So, What Is ThreatDefender MXDR?

Phil Kinsley

Field CTO, Security

ThreatDefender MXDR extends your security team with 24×7 Microsoft-native monitoring, investigation, response, threat hunting, and continuous hardening. See how eGroup operates Defender, Sentinel, Entra, and the broader Microsoft security environment while customers retain control of their tenant and data.


You’ve seen the marketing materials, you’ve looked at the website, and you might have even watched the video about SARA, but now it’s time to dig into what our ThreatDefender MXDR service actually is, what happens behind the scenes, and what we are really trying to solve for our clients.

Most organizations we work with already own a significant amount of security technology, including endpoint protection, identity protection, email security, SIEM, device management, conditional access and threat intelligence. In a Microsoft environment, that can mean Defender, Sentinel, Entra ID, Defender for Identity, Defender for Office 365, Intune and the broader security stack.

The challenge usually isn’t buying another tool. It is getting everything you already own configured properly, operating together, monitored around the clock and continually improved as both the environment and threat landscape change.

Someone still has to tune it, investigate what it finds, understand how one signal relates to another, decide what requires action, respond when something happens at 2:00 a.m. and work out whether the controls you put in place six months ago are still the right controls today.

That is the problem ThreatDefender is designed to solve.

What Is ThreatDefender MXDR?
ThreatDefender MXDR is eGroup’s Microsoft-native, co-managed Managed Extended Detection and Response service. It extends internal security teams with 24x7x365 monitoring, threat hunting, investigation, response, and security engineering while operating within the Microsoft security environment customers already own.


ThreatDefender Is an Extension of Your Security Team

ThreatDefender is eGroup’s Microsoft-native, co-managed Managed Extended Detection and Response service (MXDR), and the co-managed part is important because the intention is not to take your environment away from you and operate it somewhere else.

ThreatDefender operates and continually improves the security investments already in place while extending your team with 24x7x365 monitoring, threat hunting, investigation, response and security engineering. Your tenant remains your tenant, your security data remains your data, and your analysts can continue working directly within the Microsoft security tools they already know while our SOC works alongside them.

Building this capability internally is absolutely possible, and for some organizations it makes sense, but 24×7 coverage is only part of the equation. You also need threat hunting, detection engineering, platform expertise, mature response processes and people who can keep up with how quickly the Microsoft security ecosystem changes. ThreatDefender gives an existing security team access to those capabilities without requiring them to build an entire security operations organization around the tools they already own.

Instead of sending telemetry into another proprietary security platform, ThreatDefender operates through Microsoft’s native security architecture, including Microsoft Defender, Sentinel and Azure Lighthouse. For organizations already invested heavily in Microsoft security, we are trying to help them get more operational value from those investments rather than build another layer around them.


What Happens Behind the Scenes?

Operationally, ThreatDefender follows a familiar security lifecycle of detect, investigate, contain and remediate, but we add another stage that I think separates an effective managed security service from simply working an alert queue: harden.


Detect

Signals are continuously coming from across the Microsoft security environment, whether that is Defender for Endpoint identifying suspicious activity, Defender for Identity detecting unusual authentication behavior, Defender for Office identifying a malicious message, Entra ID generating an identity risk signal, or Sentinel correlating activity across several systems.

One signal on its own may not mean very much, but several signals around the same user, endpoint or identity can tell a very different story when endpoint, identity, email and cloud activity are looked at together.

ThreatDefender monitors those signals using Microsoft’s detection capabilities, analytics, threat intelligence, custom detection logic and the experience of our analysts and threat hunters.
Across the ThreatDefender service, our current average Mean Time to Detect, or MTTD, is less than five minutes.

That gives the team the opportunity to get an investigation moving quickly and, where necessary, start taking action before an attacker has more time to operate.


Investigate

The original alert is often only the beginning because a useful investigation means understanding what happened before it and afterwards, which user and device were involved, whether an email started the incident, whether persistence was established and whether other identities or systems may also have been affected.

Having endpoint, identity, email, cloud and SIEM telemetry working together allows the investigation to follow the activity rather than forcing an analyst to think in terms of individual products.

ThreatDefender gathers that context, performs automated investigation where appropriate and brings analysts into the process when human judgment is required.


Contain

When an active threat is identified, depending on the circumstances and the response runbooks agreed with the customer, ThreatDefender can take automated or analyst-driven actions such as isolating an endpoint, suspending a compromised identity, blocking malicious infrastructure or using Microsoft’s attack disruption capabilities.

Because ThreatDefender is co-managed, those actions are built around the customer’s environment, risk tolerance and the level of authority it wants the SOC to have when an incident occurs.


Remediate

Containment stops the immediate problem, but remediation deals with everything that follows, including understanding the full scope of the incident, resolving affected systems or identities, documenting what happened and deciding whether something within the environment should change as a result.

ThreatDefender cases are managed through resolution with the investigation history, evidence, analyst activity, response actions and recommendations retained as part of the case, while the eGroup SOC works alongside the customer’s internal teams when they need to be involved.


Then We Harden and Improve the Environment

This is probably the part of ThreatDefender that I spend the most time talking about with clients because closing incidents, while necessary, is only one part of running security operations well.

If an MSSP closes 100 incidents this month and then closes the same 100 incidents next month for many of the same reasons, I’m not convinced we have improved very much.

Learn From Every Incident

A mature security operations program should be learning from what it sees and feeding that knowledge back into the environment. Sometimes that means improving a control or reducing exposure, sometimes it means tuning a noisy detection, creating a new analytic rule or changing a response workflow, and sometimes it means discovering that the customer already owns a capability that has never been fully configured.

There is another part of this that is easy to overlook.


Keep Pace With Microsoft Security

Our team also tries to operate the way a good internal security organization would, which means we are not only looking inward at alerts and incidents. We are continually watching what is changing across Microsoft security, looking at new capabilities, updated detections, product improvements and configuration changes that could improve the environments we support.

Microsoft security changes constantly, and customers should not find out six months later that a capability they already owned could have helped solve a problem they were dealing with today.

The team reviews those changes through the lens of the environments we actually operate rather than simply repeating every Microsoft product announcement. When we see something relevant, we bring it into the regular customer cadence calls and talk through whether it should be adopted, tested, configured differently or simply watched for now.

That could be a new Defender capability, a change in Sentinel, an improvement in Exposure Management, a new identity protection control or a better way of automating an investigation.


Turn Insights Into Action

The cadence call should not be a monthly reading of ticket statistics.

It should be a conversation about what we have seen, what we have learned, what has changed and what we should do next.

That is also where the broader ThreatDefender posture and optimization program comes together, with Secure Score and Exposure Management reviews, Defender and Sentinel tuning, configuration recommendations, detection improvements, hardening activity and ongoing conversations about relevant changes across the Microsoft security ecosystem.

We are looking at why activity was possible in the first place, whether the same exposure exists elsewhere, whether we are producing unnecessary noise, whether important signals are missing and whether there is now a better way to solve the problem.

Your security environment should be better six months after ThreatDefender is deployed than it was on day one.

Not because another product was added, but because the technology you already own is being continually operated, tuned and improved.


The ThreatDefender Portal Changes the Experience

Microsoft provides an enormous amount of security information across its various portals, but consuming all of that information from an operational or executive perspective can still be difficult.

The ThreatDefender client portal gives customers a consolidated view across the service without attempting to replace the Microsoft security tools underneath it.

At an executive level, that means seeing incident volume, investigations, detection trends, triage performance, response and resolution performance and overall SOC activity, including our current average Mean Time to Detect of less than five minutes across the service, without moving between several security consoles.

For security teams, the portal provides an incident workspace containing investigation history, evidence, entities, analyst activity, response details and summaries, while reporting extends into areas such as Secure Score, Exposure Management, identity and device posture, Sentinel health, threat intelligence, email security and Sentinel ingestion and cost.

The portal is not trying to become another SIEM or XDR platform sitting on top of Microsoft.

It is there to make the service easier to consume.


And Then There Is SARA

SARA stands for Security Analysis & Response Agent, and it is our AI-enabled incident assistant built into the ThreatDefender experience.

Traditionally, if you wanted to understand an incident that happened several days ago, you might open a ticket, read through a lengthy case history, work through analyst notes or ask someone to walk you through it.

With SARA, you can interact with the incident conversationally and ask what happened, which users or devices were involved, what evidence was found, what actions were taken and how the incident was resolved. SARA uses the context already available within the case to generate summaries and help someone work through the investigation without reconstructing everything manually.

That does not mean replacing the analyst. There are situations where you absolutely want to speak to the people who investigated an incident or understand the reasoning behind a particular response.

SARA simply removes some of the friction between the customer and information already inside the service, so every question does not require another ticket, email or meeting with the SOC.


What Is Actually Different Here?

If you step back from the individual capabilities, the differences are fairly straightforward. We operate the Microsoft security environment the customer already owns rather than introducing another proprietary platform, the customer retains its tenant and security data, and our SOC works alongside the internal security team rather than replacing it.

The service also does not stop when an incident is closed. We continually tune, harden and improve the environment while watching what is changing across Microsoft security and bringing relevant updates and recommendations into the regular customer cadence.

That combination is really the ThreatDefender model: operate the environment, respond when something happens, learn from it and make the environment better afterwards.


The Architecture Is Deliberately Boring

And I mean that as a compliment.

The customer environment sends telemetry into the Microsoft security services it was designed to use, with Defender protecting endpoints, identities and email, Entra providing identity signals, Sentinel providing SIEM and SOAR capabilities, and Intune contributing device context and management.

eGroup securely accesses the appropriate services through Microsoft’s delegated management architecture and Azure Lighthouse, allowing our SOC analysts and threat hunters to monitor, investigate and respond while the customer’s analysts retain visibility into the same underlying Microsoft environment.

The data does not need to be copied into an eGroup SIEM or proprietary security data lake simply for us to provide the service, so customers retain control of their data and their existing Microsoft security environment.

What Does Microsoft-Native MXDR Mean?
ThreatDefender works through the customer’s existing Microsoft security architecture rather than requiring security telemetry to be moved into a separate eGroup SIEM or proprietary security data lake. Customers retain control of their Microsoft environment and security data while eGroup’s SOC works alongside their internal team.


Why Build This Around Microsoft?

The answer is largely driven by what we see in real customer environments.

Many organizations already own an extraordinary amount of security capability through Microsoft, but owning that capability and operating it effectively are two very different things. We see environments where important controls have never been fully configured, detections have not been tuned, Secure Score recommendations have accumulated, Sentinel has become noisy or expensive, or individual security products are still being operated separately rather than as one connected system.

Buying more technology does not necessarily fix those problems.

Operating the technology better does.

Our Microsoft Intelligent Security Association membership and Microsoft Verified MXDR Provider status provide useful validation of the service, but the real test is what happens inside the customer environment once ThreatDefender is running.

Are incidents being identified faster?
Are analysts spending less time chasing noise?
Are controls improving?
Is exposure decreasing?
Is Sentinel becoming more useful and efficient?
Is the customer getting more operational value from security technology it is already paying for?

That is how I would judge whether the service is doing its job.


Managed Doesn’t Have to Mean Outsourced

Managed security does not have to mean handing your environment to someone else and losing visibility into what is happening.

It can mean adding capabilities an internal team could not reasonably maintain around the clock, bringing additional expertise into difficult investigations, automating repetitive work and having another group continually looking for ways to improve the environment.

Your team still owns the security program.

ThreatDefender gives them more people, more coverage and more operational capability to run it.

That’s really what ThreatDefender MXDR is.

Is ThreatDefender Fully Outsourced?
No. ThreatDefender is designed as a co-managed security service. The customer continues to own the security program, tenant, and underlying Microsoft environment, while the eGroup SOC adds 24×7 coverage, investigation, response, threat hunting, and security engineering capabilities.


Extend Your Security Team

Get 24×7 Microsoft security operations without building another SOC or replacing the tools you already own. See how ThreatDefender MXDR can help your team detect, respond, and continuously improve.

Get in Touch with Us

Connect with an expert to learn what we can do for your business.

Request Access to Win Wires

Enter your work email to request access to the eGroup Win Wires repository.

By requesting access, you confirm you are using an approved business email domain. You’ll receive a secure, one-time login link after returning to the Win Wires page.