Posted in

Defender Experts MDR Plan 2 now covers non-Microsoft endpoints and cloud logs

If you run a mixed security estate, the hardest part of any managed detection service has never been the detection itself. It is the fact that your attack surface does not respect your vendor choices. An attacker moves from a third-party email gateway to a non-Microsoft EDR to an AWS workload, and most managed detection services lose the thread at the seams.

Microsoft’s July 15 announcement expands Defender Experts MDR with a new Plan 2 tier that extends managed detection and response beyond Microsoft products. The coverage runs through Microsoft Sentinel, which ingests logs from non-Microsoft cloud, identity, email, network, and endpoint sources. Plan 1, which carries forward the existing Defender Experts for XDR offering, stays focused on the Microsoft estate.

For security teams running a patchwork of CrowdStrike or SentinelOne on endpoints, Barracuda or Proofpoint for email, and Palo Alto or Fortinet firewalls alongside Microsoft Defender, this is the first time Microsoft’s managed response team is explicitly offering to triage and correlate across those boundaries.

What Plan 2 actually does

According to the announcement, Plan 2 provides 24/7 monitoring and investigation where Microsoft analysts distill high-volume telemetry into prioritized incidents. The service delivers cross-platform threat analysis that correlates signals from both Microsoft and non-Microsoft environments into a single incident narrative. Analysts get vendor-aware remediation guidance rather than generic playbooks.

The service also includes ongoing recommendations for detection tuning, data integration, and Sentinel content management. That last piece matters in practice: getting useful alerts from mixed-estate telemetry usually requires significant analyst-hours to write and maintain the correlation rules. Microsoft is offering to take on part of that operational overhead.

Customers also receive business-aligned summaries of top risks and posture gaps, plus recommendations for improving the overall security estate.

What it does not replace

The announcement does not name specific supported vendors, publish pricing, or commit to SLAs. Microsoft says Plan 2 supports “leading non-Microsoft sources” across five categories: cloud, identity, email, network, and endpoint. That phrasing suggests broad coverage but leaves the details to the sales conversation.

Plan 2 also does not remove the need to onboard and tune telemetry feeds. Sentinel still needs data connectors configured for each third-party source, and noisy or incomplete feeds will produce noisy or incomplete incident correlation. Organizations should expect to invest in getting their non-Microsoft logs flowing cleanly into Sentinel before Plan 2 adds much value.

Remediation ownership also stays with the customer. Microsoft’s experts investigate, prioritize, and recommend. They do not patch endpoints, revoke compromised credentials, or reconfigure firewalls on your behalf. That distinction is standard across managed detection services, but it is worth restating because the marketing language around “managed response” can blur it.

Defender Experts Threat Intelligence is separate

The same announcement introduced Defender Experts Threat Intelligence as a new service. This is distinct from Defender Threat Intelligence (MDTI), which is the raw intelligence platform accessible through the Defender portal. Defender Experts Threat Intelligence delivers curated briefings from designated Microsoft analysts who interpret threat activity in the context of your industry and geography.

Customers receive early-warning alerts on emerging campaigns, campaign-evolution updates as activity unfolds, and recurring briefings from their assigned expert. Microsoft describes this as closing the “intelligence-to-action gap,” which is a fair description of what contextual threat briefings are supposed to do. But Microsoft has not used GA language for this service in the announcement, so treat availability and enrollment details as something to confirm directly.

The operational question for mixed estates

If your shop runs mostly Microsoft endpoints, Defender for Endpoint with Defender Experts for XDR (now Plan 1) already gives you managed response on the estate you have. Plan 2 becomes interesting when you have meaningful non-Microsoft coverage that you cannot or will not consolidate.

The decision is less about whether Plan 2 is better and more about whether the cross-tool correlation work it absorbs justifies the cost for your specific tool mix. If your security team spends most of its time manually stitching together attack narratives across three or four vendor consoles, Plan 2 is worth a closer look. If your non-Microsoft footprint is small or well-covered by an existing MSSP, the incremental value is thinner.

Microsoft plans to demonstrate the service at Black Hat USA on August 5, where Wes Malaby, General Manager of Customer Success at Microsoft Security, will walk through the threat intelligence-to-response workflow.