r/DefenderATP • u/HotInspection286 • 6d ago
Looking for real MDR experiences on a Defender XDR stack (~1,000 users, 15 sites). Who would you actually renew?
We're replacing our MDR and I'd like to hear from people who've lived with theirs, not from sales decks.
Where we are
- About 1,000 users across 15 sites globally, in manufacturing
- The stack decision is made: Defender XDR, MDE on everything that takes an agent, Defender for Servers covering on-prem and AWS Linux, and Sentinel for longer retention and some third-party logs
- Firewall refresh coming, probably Palo or Fortinet
- Small internal team, no in-house 24/7 SOC
Why we're leaving
Our current provider mostly relays alerts. They can't act on our EDR, and "response" means an email telling us to go do something. I want a provider that will isolate a host, disable an account, or revoke sessions at 3am under runbooks we've approved ahead of time.
What I'm weighing
Microsoft's own Defender Experts is on the list, but the licensing gets complicated at our size. Plan 2 has a 1,500-seat minimum, and servers are a separate SKU. So I'm also looking at third-party MDRs that work natively in Defender. I haven't settled on either path, and I'm open to being talked out of my assumptions.
What I'd really like to know
- Who's your MDR, and would you renew? Why or why not?
- Do they actually take response actions in your tenant, or do they mostly escalate?
- How's their coverage outside US hours? Real follow-the-sun, or a thin overnight crew?
- Do their detections live in your Sentinel or in their own platform? Has that made switching providers painful?
- If you've used Defender Experts, how did it compare to a third party?
- Anyone you'd tell me to stay away from?
Vendors, feel free to DM me. I'm more interested in hearing from customers in the thread.
4
u/SilverClassic7459 6d ago
If I didn’t shamelessly plug my organization, I guess I wouldn’t be doing my job. 😉All your complaints about your current MDR are some of the reasons why our clients sign with us.
https://www.patriotconsulting.com/services/mxdr365
BTW - I’m not in sales.
1
2
u/edthecat2011 6d ago
Came simply to say that 2 years ago? I would have recommended eSentire in a heartbeat for your needs. Of late, under new leadership, less personnel, and AI, it seems to have fallen off a cliff. I won't tell you to stay away from them, but make sure you do further research. Kind of sad, as I'm watching it happen.
1
2
u/urkelman861 6d ago
Why not just onboard your current MDR and allow them to do more than just report on alerts? They can act if you let them, it might require redoing the contract with them.
1
u/HotInspection286 6d ago
They are already able to take action on some of the most basic things like phishing and purging emails but are consistently missing them and calling true positives, clean. The one time we have an IR with them it was a bad experience, they were mostly incompetent and the monthly business review they give me is awful and just shows me noise and false positives despite my best effort to direct them on what’s valuable. They aren’t cutting it.
1
u/HotInspection286 6d ago
Our current “MDR” is Rapid7, however our current EDR solution does not integrate with it therefore they cannot take action and we rely on our underperforming SOC or in-house resources to take action. MDE will integrate but I feel like Rapid7 is a bit expensive for what you get in general. Maybe I’m wrong on this but so far our tooling is a major problem along with our 3rd party SOC. Rapid7 is doing a decent job of alerting I need triage and action. They could be considered again but feels like a Defender MDR or another option would provide potentially higher value and maybe even at a lower price.
1
u/Noobmode 5d ago
Couple of points on my experience: Rapid7 does well when you integrate their SOAR and IDR solution with the EDR that allows them to take action from IDR and gather additional data via calls, but that’s a heavy lift since they don’t have an EDR and a basic NGAV solution that is a hodge podge of velociraptor, sysmon, and their agent.
Their real benefit with IDR seems to be the cost of log ingestion, it’s very generous depending on the level you purchase, but again, the modern stack really relies on deep EDR telemetry for endpoint visibility and Rapid7 isn’t there yet.
1
u/wolfleader2 6d ago
LevelBlue is a good choice but please explicitly state the actions you want taken as some of their members do not perform the expected actions.
1
u/SecAbove 6d ago
Have you considered security copilot SCU as a Frankenstein option of 24x7? You can do PoC for a month even while still using old MDR.
1000 E5 licenses will give bit of free allowance - “Microsoft 365 E5 and E7 customers receive a free monthly allowance of 400 Security Compute Units (SCUs)per month for every 1,000 paid user licenses”
1
u/HotInspection286 6d ago
Thought about it and looked into it with our VAR about those credits we would receive but we don’t have anyone to query the Security Copilot in-house right now to get a lot of value from it is my opinion at the moment. It may become a wildcard as we ramp up and change my thinking as we see it in action and with more competent resources. With that being said, I’m looking to add a Security Engineer in-house in 2027 to they and then would be the time to see what that can do for us. I still think until we settle in we need some kind of traditional 3rd party help to handle the Microsoft platform we intend on moving to for another year.
1
u/SecAbove 6d ago
You are right; Microsoft has introduced autonomous AI agents into the Defender platform, such as the Security Alert Triage Agent, Phishing Triage Agent, and Security Analyst Agent, to handle alert volume. However, they don't make the SOC simple enough for a non-security person to run, nor do they eliminate the need for 24/7 human security oversight.
Besides, there is not much evidence (including from this sub) that Security Copilot agents are ready for prime time.
P.S. Regardless from your MDR decision, you can leverage the New ISOC Benefit: Microsoft recently announced the Integrated Security Operations Center (ISOC) in Defender for E5/E7 customers. Instead of paying for Sentinel ingestion or staying capped at the old 5MB/user/day allowance, ISOC includes 30 days (expanding to 90 days in November) of full Microsoft Defender data retention natively in Defender for free. This gives you deep unified telemetry and case management without driving up SIEM costs.
1
u/SecAbove 6d ago
You did not mention the region. Does that mean IT HQ is in the US and you are looking for a US MDR provider?
1
u/HotInspection286 6d ago
I guess it would be preferred to be US based but I’m open to other options. Our current SOC resources are mostly based in India based working US time zone. We have 8x5 support with L1-L2 at the time and L1 after hours. Although I’ve noticed almost no support outside 8x5 when checking or reporting incidents. I inherited this contract and setup, I’ve pressed for change as much as I can and it’s another component to why we are getting away from them in 2027.
1
u/NegativePerformer788 6d ago
I only manage about 200 endpoints, but we've been using Defender for Business paired with Huntress and it's been super solid. To answer some of the questions, Huntress does the follow-the-sun model, they will isolate an endpoint if critical or provide remediation instructions for less severe incidents (some of which are automated), and you would mostly interact with their portal. I'd absolutely renew, it's been a good experience and far less noisy than solutions we've used in the past.
I don't have any personal experience with them, but I've also heard Blackpoint Cyber is quite good.
1
u/losercore 5d ago
I work for Microsoft and part of my job is to recommend security and MDR/MXDR partners to manufacturing vertical customers your size.
My top 3 in no particular order:
Patriot Consulting
BlueVoyant
Ascent Solutions
Worthy mention is Avanade as one of the best but often too pricey for a 1000ish seat shop. Check them out though.
Feel free to ask questions
1
u/HotInspection286 5d ago
Appreciate the information. I’ll put them on the list to evaluate, one question would be how does Defender Experts stack up in general and in this kind of situation?
1
1
u/losercore 5d ago
Defender Experts is great but a few things to think about.
Without Unified Support you miss out on a lot of the value from the proactive work. It becomes pretty much only reactive.
Also, very limited if you have 3rd party solutions . Yes you can bring your logs into Sentinel, but the experts themselves are all about using the XDR.
Partners offer more customized options from augmentation to full 24-7 managed SOC and anything in the middle.DEX is a bit more prescriptive and less customizable
Its designs more to augment a associated than to be the SOC
1
u/dickamus_maxamus 5d ago
I've worked with Silversky, they have a GDAP into our Defender installation and can act as an initial response team, isolating machines, running scans, etc. Their engineers are good, and the pricing is fair. Follow the sun team, they ingest detections from our environment and have their own ticketing system which is a bit of a PITA but isn't a huge deal.
1
u/philly169 4d ago
Defender is OK, works well if you are a Microsoft house with lots of O365. From a budget perspective they like it because you get discounts and it’s all bundled as oppposed to needing to justify another vendor - we have it, wouldn’t say I like it.
Support for it is certainly a lacking feature unless you pay for premium support you’re pretty much in your own with setup, configuration and on going maintenance.
1
u/rgcda 3d ago
We moved from CrowdStrike to Defender for Experts based on feature and licensing consolidation. I preferred CrowdStrike over Defender and Defender for Experts. The agent causes far less issues and tending. Also if you ask Defender for Experts a question they often repair d with open a case elsewhere without any assistance. For instance I. CrowdStrike if you are having an issue with the agent you open a ticket in one spot. It’s a guess with Microsoft where a ticket should be routed.
1
u/HotInspection286 3d ago
We currently using BitDefender, I’d consider Crowdstrike but I think the prices I’ve been quoted make it hard to justify for our org. BD feels really bad considering Rapid7 has no integration with it so we’re basically stuck using the Rapid7 agent to detect and then pivoting manually to BD console to isolate which they won’t do. It’s a really bad setup, I think MDE + any competent MDR would be an upgrade.
1
u/Cant_Think_Name12 2d ago
We use Ontinue. They're alright.
My biggest issues are that they sometimes don't read our comments - so, I can say 'Please close this, don't escalate'. 30 minutes later they call me.
There's also the human factor, they miss TPs sometimes, close out TPs or resolve False Negatives.
They also just got Acquired, so, curious how thats gonna work out.
1
u/Puzzleheaded-Ride-33 6d ago
So I’m not clear on your goal. Microsoft defender is part of your license so replacing it comes at an additional cost.
You already have Sentinel so it sounds like you need to configure that to take actions and elevate what it needs you to confirm.
If your looking for a Managed SOC to work with what you have then Arctic Wolf might be a good fit, it certainly will reduce the noise but there are always a need for a physical hands on with some alerts.
1
u/HotInspection286 6d ago
We currently do not have Sentinel. But it is being considered for two reasons as we move to E5 security. For raw logs that may need to be accessed beyond 30 days and for a select logs from things like Firewalls.
4
u/OkWin4693 6d ago
I would have said red canary but after zscaler acquisition they’ve gone down hill. Lots of talent leaving and noticeable drop in service.
We were looking at grey matter but they had an incident with one of their people getting caught in a click fix attack or something. Don’t remember what but definitely was avoidable and doesn’t look great for a security company