Microsoft Defender Experts Suite is an enterprise security offering that combines expert-led services, including Defender Experts for XDR, Microsoft Incident Response, and Microsoft Designated Engineering. Its two plans differ mainly in the security data Microsoft manages: Plan 1 covers Microsoft Defender workloads, while Plan 2 also extends triage and investigation to selected third-party telemetry in Microsoft Sentinel. Microsoft does not publish a standard price on its pricing page; organizations must contact Microsoft Security Sales.
What is Microsoft Defender Experts Suite?
Microsoft Defender Experts Suite packages expert-led security services for organizations that want help strengthening security operations and responding to threats. It is a broader offering than Defender Experts MDR alone: according to Microsoft’s pricing page, both Suite plans include Defender Experts for XDR, Microsoft Incident Response, and Microsoft Designated Engineering. Plan 2 also includes Microsoft Unified Enterprise for Defender Experts Suite.
Defender Experts MDR is the managed detection and response service within this picture. Microsoft security analysts manage an incident queue, investigate incidents, and either take response actions or guide the organization’s own team. Microsoft describes the service as augmenting a customer’s security operations center (SOC), not replacing it. The customer should therefore expect to retain internal security responsibilities and coordinate with Microsoft on response.
What does Defender Experts MDR include?
Microsoft Learn lists these MDR capabilities for Plan 1:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Managed detection and response for Microsoft Defender workloads.
- Proactive threat hunting.
- Ask Defender Experts.
- Live dashboards and reports.
- Proactive check-ins.
Microsoft analysts triage and investigate incidents on the customer’s behalf, then take action or guide the customer’s team through response. The precise response authority and actions should be confirmed with Microsoft as part of evaluating service terms; the service is designed to work alongside the organization’s SOC.
How do MDR Plan 1 and Plan 2 differ?
| Plan | Telemetry and investigation scope | Included MDR capabilities | Important requirement or limitation |
|---|---|---|---|
| MDR Plan 1 | Microsoft Defender workloads. | Managed detection and response, proactive threat hunting, Ask Defender Experts, live dashboards and reports, and proactive check-ins. | Third-party network signal enrichment is deprecated effective September 1, 2026, and is closed to new enablement. Existing enrichment continues until the next renewal. |
| MDR Plan 2 | Includes Plan 1 and extends expert triage and investigation to selected non-Microsoft telemetry collected in Microsoft Sentinel. | All Plan 1 capabilities, with the extended investigation scope. | Requires Microsoft Sentinel. Coverage applies to selected third-party telemetry, not necessarily every product or signal an organization uses. |
The practical distinction is data scope. Plan 1 is centered on Microsoft Defender workloads. Plan 2 is aimed at organizations that want a managed service across Microsoft signals and supported third-party data routed through Sentinel. The Plan 1 network-enrichment lifecycle change is narrower than Plan 2’s Sentinel-based third-party telemetry scope; do not treat the former as an equivalent alternative to Plan 2.
Rank #2
Does Defender Experts cover non-Microsoft security tools?
Plan 2 can include expert triage and investigation of selected non-Microsoft telemetry collected in Microsoft Sentinel. That does not establish universal support for every third-party security tool, data source, or alert type. Organizations should confirm that their specific products and telemetry are supported and that the relevant data is available in Sentinel.
For Plan 1, Microsoft says third-party network signal enrichment is deprecated as of September 1, 2026, and new enablement is closed. Organizations already using that enrichment can continue until their next renewal. This is a time-sensitive Plan 1 exception, not evidence that Plan 1 has the broader third-party coverage described for Plan 2.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWhat other Defender Experts services are available?
Microsoft’s broader Defender Experts portfolio includes services beyond MDR. Their names indicate different security needs, so they should not be assumed to be interchangeable with MDR or automatically included in every Suite plan.
- Defender Experts Hunting: Proactive threat hunting. Microsoft describes Defender Experts Hunting – XDR as hunting across endpoints, Microsoft 365, cloud applications, and identity for organizations with a robust SOC.
- Defender Experts for Servers: A named service in the Defender Experts portfolio.
- Defender Experts Threat Intelligence: A named service in the portfolio.
- Defender Experts Cybersecurity Incident Response: A named incident-response service; the Suite plans separately list Microsoft Incident Response as an included component.
Microsoft’s portfolio list does not, by itself, specify the full scope, prerequisites, or inclusion terms for each separately named service. Confirm those details for the offering and plan under consideration.
How much does Microsoft Defender Experts Suite cost?
Microsoft’s pricing page does not state a public list price for the Suite. It directs prospective customers to Microsoft Security Sales, and pricing varies by plan. No recurring rate, per-user amount, or standard contract price is established by the published information cited here. Contact Microsoft Security Sales for a quote and confirm current eligibility, licensing prerequisites, and plan terms before purchase.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to decide whether the Suite fits your organization
Assess the service against your operating model rather than treating Plan 2 as automatically better because it covers more telemetry.
Recommended Free Tools
Quick Recap
Best Value
- Map the telemetry you need investigated. If the relevant signals are Microsoft Defender workloads, Plan 1 may align with that scope. If you need investigation of selected third-party signals, check Plan 2’s supported sources and Sentinel requirements with Microsoft.
- Check Sentinel readiness. Plan 2 requires Microsoft Sentinel. Establish whether your organization has it deployed and whether the data you care about is collected there.
- Match the service to your SOC. MDR augments the customer’s SOC. Consider your team’s ability to coordinate with Microsoft, act on guidance, and retain internal response responsibilities.
- Clarify response authority. Determine which actions Microsoft may take and which require your team’s involvement; the service description allows for either action by analysts or guidance to the customer.
- Separate MDR from the other Suite components. Both Suite plans list Defender Experts for XDR, Microsoft Incident Response, and Microsoft Designated Engineering; Plan 2 additionally lists Microsoft Unified Enterprise for Defender Experts Suite. Confirm what each component means for your contract and needs.
- Verify current commercial terms. Ask Microsoft Security Sales to confirm pricing, prerequisites, supported telemetry, eligibility, and any lifecycle changes that affect your existing or proposed configuration.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

