This is the Trace Id: 176e8368ecfb1afcd3f317ee49d3a2d7
跳转至主内容 Microsoft Defender Microsoft Entra Microsoft Intune Microsoft Purview 智能 Microsoft Security Copilot 副驾驶® Microsoft Sentinel 查看所有产品 AI 支持的网络安全 云安全 数据安全与治理 标识和网络访问 AI 安全性 中小型企业 统一安全运营 零信任 价格 服务 合作伙伴 为什么选择 Microsoft 安全 网络安全意识 客户案例 安全性 101 产品试用 行业认可 安全响应中心 Microsoft 安全博客 Microsoft 安全活动 Microsoft 技术社区 文件 技术内容库 培训和认证 Microsoft Cloud 合规性计划 Microsoft 信任中心 服务信任门户 Microsoft 安全未来计划 业务解决方案中心 连络销售人员 开始免费试用 Microsoft 安全 Azure Dynamics 365 Microsoft 365 Microsoft Teams Windows 365 Microsoft AI Azure Space 混合现实 Microsoft HoloLens Microsoft Viva 量子计算 教育 汽车 金融服务 政府 医疗保健 制造业 零售业 查找合作伙伴 成为合作伙伴 合作伙伴网络 Microsoft Marketplace 软件公司 博客 Microsoft Advertising 开发人员中心 文档 活动 许可 Microsoft Learn Microsoft Research 查看站点地图

Microsoft Defender Experts MDR

Stop attackers with always-on, AI-accelerated managed detection and response (MDR), expert-led and natively integrated in Microsoft Defender.
Two persons are looking at the desktop screen
Overview

Around the clock, expert-led defense

Engage managed detection and response and proactive threat hunting with Defender Experts MDR, helping security teams stop and prevent future attacks.
  • Rely on our experts to triage and investigate prioritized incidents to focus on threats that require immediate attention.
  • Contain and mitigate incidents fast with managed response and proactive remediation.
  • Extend your team’s capacity with around-the-clock assistance from security experts via live chat.
  • Reduce risk over time with detailed recommendations to improve your overall security posture.
CAPABILITIES

Explore the features of Defender Experts MDR

Built-in defense

Get natively integrated with MDR for protection across endpoints, identities, email, cloud apps, and cloud workloads.

Human expertise

Rely on human security experts with combined experience of 600+ years to deliver continuous coverage.

AI and agentic AI

Gain fast, efficient response with service powered by automation, AI, and agentic AI

Proactive threat hunting

Uncover novel threats before they escalate, using around-the-clock, AI-powered proactive threat hunting.

Extensive threat intelligence

Stay ahead of evolving risks via 100+ trillion daily signals analyzed by more than 10,000 security experts.

Access to experts

Consult service delivery engineers and experts for ongoing insights on the latest in the threat landscape.

Human and AI collaboration for better security

Discover how Defender Experts is striving to be a trusted parter in SOC evolution and using automation, AI, and agentic AI to deliver faster response.

Bolster your SOC with Defender Experts MDR

Get alert triage, incident analysis, and managed response, plus proactive recommendations around the clock—all with Defender Experts MDR.
VIDEO

Defend against evolving threats

See how Defender Experts stopped a ClickFix attack through early detection, threat intel, and expert-led response.

Frequently asked questions

  • Microsoft Defender Experts Hunting provides proactive threat hunting service to find threats. This service is meant for customers who have a robust security operations center (SOC) and want that deep expertise in hunting to expose advanced threats. Microsoft Defender Experts MDR provides end-to-end security operations capabilities to monitor, investigate, and respond to security alerts. This service is meant for customers with constrained SOCs that are overburdened with alert volume, in need of skilled experts, or both. Defender Experts MDR also includes the proactive threat hunting offered by Defender Experts Hunting.
  • Defender Experts MDR provides managed detection and response across any combination of the following Microsoft Defender products:
    • Defender for Endpoint
    • Defender for Office 365 P2
    • Defender for Identity
    • Defender for Cloud Apps
    • Microsoft Entra ID P2
    • Microsoft Defender for Cloud (with Defender Experts for Servers)
    Refer to documentation for more details.
  • Microsoft expert analysts can take actions based on the roles granted to them in Microsoft Defender. These analysts can investigate and provide managed response for your SOC team to act on. They can also take specific remediation actions agreed upon with your SOC team.
  • Defender Experts MDR covers incidents categorized as High or Medium severity in Windows, Linux, and macOS devices. Incidents categorized as Compliance, Data Loss Prevention (DLP), or Custom Detections and those affecting internet of things (IoT), iOS, or Android devices are outside the service's scope.
Get started

Enhance your security with expert-led services

Help make your future more secure. Get started today.

关注 Microsoft 安全