Microsoft Threat Experts

Applies to:

Microsoft Threat Experts is a managed detection and response (MDR) service that provides Security Operation Centers (SOCs) with expert level monitoring and analysis to help them ensure that critical threats in their unique environments don’t get missed.

This new capability provides expert-driven insights and data through targeted attack notification and access to experts on demand.


Microsoft Defender ATP customers need to apply for the Microsoft Threat Experts managed threat hunting service to get proactive targeted attack notifications and to collaborate with experts on demand. A Microsoft Threat Experts subscription is a prerequisite for experts on demand collaboration. See Configure Microsoft Threat Experts capabilities for details.

Targeted attack notification

Microsoft Threat Experts provides proactive hunting for the most important threats to your network, including human adversary intrusions, hands-on-keyboard attacks, or advanced attacks like cyberespionage. The managed hunting service includes:

  • Threat monitoring and analysis, reducing dwell time and risk to the business
  • Hunter-trained artificial intelligence to discover and prioritize both known and unknown attacks
  • Identifying the most important risks, helping SOCs maximize time and energy
  • Scope of compromise and as much context as can be quickly delivered to enable fast SOC response.

Collaborate with experts, on demand

Customers can engage our security experts directly from within Microsoft Defender Security Center for timely and accurate response. Experts provide insights needed to better understand the complex threats affecting your organization, from alert inquiries, potentially compromised machines, root cause of a suspicious network connection, to additional threat intelligence regarding ongoing advanced persistent threat campaigns. With this capability, you can:

  • Get additional clarification on alerts including root cause or scope of the incident
  • Gain clarity into suspicious machine behavior and next steps if faced with an advanced attacker
  • Determine risk and protection regarding threat actors, campaigns, or emerging attacker techniques
  • Seamlessly transition to Microsoft Incident Response (IR) or other third-party Incident Response services when necessary

The option to Consult a threat expert is available in several places in the portal so you can engage with experts in the context of your investigation:

  • Help and support menu
    Screenshot of MTE-EOD menu option

  • Machine page actions menu
    Screenshot of MTE-EOD machine page action menu option

  • Alerts page actions menu
    Screenshot of MTE-EOD alert page action menu option

  • File page actions menu
    Screenshot of MTE-EOD file page action menu option