
Anyone looking into the security of their organisation soon faces a row of abbreviations: EDR, XDR, SIEM, SOC, MDR. Providers use them interchangeably, which makes comparing hard. This article explains what they mean, what Microsoft already does for you and where you need a specialist.
Four terms, one building
Compare digital security with securing your building. Sensors and an alarm report that something is happening. Cameras record what happened. In a control room people judge whether it is real. And a guard takes action.
The sensors and the alarm
Microsoft Defender on every device, mailbox and account spots suspicious behaviour.
Part of your Microsoft licence, complete with the Defender Suite.All camera footage in one place
Collects and links logs from every source, so patterns become visible and you can look back.
Only needed with many sources outside Microsoft.The control room with people
Specialists who assess the alerts: a real incident or a false alarm, and what is the impact?
A function, not a product.The guard who steps in
Not just raising the alarm but acting at once: blocking the account, isolating the laptop, revoking sessions.
Control room and guard in one service.Incident response is the fire brigade and the investigation afterwards, for a major attack.
The key insight: a SOC is a function, not a product. It is people and agreements that assess and follow up alerts. A SIEM is one of the tools such a control room can use, but not the only one. For most organisations running on Microsoft 365, a SIEM is not needed at the start.
Why one attack story says more than four alerts
An attack rarely consists of a single step. A phishing email leads to a stolen password, the attacker signs in with it, and then something happens on a laptop. With separate security products you get four alerts from four systems, and someone has to piece them together. Defender XDR does that automatically.
- Phishing emailDefender for Office 365
- Risky sign-inEntra ID Protection
- Suspicious PowerShellDefender for Endpoint
- Unusual cloud activityDefender for Cloud Apps
A multi-stage attack
Phishing, a stolen sign-in and activity on the laptop, in one timeline.
- User
- Mailbox
- Laptop
- IP addresses
- Files
- Processes
Contained automatically
Within minutes: user contained, device isolated.
The human layer
- Confirm the incident
- Establish the impact
- Inform you
- Verify the containment
- Carry out the fix
Microsoft does the detection, the correlation and the first containment. We provide the analysis, the follow-up and the remediation.
That saves more than time. Because Microsoft sees the whole story, it can also step in itself when it is confident enough: the account is contained and the laptop isolated, within minutes. After that a person is needed to judge how serious it is and what has to be fixed.
What does the technology do, and what do people do?
Good security analysts are scarce and expensive. A traditional control room grows with the number of alerts: more alerts, more people. We turn that around. The technology does the routine work, our specialists do the thinking.
- All signalsMicrosoft
Defender XDR sees and links what happens across accounts, devices, email and cloud apps.
- Handled automaticallyAutomatic
Known attacks are disrupted and investigated automatically, at night too.
- The specialistRemarx
What technology cannot do: judge how serious it is, weigh your situation, fix it and advise.
People remain accountable. In the runbook we agree together what may happen automatically and what gets a human check first.
For you that means three things. Known attacks are contained faster, at night too. You do not pay for analysts clicking away alerts. And our specialist has time for what matters: your situation, the fix and the advice. New Microsoft capabilities, such as AI assistants for security, we build in as soon as they are available for your licence. That is an ambition, not a promise.
How far back can you look?
To intervene now, Defender sees enough. For investigation afterwards something else counts: how long the data is kept.
Retention with Business Premium and the Defender Suite, without a SIEM
Source Microsoft, October 2026. Default retention periods may change per product.
If an incident is only discovered after two months, you will still see the alert, but the details are gone: which processes ran and where the sign-ins came from. That requires extra log retention. It can be targeted, for the most important data only, without a full SIEM.
When do you actually need a SIEM?
Both options below are a full control-room function on the same Microsoft foundation. The SIEM layer with Microsoft Sentinel adds sources outside Microsoft, automated playbooks and a longer history.
| MDR on Defender XDROur advice for most organisations | MDR with a SIEMEverything on the left, plus Microsoft Sentinel | |
|---|---|---|
| Sources | Accounts, devices, email and Teams, cloud apps, on-premises Active Directory | Also firewall, VPN, network, production systems and other SaaS |
| Detection | Microsoft detections, linked into one attack story, plus custom rules | Also correlation with sources outside Microsoft and threat intelligence |
| Intervention | Isolate device, block account, revoke sessions, remove email | Also automated playbooks, including on external systems |
| Looking back | 30 days in detail, 180 days for incidents | 90 days as standard, up to years in a low-cost archive |
| Costs | Defender Suite per user plus the MDR service | Also Sentinel per gigabyte of data and managing the SIEM |
| Suits | An organisation that works almost entirely in Microsoft 365 | Many sources outside Microsoft or strict logging requirements |
What do you need to get started?
The foundation is Microsoft 365 Business Premium with the Defender Suite, an add-on of € 8.70 per user per month (Microsoft list price for an annual subscription, excluding VAT). Business Premium on its own is not enough: protection for identities and cloud apps and the extended detection on devices and email are in the Defender Suite. If you work with Microsoft 365 E5, you already have it.
On top of that you need someone who watches and steps in. That is our Managed Detection & Response: contained automatically day and night, reviewed and fixed on working days by a dedicated specialist, alongside your current IT provider. Curious what that would look like for you? Book twenty minutes with Martijn or Remy.
Your next step.
Managed Detection & Response
Monitoring that actually intervenes. A hijacked account is blocked within seconds, an infected laptop isolated: automatically, at night too.
Read moreSecurity Assessment & pentest
Where does an attacker get in?. A security assessment shows where you are vulnerable: technically and organisationally.
Read moreWhat does it cost?
Configure your environment and see a monthly amount straight away.
Open the calculatorTwenty minutes with Martijn or Remy.
You speak directly with one of the founders. You tell us what's going on; we tell you honestly whether and how we can help. Even if the answer is 'you don't need us'.


Pick a time
On working days, via Teams or phone. Choose a slot in our calendar and get an instant confirmation.
Open the calendar Prefer to call? 085 060 9448 · Or send a message