threat_intelligence698 wordsRead on Arc Codex

Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

Security teams are being asked to defend a growing attack surface with fewer people and around the clock, against threat actors who never take a night off. As cyberattackers increasingly use AI to launch and scale campaigns, the volume, speed, and sophistication of threats continue to rise. Closing that gap takes more than tooling. It takes a partner that pairs a leading security platform with scaled intelligence and human experts who can act on your behalf at any hour. That’s exactly what Microsoft Defender Experts MDR is built to do. We are excited to announce that we have been named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise Vendor Assessment (Doc #US54792426, July 2026). Read the excerpt here. Expert-led MDR, built on the Microsoft Defender platform Microsoft Defender Experts MDR is a round-the-clock, expert-led managed detection and response service that helps security teams triage, investigate, and respond to incidents so they can stop cyberattackers in their tracks and prevent future compromise. Rather than bolting a separate stack of tools and connectors onto your environment, the service operates natively on Microsoft Defender, with built-in protection across endpoints, identities, email, cloud apps, cloud workloads, and network security, as well as around-the-clock proactive threat hunting with Microsoft Defender Experts Hunting. Because the service is delivered on the same platform it monitors, detection and intelligence improvements reach customers continuously. The insights our experts generate also strengthen protection across the broader Defender ecosystem, so every customer benefits from what we learn defending the next environment. Threat intelligence at internet scale Great detection starts with great intelligence. Defender Experts MDR draws on Microsoft’s global threat intelligence: more than 10,000 security researchers and 100 trillion signals analyzed every day across billions of users and millions of organizations.1 That breadth lets our analysts recognize subtle patterns early, often before a campaign escalates, and respond with higher-confidence attribution than intelligence sourced from any single customer’s telemetry could provide. AI-accelerated operations, expert-led decisions Defender Experts MDR also combines advanced AI and generative AI with seasoned human experts. AI filters noise, grades and classifies incidents, and accelerates investigation at machine speed and scale, while our analysts own the outcome. According to the IDC MarketScape, “70% AI-assisted workflows are enabled through automated noise filtering, AI-based grading, and agentic operations while maintaining expert decision-making.” Furthermore, “quantified outcomes noted include 97% AI classification accuracy, 77% malware/phishing agent-investigated, 72% faster resolution combining AI and humans, and 45% autonomous investigations.” The impact shows up in the work. Over the past year, Defender Experts mitigated 27,000 high-severity incidents, and the team’s threat research now contributes a meaningful share of all Defender detections, enriching protection for customers well beyond the MDR service itself. Throughout, a dedicated security delivery expert and on-demand access to our experts keep customers informed with proactive check-ins, live dashboards, and clear, actionable reporting. Managed threat hunting, included Many providers treat proactive threat hunting as a premium add-on. Defender Experts MDR includes it as a core part of the service with Defender Experts Hunting, extending your team with Microsoft experts who continuously look for advanced threats across your environment. These hunts are informed by Microsoft Threat Intelligence, Defender telemetry, and human analysis, in order to better identify malicious activity and improve security operations center (SOC) response. When a threat is found, Defender Expert notifications appear as incidents in the Defender portal with technical context, recommended remediation, and, when needed, access to on-demand support for additional guidance. The work also feeds back into hunter-trained AI and reporting, so customers can see what was investigated, how the activity maps to MITRE tactics, and how threats are categorized by behavior, characteristics, and impact. Get started Read the IDC MarketScape: Worldwide MDR/MXDR for the Enterprise 2026 Vendor Assessment excerpt, and visit the Microsoft Defender Experts MDR webpage to see how expert-led, round-the-clock managed detection and response can extend your team, drive SOC efficiency, and help you stay ahead of emerging cyberthreats. To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters, and follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.