Lesson 33 — Working with Microsoft Defender Experts
Microsoft Defender Experts services extend the internal SOC with Microsoft-managed incident investigation, response guidance and proactive threat hunting.
Security Copilot can help prepare incident evidence, generate hunting queries and compare findings, while Microsoft experts contribute human investigation and threat-hunting experience.
This lesson explains how to combine Microsoft experts, AI assistance and internal analyst judgement while preserving permissions, response boundaries, business context and customer accountability.

What you will learn
This lesson develops a collaborative Microsoft experts and internal SOC operating model.
Defender Experts collaboration workflow
↓
Security Copilot prepares a structured evidence brief
↓
Microsoft experts triage, investigate or hunt
↓
Expert findings and recommendations are delivered
↓
Internal SOC reviews sources, confidence and business context
↓
Differences and missing evidence are investigated
↓
Authorised response actions are approved or performed
↓
Action success and residual risk are validated
↓
Technical and executive reporting is completed
↓
Detections, controls and service runbooks are improved
Collaborative security operating model
| Participant | Contribution | Core question |
|---|---|---|
| Security Copilot | AI-assisted summaries, queries, enrichment and reporting. | How can evidence be prepared faster? |
| Defender Experts MDR | Managed triage, investigation, response guidance and collaboration. | How can Microsoft extend incident operations? |
| Defender Experts Hunting | Proactive threat hunting across supported Microsoft data. | What threats may exist beyond current incidents? |
| Internal SOC | Business context, validation, approvals and organisational response. | What does the evidence mean for the business? |
| Permissions | Reader or operator capabilities and agreed action boundaries. | What may Microsoft experts access or change? |
| Governance | Ownership, audit, privacy, escalation and service review. | Who remains accountable? |
Learning objectives
- Understand Defender Experts MDR and Hunting.
- Separate Copilot assistance from human expert services.
- Define shared responsibilities and response boundaries.
- Use appropriate expert permissions.
- Validate expert findings and recommendations.
- Measure hunting and managed-response value.
- Preserve customer governance and accountability.
What are Microsoft Defender Experts?
Microsoft Defender Experts are Microsoft-managed security services that extend customer SOC investigation, response and threat-hunting capabilities.
Defender Experts MDR
Defender Experts MDR provides managed detection and response across the Microsoft Defender incident queue in partnership with the customer security team.
Defender Experts Hunting
Defender Experts Hunting provides proactive threat hunting across supported Microsoft Defender data.
Hunting beyond endpoints
Defender Experts Hunting can hunt across endpoints, Microsoft 365, cloud applications and identity telemetry.
Server hunting
Defender Experts Hunting for Servers supports proactive hunting across hybrid and multicloud server environments.
MDR includes proactive hunting
Defender Experts Hunting is integrated into the MDR service to help prioritise significant threats.
Security Copilot is different
Security Copilot is an AI-assisted security platform, while Defender Experts services include Microsoft human analysts and managed workflows.
Internal SOC remains essential
Customer analysts provide business context, own risk decisions and coordinate organisational response.
Shared responsibility
Microsoft experts, Security Copilot and the internal SOC contribute different strengths to one investigation.
Microsoft analyst role
Microsoft experts can triage, investigate, hunt, recommend actions and collaborate with the customer team.
Customer analyst role
The customer validates business impact, approves response, manages local dependencies and accepts residual risk.
Security Copilot role
Copilot can summarise incidents, generate queries, enrich indicators and prepare evidence for review.
Do not confuse assistance with ownership
External assistance does not transfer accountability for business and regulatory decisions.
Service prerequisites
Defender Experts services require supported licensing, products, onboarding and configured access.
Data quality matters
Experts can only investigate evidence available through connected and healthy Microsoft security products.
Permissions define capability
The roles granted to Microsoft experts determine which investigation and response actions they can perform.
Security Reader access
With read-oriented permissions, experts can investigate and provide managed-response recommendations for the customer SOC.
Security Operator access
With agreed operator permissions, experts can take specific remediation actions within the configured service model.
Use least privilege
Grant only the permissions required for the agreed service scope.
Cross-tenant access
Defender Experts permissions can use configured cross-tenant role assignments for Microsoft analysts.
Review access regularly
Permissions should be reviewed after scope, staffing, licensing or service changes.
Define response boundaries
Document which actions Microsoft may take automatically, after approval or only recommend.
Define communication paths
Identify operational, management, privacy, legal and business contacts.
Define escalation criteria
Agree which incident conditions require immediate customer engagement.
Define service expectations
Understand coverage, communication channels, response processes and customer obligations.
Prepare the environment
Healthy sensors, connectors, identity telemetry and endpoint coverage improve service effectiveness.
Onboard critical assets
Ensure important users, devices, servers, mailboxes and cloud workloads are visible.
Maintain accurate ownership
Resource, device and user ownership helps experts assess business relevance.
Provide business context
Critical systems, maintenance windows and approved tools may not be obvious from telemetry alone.
Incident triage
Defender Experts MDR can review incidents, alerts, evidence and initial severity.
Incident investigation
Experts can analyse entities, timelines, process trees, identities and related activity.
Managed response
The service can provide recommended response actions and, where authorised, execute agreed actions.
Proactive hunting
Experts search for threats that may not have generated complete incidents.
Threat intelligence
Microsoft intelligence can support campaign, actor, malware and infrastructure context.
Investigation recommendations
Recommendations should identify evidence, affected scope and intended risk reduction.
Customer validation
The internal SOC should verify the recommendation against business context and current evidence.
Response approval
High-impact actions should follow the organisation’s approval model.
Security Copilot preparation
Use Copilot to create a concise incident brief before reviewing expert findings.
Copilot evidence summary
Summarise alerts, entities, timelines, indicators and unresolved questions.
Copilot hunting support
Generate focused KQL to validate or extend an expert hunting observation.
Copilot comparison prompt
Compare internal findings with Defender Experts recommendations and identify differences.
Copilot reporting support
Draft technical and executive updates from validated expert and internal findings.
Review original evidence
Do not rely only on a Copilot summary or expert recommendation.
Check incident identity
Confirm incident, alert, tenant, device, user and time range.
Check source records
Open original events, query rows, entity pages and investigation evidence.
Check recommendation rationale
Understand why the action was proposed and which evidence supports it.
Check confidence
Separate confirmed observations, likely conclusions and unresolved possibilities.
Check missing telemetry
Identify unavailable products, devices, workspaces and time periods.
Check business impact
Evaluate service dependencies, operational risk and user impact.
Check response feasibility
Confirm that the organisation can safely perform the recommended action.
Check action completion
Verify whether remediation succeeded and record the outcome.
Collaborative investigation
Internal analysts and Microsoft experts can work from the same incident while preserving roles and ownership.
Avoid duplicate work
Share validated findings, queries, actions and open questions clearly.
Use structured handovers
Record current status, scope, confidence, evidence, recommendations and owners.
Document disagreements
When analysts disagree, preserve both interpretations and identify the evidence needed to resolve them.
Escalate uncertainty
Complex malware, identity, cloud or attribution questions may require specialist review.
Threat-hunting findings
Defender Experts Hunting surfaces findings and alerts from proactive searches.
Hunting reports
Service reports help customers review threats surfaced by hunting over selected reporting periods.
Review hunting trends
Look for recurring techniques, affected assets, visibility gaps and control weaknesses.
Convert findings to detections
Validated hunting discoveries can improve internal analytics and custom detections.
Convert findings to controls
Use repeated findings to improve configuration, hardening and identity controls.
Measure service value
Assess validated findings, investigation depth, time saved and detection improvements.
Do not count alerts alone
A high alert count does not necessarily indicate better service value.
Measure coverage improvements
Track new telemetry, onboarded assets and previously hidden attack paths.
Measure response outcomes
Review time to understand, contain and recover.
Measure recommendation quality
Track accepted, modified and rejected recommendations and why.
Measure collaboration quality
Review handover clarity, response coordination and unresolved ownership.
Common mistake: blind trust
Microsoft expertise should be respected but still validated against customer context.
Common mistake: ignoring recommendations
Repeatedly dismissing expert findings without evidence wastes service value.
Common mistake: unclear ownership
Incidents can stall when response responsibility is not assigned.
Common mistake: insufficient permissions
Experts cannot deliver the agreed service if access is incomplete.
Common mistake: excessive permissions
Overprivileged access increases risk without improving every workflow.
Common mistake: poor telemetry
Missing or unhealthy data limits investigation and hunting.
Common mistake: no business context
Legitimate administration can be mistaken for suspicious activity.
Common mistake: no follow-through
Recommendations have little value if actions are not assigned and verified.
Common mistake: no learning loop
Closing incidents without updating detections and controls loses long-term value.
Use a service runbook
Document contacts, permissions, action boundaries, escalation and evidence requirements.
Use regular reviews
Review service findings, hunting reports, access, coverage and operational issues.
Train internal analysts
The SOC should understand the service, recommendations and escalation process.
Preserve auditability
Record Microsoft actions, customer approvals, evidence and final decisions.
Protect sensitive information
Expert collaboration can involve personal, confidential or regulated investigation data.
Retain customer accountability
The customer remains responsible for organisational governance and business decisions.
Use another pair of eyes
Expert review is most valuable when the incident is complex, high impact or incomplete.
Final analyst judgement
Microsoft experts and Security Copilot strengthen the investigation, but the authorised customer team approves the final outcome.
Example collaborative investigation prompt
Include:
1. Correct incident, alert, user and device identifiers
2. Validated incident summary and current status
3. Complete timeline with source evidence
4. Identity, endpoint, email and cloud findings
5. KQL queries and representative raw rows
6. Enriched indicators and threat-intelligence context
7. Containment actions already completed
8. Missing telemetry and unresolved questions
9. Internal analyst confidence and alternative explanations
10. Specific questions requiring expert review
Do not present unverified Copilot conclusions as confirmed evidence.
Agent Foskett investigation: “A second pair of eyes”
↓
Security Copilot had assembled the timeline
↓
The internal SOC had identified two compromised devices
↓
Containment appeared complete
↓
Agent Foskett requested expert review
↓
Microsoft analysts examined the network and hunting evidence
↓
A second command-and-control IP was identified
↓
The indicator had appeared on another workstation
↓
The third device had no ransomware alert
↓
It contained the same persistence mechanism
↓
The original investigation was not wrong
↓
It was not finished
↓
Containment expanded to the third device
↓
The detection was updated
↓
The incident closed with the complete scope
Defender Experts collaboration checklist
| Area | Question | Validation action |
|---|---|---|
| Service | Is MDR, Hunting or another service in scope? | Confirm licensing and service model. |
| Coverage | Are required products and assets onboarded? | Check sensors, connectors and telemetry. |
| Permissions | What may Microsoft experts read or change? | Review roles and action boundaries. |
| Context | Has business criticality and approved activity been supplied? | Maintain asset and owner information. |
| Evidence | Do recommendations cite supporting data? | Open alerts, queries and entity records. |
| Confidence | Are findings confirmed, probable or unresolved? | Record confidence and missing evidence. |
| Action | Who approves and performs remediation? | Follow the agreed response model. |
| Audit | Are expert and customer actions recorded? | Preserve timestamps, identities and outcomes. |
| Learning | Did the engagement improve detections or controls? | Update rules, playbooks and coverage. |
| Ownership | Who approves final incident closure? | Retain customer accountability. |
Key takeaways
- Defender Experts MDR provides managed detection and response in partnership with the customer SOC.
- Defender Experts Hunting provides proactive hunting across endpoints, Microsoft 365, cloud applications and identity data.
- Security Copilot provides AI-assisted investigation support rather than replacing Microsoft or customer analysts.
- Permissions determine whether Microsoft experts provide recommendations or perform agreed remediation actions.
- Healthy telemetry, asset ownership and business context improve expert effectiveness.
- Expert recommendations should be validated against original evidence and operational impact.
- Hunting reports can reveal recurring threats, coverage gaps and detection opportunities.
- Internal SOC teams retain responsibility for governance, approvals and business-risk decisions.
- Service value should be measured through validated findings, response outcomes and improved controls.
- The customer remains accountable for final incident closure and residual risk.
What Agent Foskett shared
- Incident identifiers
- Validated timeline
- Affected devices
- KQL results
- Indicators
- Containment status
- Missing evidence
- Open questions
- Business context
- Response boundaries
Best practices
- Define service scope.
- Use least privilege.
- Maintain healthy telemetry.
- Provide business context.
- Validate recommendations.
- Document disagreements.
- Verify actions.
- Review hunting trends.
- Improve detections.
- Retain customer ownership.
Related Agent Foskett resources
Continue Module 4 — Operational Security Copilot
What is Microsoft Defender Experts MDR?
Microsoft Defender Experts MDR provides managed incident triage, investigation, response guidance and proactive threat hunting in partnership with a customer security operations team.
What is Microsoft Defender Experts Hunting?
Defender Experts Hunting is a proactive threat-hunting service across supported endpoint, Microsoft 365, cloud-application and identity data.
Security Copilot and Defender Experts
Security Copilot accelerates evidence preparation and analysis, while Microsoft Defender Experts contribute managed human investigation and hunting expertise and the customer retains business ownership.
