Managed detection & response

We detect, investigate, and contain. You run the business.

A senior-analyst-led SOC for your Microsoft estate. No agent to install, no platform to migrate to, and no alert dumps: threats are contained for you, at the authority level you set.

15-min analyst reaction on high-severity alerts Runs on the Defender and Sentinel you already own EU operations, data stays in your tenant Senior analyst signs off on every incident
IncidentIR-2026-0418-01
RESOLVED · 09:54
StatusResolved
SeverityHigh
Elapsed13:18
Anomalous sign-in detected
Impossible travel: Stockholm to San Francisco.
Entra IDRuleImpossibleTravel
09:41:02
Token-theft indicator correlated
Refresh-token replay on the same session.
DefenderConfidence92%
09:41:08
User risk elevated to High
Risk policy auto-blocked further sign-ins.
Entra ID ProtectionActionAutomatic
09:41:19
Analyst acknowledged
Runbook TOKEN-THEFT-02 engaged by L.E.
SOC · StockholmRunbookTT-02
09:42:05
Session revoked, device quarantinedContained
Sessions killed; endpoint isolated from network.
Conditional AccessDeviceIsolated
09:44:51
Signed incident report deliveredResolved
Timeline, IOCs & remediation sent to IT lead.
Falconer SOCSLAMet
09:54:20
13minDetect → contain
Incident responseResolved
How it works

From signal to closed incident

The same five steps for every detection. Where they end depends on the authority you give us.

1

Detect

Your Microsoft telemetry stays where it is. Our detection rules run inside your Sentinel workspace and Defender suite, tuned to fire on real attacker behaviour rather than noisy defaults.

2

Engage

An analyst takes ownership of every high-severity alert within 15 minutes. That is our operating number, not a contractual minimum we rarely hit.

3

Investigate

A senior analyst decides true positive or false positive, then establishes scope, timeline, and blast radius across identity, email, endpoint, and cloud. False positives die here, not in your inbox.

4

Contain

Confirmed threats are contained per the authority level you set: we guide your team, act on your approval, or act immediately under a pre-agreed matrix. Never unilaterally outside it.

5

Report

Every incident closes with a plain-language report: what happened, what we did, what to fix. Written by the analyst who worked it, readable by your leadership.

A Falconer analyst on the phone at a desk late at night, working an incident
Response authority

How much do we do for you?

The first question to ask any MDR provider: do you recommend, or do you take action? Here is our answer, in writing.

The five actions we commit to

Session / token revocation (Entra ID) · Device isolation (Defender for Endpoint) · Account disable · Process kill & file quarantine · Conditional Access block (risky sign-ins)

Level 1 · MDR Essential

Notify

We investigate, you contain.

We triage, investigate, and escalate confirmed incidents with step-by-step remediation guidance. Your team executes the five actions; we stay on the line.

What that means
  • Guided containment, your team executes
  • Deep-dive investigation included
  • Monthly detection tuning
CoverageBusiness hours
ChannelEmail and ticket
Level 2 · MDR Professional

Approve

We contain on your go-ahead.

We stage the containment action and execute all five the moment you approve on the dedicated channel. One message, not a project.

What that means
  • All five actions, executed on your approval
  • Weekly proactive threat hunting
  • Response playbooks: isolation, revocation, containment
Coverage15 hours/day
ChannelDedicated Teams or Slack
Level 3 · MDR Elite

Act

We contain immediately.

For high-severity incidents we execute first, under an authority matrix agreed per action type at onboarding, then walk you through what happened.

What that means
  • All five actions, pre-authorised
  • Continuous threat hunting
  • DFIR retainer: 10 hours/month included
Coverage24/7 human response
ChannelNamed analyst, priority escalation
A senior analyst signs off on every incident, at every level. We never act outside the matrix you set.
What you receive

No black box. You see what we see.

We work inside your tenant, so nothing is hidden behind our portal. And every incident closes with a report like this one, redacted from a real engagement.

  • Written by the analyst who worked the incident
  • Plain language for leadership, technical detail for IT
  • The full audit trail stays queryable in your own tenant
A printed Falconer incident report, FS-2483, held at a table with several passages redacted in black marker
Coverage

No agent. No rip-and-replace. Your stack, operated properly.

Agent-based MDR asks you to install their platform next to the licenses you already pay for. We do the opposite: we operate the Microsoft security stack you own, across every surface an attacker would touch.

Deep on Microsoft rather than shallow on everything. That is the trade we made on purpose.

Endpoint
Microsoft Defender for Endpoint
Identity
Microsoft Entra ID
Email & collaboration
Defender for Office 365
Cloud
Azure · Defender for Cloud
SIEM & analytics
Microsoft Sentinel
Tiers

Three tiers, priced without the sales maze

What is listed is what is included. The only metered item is DFIR beyond the Elite retainer, billed by the hour.

Pricing

Sized by user count and tenant complexity. You get an exact quote after the free review, and the price you sign is the price at renewal.

MDR Essential

Automated detection with business-hours analyst support. We triage and investigate; your team executes containment with our guidance.

CoverageBusiness hours
ResponseEscalation + guidance
ChannelEmail & ticket
Technology
  • Endpoint protection. Defender for Endpoint P2 monitoring
  • Email security. Phishing and malware detection
  • Identity protection. Sign-in monitoring with Conditional Access
  • Centralised security hub. All alerts in one platform
What you get
  • Automated threat detection around the clock
  • Business-hours analyst monitoring
  • Alert triage and deep-dive investigation
  • Escalation with remediation guidance
  • Weekly security report
  • Monthly detection tuning
Book assessment
Most popular

MDR Professional

Extended coverage with hands-on containment. We detect, investigate, and contain threats; your team stays focused on business.

Coverage15 hours/day
ResponseActive containment
ChannelDedicated Teams/Slack
Technology
  • Advanced endpoint protection. Defender for Endpoint P2 with active threat response
  • Enhanced email security. Multi-layer phishing protection and attack simulation
  • Risk-based identity protection. Automatic blocking of suspicious logins, leaked-credential detection
  • Intelligent security hub. Threat correlation across all services
What you get
Everything in Essential, plus:
  • Extended human response, 15 hours a day
  • Active containment by our analysts, on your approval
  • Weekly proactive threat hunting
  • Response playbooks: isolation, revocation, containment
  • Monthly security posture review
  • Quarterly tabletop exercise (60-90 min)
Key upgrade: risk-based blocking scores sign-in attempts on 30+ factors (location, device, behaviour, leaked credentials). High-risk logins are blocked instantly, powered by Entra ID P2.
Book assessment
Enterprise-grade

MDR Elite

Full 24/7 human response with a DFIR retainer, named analyst, and network-level protection. Enterprise-grade security operations.

Coverage24/7 human response
ResponseFull containment + DFIR
ChannelNamed analyst + priority escalation
Technology
  • Complete endpoint protection. Defender for Endpoint P2 with continuous threat hunting
  • Email & cloud app security. Extends to SharePoint, Teams, OneDrive
  • Full identity protection. Just-in-time admin access, automated access reviews
  • Network-level security. DNS filtering blocks threats before they load
  • Extended security hub. 12-month log retention for compliance
What you get
Everything in Professional, plus:
  • 24/7 human triage and pre-authorised response
  • DFIR retainer: 10 hours a month included
  • Named security analyst on your account
  • Priority escalation, IR team on call
  • Regulator-ready incident reporting (GDPR, NIS2)
  • Quarterly strategic security review and roadmap
Elite advantage: the DFIR retainer means a major incident starts with responders who already know your environment, not a cold engagement.
Book assessment

No renewal upcharge and no gated hunting. Month to month after a 90-day initial term.

The alternatives

If you have fired an MSSP before, this section is for you

The category earned its reputation. Here is what changes.

Legacy MSSP
Falconer MDR
When something fires
A ticket lands in a queue
A senior analyst engages within 15 minutes
The response
An alert forwarded with a to-do list
Containment executed for you, per your authority level
Who works it
L1 triage and an escalation ladder
A senior analyst, end to end
Visibility
Their portal, their black box
Your tenant, full audit trail
The stack
Their agent installed on your endpoints
The Microsoft tools you already license

And if the plan is to build instead: continuous in-house coverage takes four to six analysts at roughly €90-120k each, 12 to 18 months to stand up. MDR is live in weeks, at a fraction of one hire.

4-6
Analysts to build it
12-18mo
To stand it up
3-4wks
Falconer MDR live
Why us
Nobody on the MDR shortlist can say all of this: EU-based, Microsoft-native, senior analyst on every incident, data in your tenant.

EU / Nordic operations · Your Sentinel workspace · GDPR · NIS2

Logs, alerts, and incident records never leave your Microsoft tenant. We work through scoped, revocable access, and every action we take is logged where you can audit it.

Proof

From the teams we protect

We tried to deploy Microsoft Sentinel ourselves and spent 9 months drowning in alerts and spiralling costs. Falconer optimised our deployment in 3 weeks. Costs down 64%, false positives down 80%, and we caught a PHI access attempt in the first month that our old setup would have missed.

Senior IT Security SpecialistHealthcare provider
Client rating 5.0 on GoodFirms
On the team
OSCP OSWE CISSP

Detections are written against real attacker behaviour across identity, email, endpoint, and cloud, and tuned to your environment during onboarding. Ask us what we cover and where; you will get a straight answer.

Onboarding

Live in weeks, not months

The rules of engagement are agreed before the first alert, so nobody improvises during an incident.

1Week 1

Security consultation

A free 30-minute call about your environment and requirements. We recommend a tier and give you the budgetary picture. No pressure, no obligation.

2Weeks 1-2

Baseline & rules of engagement

Technical review of your Microsoft estate sets the detection baseline. Together we agree the authority matrix, per action type, and the escalation channels.

3Weeks 2-4

Detections live

Monitoring deployed, detection rules tuned to your environment, channels tested with a live drill. A dedicated onboarding contact throughout.

4Ongoing

Continuous improvement

Detections tuned, hunting on cadence per your tier, quarterly reviews. Reaction-time actuals reported every month, not just the good ones.

A printed rules of engagement document showing containment authority, escalation path and out of hours sections, with a pen on the signature line
Signed by both sides

Your named approvers, the authority tier you grant us, and the numbers we call at 03:00, fixed in writing before we go live.

Reviewed at the quarterly service review and again whenever you change tier, so the authority we hold is always the authority you last agreed.

FAQ

The questions buyers actually ask

Do you take action, or just alert us?

We take action, to the level you authorise. Essential customers get investigated incidents with step-by-step guidance. Professional customers get hands-on containment on their approval. Elite customers get pre-authorised response: we contain first and brief you after. We never act outside the authority matrix you set.

What exactly can you contain?

Five actions, in writing: session and token revocation in Entra ID, device isolation via Defender for Endpoint, account disable, process kill and file quarantine, and Conditional Access blocks on risky sign-ins. Anything beyond those is guided remediation with your team.

What is your real response time?

An analyst takes ownership of high-severity alerts within 15 minutes. That is our operating number, and we report the actuals to you monthly. We do not publish a financially-backed SLA we could only honour on paper.

Do we need Sentinel, or can you monitor Defender alone?

Sentinel is our detection platform and we deploy it as part of onboarding; if you already run it, we optimise your existing workspace. Essential engagements lean on your Defender and Entra ID signals with a centralised hub, so you are covered while Sentinel is stood up.

Is threat hunting included, or an add-on?

Included: weekly from Professional, continuous with Elite. Essential includes monthly detection tuning instead. Nothing is free in year one and charged at renewal.

Where is our data processed?

Inside your own Microsoft tenant, in your Sentinel workspace. We operate with scoped, revocable access from the EU, and every action we take is logged where you can query it.

What happens during a major incident? Is DFIR included?

Elite includes a 10-hour-per-month DFIR retainer, so a major incident starts with responders who already know your environment. Beyond the retainer, and for other tiers, DFIR is billed by the hour at a rate agreed up front.

Contact

Tell us what you’re dealing with

A Microsoft security specialist reads every message and replies, usually within one business day. Whether you need monitoring, help with a specific tool, or just have a question, start here.

New to this? Ask about a free Microsoft security review as a starting point.

What we can help with
  • Managed detection and response
  • Microsoft Sentinel engineering
  • Identity and email security
  • A free Microsoft security review
1You send a message
2A specialist replies within a business day
3We set up a call to scope what you need

"*" indicates required fields

This field is for validation purposes and should be left unchanged.