On this page
Service Overview
The Service Add-On for Microsoft Defender for XDR provides continuous monitoring, detection, investigation, and response to security threats generated by in-scope devices with Microsoft Defender for XDR deployed. This service is intended to be delivered in conjunction with DeepSeas Endpoint MDR to maximize visibility and security across the Client's Microsoft devices.
Methodology
- Continuous ingestion and correlation of security telemetry within Microsoft Defender for XDR
- Analyst-led triage to distinguish true threats from false positives
- Execution of response actions and escalation in accordance with agreed runbook
Deliverables
Service Assumptions
- Microsoft Defender for Endpoint is licensed, deployed, and properly configured
- Microsoft Defender for XDR is licensed, deployed, and properly configured
- Required data sources and integrations are accessible to the service team
Client Responsibilities
- Maintain valid Microsoft Defender for XDR licensing
- Maintain required tenant console access to DeepSeas personnel
- Approve response runbook

Back to Service Library