You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/before-you-begin-xdr.md
+24-13Lines changed: 24 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -17,7 +17,7 @@ ms.custom:
17
17
- cx-ti
18
18
- cx-dex
19
19
search.appverid: met150
20
-
ms.date: 04/24/2025
20
+
ms.date: 07/04/2025
21
21
---
22
22
23
23
# Before you begin using Defender Experts for XDR
@@ -28,25 +28,36 @@ ms.date: 04/24/2025
28
28
29
29
This document outlines the key prerequisites you must meet and essential information you must know before purchasing the Microsoft Defender Experts for XDR service.
30
30
31
-
## Eligibility and licensing
31
+
## Prerequisites and licensing
32
32
33
33
Defender Experts for XDR is a separate service from your existing Defender products. To enable us to get started with this managed service, we require the following licensing prerequisites:
34
34
35
-
- Microsoft Defender for Endpoint P2 must be licensed and enabled on eligible devices
36
-
- Microsoft Defender Antivirus must be licensed and enabled in active mode on devices onboarded to Defender for Endpoint (required for endpoint detection and response capabilities)
37
-
- Microsoft Entra ID P1 must be licensed for all users and enabled (required for enabling secure service provider access)
35
+
- Microsoft Entra ID P1 must be licensed for all users and enabled (required for enabling secure service provider access).
36
+
-**At least one** Microsoft Defender product (Microsoft Defender for Endpoint, Microsoft Defender for Office 365 P2, Microsoft Defender for Identity, or Microsoft Defender for Cloud Apps) must be licensed and deployed in active mode.
38
37
39
-
The following products are also eligible to get Defender Experts for XDR coverage, and you must have their appropriate product licenses to get started with the service:
38
+
### Product Eligibility
40
39
41
-
- Microsoft Defender for Office 365 P2
42
-
- Microsoft Defender for Identity
43
-
- Microsoft Defender for Cloud Apps
40
+
Defender Experts for XDR provides managed detection and response across any combination of the following Microsoft Defender products:
41
+
- Defender for Endpoint
42
+
- Defender for Office 365 P2
43
+
- Defender for Identity
44
+
- Defender for Cloud Apps
44
45
45
-
The following product is **not** covered by this service:
46
+
To begin service operations, at least one of these products must be appropriately licensed and deployed in active mode. Even if some products—such as Defender for Endpoint—aren't configured in active mode, Defender Experts can still provide coverage for the other eligible products in your environment. However, the depth of response might vary. For more information, see [Product configuration and service coverage](#product-configuration-and-service-coverage).
46
47
47
-
- Microsoft Defender for IoT
48
+
The following product isn't covered by this service:
49
+
- Microsoft Defender for IoT
50
+
51
+
### Product configuration and service coverage
52
+
Defender Experts for XDR provides managed detection and response across Microsoft Defender products that are licensed and properly deployed in your environment.
53
+
While all Defender products (except Defender for IoT) can be included in the service, the depth of coverage might vary depending on how each product is configured.
54
+
-**Products deployed in active mode are fully covered.** Defender Experts investigate and respond to incidents involved in these products on your behalf.
55
+
-**Products deployed in passive mode might be non-actionable by Defender Experts.** In such cases, guided response might still be provided, but no remediation actions are taken on your behalf.
56
+
57
+
We recommend ensuring that at least one product, such as Defender for Endpoint or Defender for Office 365, is deployed in active mode. This enables Defender Experts to take direct action on high-priority threats, including advanced attacks like adversary-in-the-middle (AiTM).
58
+
59
+
For maximum, native coverage, we recommend deploying the full Microsoft Defender XDR suite and enabling all eligible products in active mode.
48
60
49
-
Defender Experts for XDR is a managed extended detection and response (XDR) service. To get native XDR coverage, we recommend deploying the full Microsoft Defender XDR suite.
50
61
51
62
### Server coverage
52
63
@@ -55,7 +66,7 @@ Defender Experts for XDR also covers servers—whether on premises or on a hyper
55
66
56
67
### Ask Defender Experts
57
68
58
-
[Ask Defender Experts](experts-on-demand.md) is intended to provide a better understanding of complex threats affecting your organization. It focuses on products included in Microsoft Defender XDR (Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity). [See sample questions you can ask Defender Experts](experts-on-demand.md#sample-questions-you-can-ask-from-defender-experts).
69
+
[Ask Defender Experts](experts-on-demand.md) is intended to provide a better understanding of complex threats affecting your organization. It focuses on products included in Microsoft Defender XDR (Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, and Defender for Identity). [See sample questions you can ask Defender Experts](experts-on-demand.md#sample-questions-you-can-ask-from-defender-experts).
59
70
60
71
As part of the service's built-in [Microsoft Defender Experts for Hunting](defender-experts-for-hunting.md), customers are assigned 10 **Ask Defender Experts** credits, which you can use to submit questions, at the start of each calendar quarter. Unused credits from the current quarter roll up to the next one. You can use up to 20 credits only per quarter. All unused credits expire by the end of the calendar year or at the end of your subscription term, whichever comes first.
Copy file name to clipboardExpand all lines: defender-xdr/defender-experts-scoped-coverage.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -56,7 +56,7 @@ Currently, the service doesn't offer support to rename these predefined groups,
56
56
The following section lists down questions that you or your SOC team might have regarding scoped coverage:
57
57
58
58
1.**What aspects of the XDR service remain consistent with Defender Experts scoped coverage?**
59
-
- This service doesn't change our pricing structure. You still pay for Defender Experts service based on [E5](before-you-begin-xdr.md#eligibility-and-licensing) and Microsoft Defender for Endpoint for Servers for your desired user base.
59
+
- This service doesn't change our pricing structure. You still pay for Defender Experts service based on [E5](before-you-begin-xdr.md#prerequisites-and-licensing) and Microsoft Defender for Endpoint for Servers for your desired user base.
60
60
- This service doesn't scope according to individual Microsoft Defender products and services (such as Microsoft Defender for Endpoint, Microsoft Defender for Office 365, or Microsoft Defender for Cloud). That is, the minimum baseline for scoped coverage is still the E5 license.
61
61
- There's no change in permissions for analysts in Defender Experts for XDR. Defender Experts analysts will still have access to your entire tenant and not just the scoped assets.
0 commit comments