Agent Foskett Academy • Microsoft Security Copilot • Module 4 • Lesson 33

Lesson 33 — Working with Microsoft Defender Experts

Microsoft Defender Experts services extend the internal SOC with Microsoft-managed incident investigation, response guidance and proactive threat hunting.

Security Copilot can help prepare incident evidence, generate hunting queries and compare findings, while Microsoft experts contribute human investigation and threat-hunting experience.

This lesson explains how to combine Microsoft experts, AI assistance and internal analyst judgement while preserving permissions, response boundaries, business context and customer accountability.

The best investigators are never afraid to ask for another pair of eyes.
Agent Foskett Working with Microsoft Defender Experts lesson
What you will learn

This lesson develops a collaborative Microsoft experts and internal SOC operating model.

✓ Defender Experts MDR and Hunting
✓ Permissions and response boundaries
✓ Copilot-assisted collaboration
✓ Validation and customer ownership

Defender Experts collaboration workflow

Microsoft Defender incident or hunting finding

Security Copilot prepares a structured evidence brief

Microsoft experts triage, investigate or hunt

Expert findings and recommendations are delivered

Internal SOC reviews sources, confidence and business context

Differences and missing evidence are investigated

Authorised response actions are approved or performed

Action success and residual risk are validated

Technical and executive reporting is completed

Detections, controls and service runbooks are improved

Collaborative security operating model

ParticipantContributionCore question
Security CopilotAI-assisted summaries, queries, enrichment and reporting.How can evidence be prepared faster?
Defender Experts MDRManaged triage, investigation, response guidance and collaboration.How can Microsoft extend incident operations?
Defender Experts HuntingProactive threat hunting across supported Microsoft data.What threats may exist beyond current incidents?
Internal SOCBusiness context, validation, approvals and organisational response.What does the evidence mean for the business?
PermissionsReader or operator capabilities and agreed action boundaries.What may Microsoft experts access or change?
GovernanceOwnership, audit, privacy, escalation and service review.Who remains accountable?

Learning objectives

  • Understand Defender Experts MDR and Hunting.
  • Separate Copilot assistance from human expert services.
  • Define shared responsibilities and response boundaries.
  • Use appropriate expert permissions.
  • Validate expert findings and recommendations.
  • Measure hunting and managed-response value.
  • Preserve customer governance and accountability.

What are Microsoft Defender Experts?

Microsoft Defender Experts are Microsoft-managed security services that extend customer SOC investigation, response and threat-hunting capabilities.

Defender Experts MDR

Defender Experts MDR provides managed detection and response across the Microsoft Defender incident queue in partnership with the customer security team.

Defender Experts Hunting

Defender Experts Hunting provides proactive threat hunting across supported Microsoft Defender data.

Hunting beyond endpoints

Defender Experts Hunting can hunt across endpoints, Microsoft 365, cloud applications and identity telemetry.

Server hunting

Defender Experts Hunting for Servers supports proactive hunting across hybrid and multicloud server environments.

MDR includes proactive hunting

Defender Experts Hunting is integrated into the MDR service to help prioritise significant threats.

Security Copilot is different

Security Copilot is an AI-assisted security platform, while Defender Experts services include Microsoft human analysts and managed workflows.

Internal SOC remains essential

Customer analysts provide business context, own risk decisions and coordinate organisational response.

Shared responsibility

Microsoft experts, Security Copilot and the internal SOC contribute different strengths to one investigation.

Microsoft analyst role

Microsoft experts can triage, investigate, hunt, recommend actions and collaborate with the customer team.

Customer analyst role

The customer validates business impact, approves response, manages local dependencies and accepts residual risk.

Security Copilot role

Copilot can summarise incidents, generate queries, enrich indicators and prepare evidence for review.

Do not confuse assistance with ownership

External assistance does not transfer accountability for business and regulatory decisions.

Service prerequisites

Defender Experts services require supported licensing, products, onboarding and configured access.

Data quality matters

Experts can only investigate evidence available through connected and healthy Microsoft security products.

Permissions define capability

The roles granted to Microsoft experts determine which investigation and response actions they can perform.

Security Reader access

With read-oriented permissions, experts can investigate and provide managed-response recommendations for the customer SOC.

Security Operator access

With agreed operator permissions, experts can take specific remediation actions within the configured service model.

Use least privilege

Grant only the permissions required for the agreed service scope.

Cross-tenant access

Defender Experts permissions can use configured cross-tenant role assignments for Microsoft analysts.

Review access regularly

Permissions should be reviewed after scope, staffing, licensing or service changes.

Define response boundaries

Document which actions Microsoft may take automatically, after approval or only recommend.

Define communication paths

Identify operational, management, privacy, legal and business contacts.

Define escalation criteria

Agree which incident conditions require immediate customer engagement.

Define service expectations

Understand coverage, communication channels, response processes and customer obligations.

Prepare the environment

Healthy sensors, connectors, identity telemetry and endpoint coverage improve service effectiveness.

Onboard critical assets

Ensure important users, devices, servers, mailboxes and cloud workloads are visible.

Maintain accurate ownership

Resource, device and user ownership helps experts assess business relevance.

Provide business context

Critical systems, maintenance windows and approved tools may not be obvious from telemetry alone.

Incident triage

Defender Experts MDR can review incidents, alerts, evidence and initial severity.

Incident investigation

Experts can analyse entities, timelines, process trees, identities and related activity.

Managed response

The service can provide recommended response actions and, where authorised, execute agreed actions.

Proactive hunting

Experts search for threats that may not have generated complete incidents.

Threat intelligence

Microsoft intelligence can support campaign, actor, malware and infrastructure context.

Investigation recommendations

Recommendations should identify evidence, affected scope and intended risk reduction.

Customer validation

The internal SOC should verify the recommendation against business context and current evidence.

Response approval

High-impact actions should follow the organisation’s approval model.

Security Copilot preparation

Use Copilot to create a concise incident brief before reviewing expert findings.

Copilot evidence summary

Summarise alerts, entities, timelines, indicators and unresolved questions.

Copilot hunting support

Generate focused KQL to validate or extend an expert hunting observation.

Copilot comparison prompt

Compare internal findings with Defender Experts recommendations and identify differences.

Copilot reporting support

Draft technical and executive updates from validated expert and internal findings.

Review original evidence

Do not rely only on a Copilot summary or expert recommendation.

Check incident identity

Confirm incident, alert, tenant, device, user and time range.

Check source records

Open original events, query rows, entity pages and investigation evidence.

Check recommendation rationale

Understand why the action was proposed and which evidence supports it.

Check confidence

Separate confirmed observations, likely conclusions and unresolved possibilities.

Check missing telemetry

Identify unavailable products, devices, workspaces and time periods.

Check business impact

Evaluate service dependencies, operational risk and user impact.

Check response feasibility

Confirm that the organisation can safely perform the recommended action.

Check action completion

Verify whether remediation succeeded and record the outcome.

Collaborative investigation

Internal analysts and Microsoft experts can work from the same incident while preserving roles and ownership.

Avoid duplicate work

Share validated findings, queries, actions and open questions clearly.

Use structured handovers

Record current status, scope, confidence, evidence, recommendations and owners.

Document disagreements

When analysts disagree, preserve both interpretations and identify the evidence needed to resolve them.

Escalate uncertainty

Complex malware, identity, cloud or attribution questions may require specialist review.

Threat-hunting findings

Defender Experts Hunting surfaces findings and alerts from proactive searches.

Hunting reports

Service reports help customers review threats surfaced by hunting over selected reporting periods.

Review hunting trends

Look for recurring techniques, affected assets, visibility gaps and control weaknesses.

Convert findings to detections

Validated hunting discoveries can improve internal analytics and custom detections.

Convert findings to controls

Use repeated findings to improve configuration, hardening and identity controls.

Measure service value

Assess validated findings, investigation depth, time saved and detection improvements.

Do not count alerts alone

A high alert count does not necessarily indicate better service value.

Measure coverage improvements

Track new telemetry, onboarded assets and previously hidden attack paths.

Measure response outcomes

Review time to understand, contain and recover.

Measure recommendation quality

Track accepted, modified and rejected recommendations and why.

Measure collaboration quality

Review handover clarity, response coordination and unresolved ownership.

Common mistake: blind trust

Microsoft expertise should be respected but still validated against customer context.

Common mistake: ignoring recommendations

Repeatedly dismissing expert findings without evidence wastes service value.

Common mistake: unclear ownership

Incidents can stall when response responsibility is not assigned.

Common mistake: insufficient permissions

Experts cannot deliver the agreed service if access is incomplete.

Common mistake: excessive permissions

Overprivileged access increases risk without improving every workflow.

Common mistake: poor telemetry

Missing or unhealthy data limits investigation and hunting.

Common mistake: no business context

Legitimate administration can be mistaken for suspicious activity.

Common mistake: no follow-through

Recommendations have little value if actions are not assigned and verified.

Common mistake: no learning loop

Closing incidents without updating detections and controls loses long-term value.

Use a service runbook

Document contacts, permissions, action boundaries, escalation and evidence requirements.

Use regular reviews

Review service findings, hunting reports, access, coverage and operational issues.

Train internal analysts

The SOC should understand the service, recommendations and escalation process.

Preserve auditability

Record Microsoft actions, customer approvals, evidence and final decisions.

Protect sensitive information

Expert collaboration can involve personal, confidential or regulated investigation data.

Retain customer accountability

The customer remains responsible for organisational governance and business decisions.

Use another pair of eyes

Expert review is most valuable when the incident is complex, high impact or incomplete.

Final analyst judgement

Microsoft experts and Security Copilot strengthen the investigation, but the authorised customer team approves the final outcome.

Example collaborative investigation prompt

Prepare incident 4821 for review with Microsoft Defender Experts.

Include:
1. Correct incident, alert, user and device identifiers
2. Validated incident summary and current status
3. Complete timeline with source evidence
4. Identity, endpoint, email and cloud findings
5. KQL queries and representative raw rows
6. Enriched indicators and threat-intelligence context
7. Containment actions already completed
8. Missing telemetry and unresolved questions
9. Internal analyst confidence and alternative explanations
10. Specific questions requiring expert review

Do not present unverified Copilot conclusions as confirmed evidence.

Agent Foskett investigation: “A second pair of eyes”

A ransomware investigation had consumed two days

Security Copilot had assembled the timeline

The internal SOC had identified two compromised devices

Containment appeared complete

Agent Foskett requested expert review

Microsoft analysts examined the network and hunting evidence

A second command-and-control IP was identified

The indicator had appeared on another workstation

The third device had no ransomware alert

It contained the same persistence mechanism

The original investigation was not wrong

It was not finished

Containment expanded to the third device

The detection was updated

The incident closed with the complete scope
Expert review did not replace the investigation. It revealed the chapter the first investigation had missed.

Defender Experts collaboration checklist

AreaQuestionValidation action
ServiceIs MDR, Hunting or another service in scope?Confirm licensing and service model.
CoverageAre required products and assets onboarded?Check sensors, connectors and telemetry.
PermissionsWhat may Microsoft experts read or change?Review roles and action boundaries.
ContextHas business criticality and approved activity been supplied?Maintain asset and owner information.
EvidenceDo recommendations cite supporting data?Open alerts, queries and entity records.
ConfidenceAre findings confirmed, probable or unresolved?Record confidence and missing evidence.
ActionWho approves and performs remediation?Follow the agreed response model.
AuditAre expert and customer actions recorded?Preserve timestamps, identities and outcomes.
LearningDid the engagement improve detections or controls?Update rules, playbooks and coverage.
OwnershipWho approves final incident closure?Retain customer accountability.

Key takeaways

  • Defender Experts MDR provides managed detection and response in partnership with the customer SOC.
  • Defender Experts Hunting provides proactive hunting across endpoints, Microsoft 365, cloud applications and identity data.
  • Security Copilot provides AI-assisted investigation support rather than replacing Microsoft or customer analysts.
  • Permissions determine whether Microsoft experts provide recommendations or perform agreed remediation actions.
  • Healthy telemetry, asset ownership and business context improve expert effectiveness.
  • Expert recommendations should be validated against original evidence and operational impact.
  • Hunting reports can reveal recurring threats, coverage gaps and detection opportunities.
  • Internal SOC teams retain responsibility for governance, approvals and business-risk decisions.
  • Service value should be measured through validated findings, response outcomes and improved controls.
  • The customer remains accountable for final incident closure and residual risk.

What Agent Foskett shared

  • Incident identifiers
  • Validated timeline
  • Affected devices
  • KQL results
  • Indicators
  • Containment status
  • Missing evidence
  • Open questions
  • Business context
  • Response boundaries

Best practices

  • Define service scope.
  • Use least privilege.
  • Maintain healthy telemetry.
  • Provide business context.
  • Validate recommendations.
  • Document disagreements.
  • Verify actions.
  • Review hunting trends.
  • Improve detections.
  • Retain customer ownership.

Continue Module 4 — Operational Security Copilot

Lesson 33 combines internal analysts, Copilot and Microsoft experts. The next lesson integrates Security Copilot into daily SOC operations.
⬅ Previous lesson
Lesson 32 — Automating Repetitive InvestigationsAccelerate repetitive SOC work while preserving review gates.
🏠 Academy home
Microsoft Security Copilot AcademyReview the complete 40-lesson roadmap.
📚 Module 4
Lesson 34 — Security Copilot in Daily OperationsIntegrate Copilot into handovers, incident review, hunting, reporting, knowledge transfer and analyst development.

What is Microsoft Defender Experts MDR?

Microsoft Defender Experts MDR provides managed incident triage, investigation, response guidance and proactive threat hunting in partnership with a customer security operations team.

What is Microsoft Defender Experts Hunting?

Defender Experts Hunting is a proactive threat-hunting service across supported endpoint, Microsoft 365, cloud-application and identity data.

Security Copilot and Defender Experts

Security Copilot accelerates evidence preparation and analysis, while Microsoft Defender Experts contribute managed human investigation and hunting expertise and the customer retains business ownership.