
MDR: Who Is Actually Watching Your Alerts at Three in the Morning
TL;DR:
MDR is the people who watch your security alerts overnight so that nobody on your team has to.
Think of it like the difference between an alarm system and a monitored one. The sensors are identical. One of them rings inside an empty building at 2am. The other rings somewhere staffed, where a person looks at the camera and decides whether to call the police or go back to their coffee.
On a good day you never hear from them. On a bad day somebody catches a login from another continent, cuts that laptop off the network before it spreads, and tells you about it on Monday morning as a story instead of a crisis.
Beyond the Basics:
Here's the shift: detection tooling got good enough that the bottleneck stopped being the software and started being whether anyone is awake.
Endpoint tools produce alerts continuously, and most of them are noise. Somebody has to separate the genuine intrusion from the developer running an unusual script, and that somebody has to exist at 3am on a Sunday. Round-the-clock coverage takes roughly five or six trained analysts once you account for shifts, holidays, and turnover. Very few businesses outside the enterprise can justify that payroll, which is the entire reason this service exists.
- Telemetry streams to the provider. Endpoint, identity, and often network and cloud logs feed their platform continuously rather than being pulled after something goes wrong.
- Analysts triage what the tooling raises. Human judgment against the alert plus its context, which is what separates a real detection from the thousand that look similar.
- Confirmed incidents get investigated. Where it started, what it touched, whether credentials moved, what else in the environment shows the same pattern.
- They contain it under authority you granted in advance. Isolate the device, disable the account, kill the process, before a phone call rather than after one.
That fourth step is where contracts differ most, and it is the question to ask first. A provider that only notifies you has handed a 3am problem back to the person who was asleep. Ask what they are permitted to do without waking anyone, and what their committed response time actually is.
In a Microsoft environment this usually sits on Defender for Endpoint and Sentinel, and Microsoft sells its own service on top. Most providers integrate with what you already run rather than replacing it.
Here's the catch: MDR only sees what you feed it and only does what you authorized. Onboard half your estate and the other half is unwatched, whatever the invoice says. Buy notify-only coverage and you have bought a voicemail.