you:
- Microsoft Entra ID P1 across the tenant. This is the eligibility floor. Entra ID P2 is required if you want identity incidents covered.
- At least one covered workload, licensed and deployed in active mode. Microsoft Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity, Defender for Cloud Apps, or Entra ID P2.
- Active mode, not passive. Products running passively may be non-actionable. Microsoft can still give guided response, but it will not remediate on your behalf.
- A Defender for Endpoint for Server licence for each covered server. Microsoft counts a server as a user account for billing.
- For Plan 2 only: Microsoft Sentinel connected to the Defender portal, 90-day Log Analytics retention on real-time detection sources, and a supported endpoint detection and response product on every endpoint.
Before you contact Microsoft, check which Defender products are in passive mode and confirm your Entra ID tier.
When Microsoft-Native Is Genuinely the Right Answer
Some organisations should buy Defender Experts MDR Plan 1 and stop there, including organisations that would otherwise be a good fit for a managed provider like CyberQuell. The test is not whether Microsoft's service is good. It is whether everything you need watched falls inside the boundaries Microsoft publishes, and whether you have someone able to act on what it sends you.
Native is the right answer when all five of these are true:
- Every device you need monitored runs Windows, Linux or macOS. Microsoft covers High and Medium severity incidents on those three. If your fleet is Intune-managed iOS and Android, those devices are outside the service in both plans, and nobody is watching them for you.
- Every signal you care about is a Microsoft Defender workload. Plan 1 covers no non-Microsoft telemetry at all. A firewall, an identity provider or a cloud platform outside the Defender estate produces nothing the service will look at.
- You have no operational technology or IoT to monitor. Microsoft names Defender for IoT as not covered and puts IoT devices outside scope. This one is worth checking rather than assuming: it is also uncovered by most of the third-party field, so it does not automatically point elsewhere.
- Your team can action guided response. Microsoft's analysts act inside Microsoft Defender where you grant the roles, and advise everywhere else. Guidance nobody has time to execute is not coverage.
- You accept that low-severity incidents and an active breach are yours. Low severity sits outside scope. So does incident response: Defender Experts MDR does not respond to a live compromise, which is a separate engagement.
Score yourself honestly. Five out of five and Microsoft's own service is the correct purchase. Two or more failures and the conditions below are the ones that apply.
When a Third-Party MDR Earns Its Cost
Invert the test. A third party earns its cost when something you need watched sits outside Microsoft's published boundaries, and no plan you can buy brings it back in. For most 50 to 500 employee estates that turns on one thing: Plan 2 is the only route to non-Microsoft telemetry, and it starts at 1,500 licensed seats.
A third-party MDR earns its cost when any of these are true:
- You run a second endpoint product, a non-Microsoft firewall, or an identity provider outside Entra. Plan 1 sees none of it. Plan 2 covers eight named sources, and only above 1,500 seats. Below that threshold, where Microsoft's stack needs third-party cover is the whole gap.
- Nobody on your side can action guided response at 2am. Microsoft advises outside Defender and acts inside it only where you grant roles. If the guidance lands in an unattended inbox, coverage exists on paper only.
- Low-severity incidents matter to you. Microsoft covers High and Medium. Precursor activity that never escalates on its own is a real category, and it is uncovered in both plans.
- You need evidence output Microsoft's reporting does not produce. Named auditable detail per incident, on your retention schedule, in your tenant. Worth confirming what your framework actually demands before assuming either side clears it.
- You want a second opinion on Microsoft's own detections. A single vendor building the platform, writing the detections and grading its own response has no independent check in it.
None of these is a reason to leave Defender. They are reasons to put someone on top of it, which is what managed XDR across mixed estates describes. Which kind of provider fits comes next.
Before you decide, it is worth knowing where the configuration gaps sit in your current environment. CyberQuell runs a security assessment against CIS benchmarks that returns findings ranked by severity and specific remediation steps, whether or not you end up hiring anyone.
How Defender-Compatible MDR Providers Differ
Providers that work with Microsoft Defender sort into four operating models, and the model tells you more than the brand does. It decides who owns the SIEM, who can take action inside your tenant, and what you are buying alongside detection. The MDR Providers directory groups 82 Defender-compatible providers this way. Microsoft's own service appears in none of them, because the directory does not profile it.
Two things the model does not settle. Whether a provider ingests your existing Defender telemetry or expects its own agent varies by contract rather than by brand, and several vendors do both depending on what you buy. Operational technology is covered as standard by four of the 82. Both are questions to put to a shortlist rather than assumptions to carry into one. Groupings from the MDR Providers directory, retrieved 31 August 2026, which notes its listings come from public sources and may contain errors.
What to Verify Before Signing With a Third Party
Put these eight questions to any provider in writing before you sign. Each is answerable in a sentence, and the answers differ enough between providers to decide a shortlist.
- Does the service run on our existing Defender agent, or do you deploy your own? Both are valid. Only one of them adds a second endpoint product to your estate.
- Which Microsoft Entra roles will your analysts hold in our tenant, and which response actions can they take without asking us first?
- How do you price, per seat, per endpoint or per environment, and what is excluded from that figure? Microsoft prices Defender Experts MDR per seat on top of licences you already hold. Third-party models vary enough that the unit matters more than the rate.
- Who pays Microsoft Sentinel ingestion and retention? Ask for it in writing. It is the cost most often assumed away on both sides.
- Do we get raw Kusto Query Language access to our own logs, or only your console?
- What is the log retention period, and in which region does our data sit?
- What is the escalation path out of hours, and who is the named contact?
- What happens to coverage if we add a second endpoint product or an operational technology environment?
A provider that will not answer these in writing has told you something.
Can You Run Both? The Hybrid Model
Yes. Hybrid means Microsoft's service and a third party covering different parts of the same estate, and it is worth the coordination overhead when the uncovered surface is small and well-defined. When it is neither, pick one provider.
- Defender Experts for Microsoft workloads, a third party for what Plan 1 excludes. Microsoft holds the Defender queue. The third party takes mobile, low-severity activity, and any non-Microsoft source you run below the 1,500-seat Plan 2 threshold. Cleanest split, because the boundary is Microsoft's own and both sides can read it.
- Native detection, independent threat hunting. Microsoft runs detection and response. A separate provider hunts across the same telemetry with its own detections. Buys a second opinion on Microsoft's own grading without duplicating the response function.
- Native monitoring, external incident response retainer. Neither plan responds to an active compromise. The retainer sits unused until it is needed and covers the boundary Microsoft states outright.
- Managed service provider fronting, Microsoft underneath. One provider owns the relationship, escalation and reporting; Microsoft's service runs beneath it. Fits estates already managed by a provider.
Splitting by what Plan 1 excludes fits mixed estates under 1,500 seats. Adding an external incident response retainer fits regulated or previously breached organisations, and it stacks with any of the others. Where MDR and SIEM divide the work shapes the first and fourth patterns in particular.
Final Thoughts
The decision comes down to what sits outside Microsoft's boundaries and whether anyone on your side can act on what lands in the queue. If every device runs Windows, Linux or macOS, every signal is a Defender workload, and your team can action guided response, buy Plan 1 and stop reading. If you run a second endpoint product, a non-Microsoft firewall, or an identity provider outside Entra, and you are below 1,500 seats, Microsoft has no plan that covers it and a third party is doing that work or nobody is.
CyberQuell is a Microsoft-native provider in the first of those four operating models, running managed detection and response on Microsoft Defender and Microsoft Sentinel for organisations in exactly that gap. If you want to talk through where your coverage currently stops, book a call with our team.
.png)


.png)