Microsoft Defender Experts for Hunting

XDR

Microsoft Defender Experts for Hunting is a managed threat hunting service for organizations that already use Microsoft Defender XDR and want Microsoft hunters to look for hidden attacks across Defender telemetry. After Microsoft finds suspicious activity, the service investigates, creates Defender Experts Notifications and hands off contextual alert information with remediation instructions, while the buyer still owns SOC response, containment, remediation, recovery and non-Microsoft telemetry.

What they do
Investigate and advise
Works with
Their platform
Built for
Mid-Market / Enterprise
Price
No public standalone price found.
Best for
Microsoft Defender XDR customers with an internal SOC that needs additional threat hunting depth

They cover

  • Endpoints
  • Cloud Workloads
  • Identity & Access
  • Email
  • Network
  • SaaS Applications

Your team still owns

  • Running the SOC workflow after Microsoft sends a notification
  • Licensing and enabling eligible Defender products across the tenant
  • Responding to remediation instructions and approving disruptive actions
  • Covering detections from non-Microsoft security vendors and unsupported Microsoft products
  • Recovery, business decisions and broader incident response beyond the hunting service

Pricing

Line Figure
Published price No public standalone price found.
Billing model Custom
Contract Not published
Onboarding Depends on Microsoft commercial approval, tenant readiness, eligible Defender licensing, active Defender deployment, notification contacts and SOC workflow setup.

Tradeoffs

Works well

  • Strong native fit for Microsoft Defender XDR customers that do not want another console
  • Microsoft experts can hunt using Defender advanced hunting data and Microsoft threat intelligence
  • Buyer keeps response control while gaining expert hunting and notification context
  • Official documentation is unusually clear about prerequisites, data access and scope exclusions
  • HIPAA BAA support and ISO certification signals can help regulated buyers assess the service

Watch out for

  • Not a full SOC replacement or vendor-neutral MDR service
  • No public standalone list price was found
  • Coverage depends on eligible Microsoft Defender licensing and active deployment quality
  • Detections from other vendors, Microsoft Purview and Defender for IoT are outside scope
  • Government and sovereign cloud customers are not covered by the commercial service availability statement

What buyers say

Alert noise

Not assessed

Transparency

Not assessed

Customers like

  • Native fit for organizations already standardized on Microsoft Defender XDR
  • Proactive human hunting adds a second set of eyes for emerging threats
  • Ask Defender Experts can help internal analysts interpret threats and notifications
  • Notifications appear inside Microsoft Defender incident and alert workflows

Watch out for

  • Review volume is small compared with broader Defender XDR product reviews
  • Community discussion warns not to treat Hunting alone as full MDR
  • Value depends on Defender deployment quality, licensing and tenant readiness
  • Non-Microsoft telemetry and unsupported Microsoft products remain outside scope

Reputation reads from public reviews, not vendor-published numbers.

Ask before buying

  1. Which Defender workloads, identities, devices and server assets are eligible in our tenant?
  2. How do Defender Experts Notifications flow into our SIEM, ticketing and on-call process?
  3. Are we buying standalone Hunting, Hunting with Servers, Defender Experts for XDR or Defender Experts Suite?

Integrations

Microsoft Defender XDRMicrosoft SentinelMicrosoft Defender for Endpoint P2AzureAWSGCPMicrosoft 365Microsoft Defender for Office 365 P2Microsoft Defender for IdentityMicrosoft Defender for Cloud AppsMicrosoft Entra ID P2Microsoft Defender for Cloud

Editorial notes

Why investigate and advise

Microsoft says Hunting was created for customers with a mature SOC and that its experts investigate findings, then hand off contextual alert information and remediation instructions. That supports guided response, not provider-owned containment.

Tenant-level scope

Microsoft says customers cannot buy partial coverage for Defender Experts for Hunting; it applies at the tenant level and automatically includes identities and devices. Buyers should model licensing and privacy implications before enrollment.

Microsoft-only boundary

Official prerequisites exclude detections from other security vendors, and the service description excludes Microsoft Purview and Defender for IoT. Treat this as Microsoft Defender telemetry coverage, not vendor-neutral SOC outsourcing.

Adjacent XDR service

Defender Experts for XDR is the stronger managed response offer and includes Hunting. This profile covers standalone Defender Experts for Hunting, so XDR response claims should not be imported unless the buyer contracts for XDR.

Questions

Is Defender Experts for Hunting the same as Defender Experts for XDR?
No. Defender Experts for Hunting is the managed threat hunting service for customers that already run their own SOC. Defender Experts for XDR is the broader managed XDR service, includes Hunting and is the better fit when the buyer wants Microsoft to manage Defender incident triage and response workflows.
Does Microsoft contain threats for you with Hunting?
This profile classifies standalone Hunting as Investigate and advise. Microsoft hunters investigate findings and provide Defender Experts Notifications with context and remediation instructions, but the buyer still owns containment, remediation, recovery and incident command unless a broader service covers those actions.
What licensing is required?
Microsoft lists Defender for Endpoint P2 and active Microsoft Defender Antivirus on onboarded endpoint devices as required. Defender for Office 365 P2, Defender for Identity, Defender for Cloud Apps and Entra ID P2 are eligible for coverage when appropriately licensed, and server coverage requires the Hunting service plus Defender for Servers Plan 1 or Plan 2.
Is pricing public?
No current standalone list price was found. Microsoft says the service is sold separately from Defender XDR products and must be transacted through Microsoft commercial sales, so buyers need a scoped quote.