It’s one of the most common questions we get from managing partners and office managers: “We’re already paying for Microsoft Defender through our 365 licenses. Why would we pay for something else?” It’s a fair question, and the honest answer is more useful than a sales pitch.
The short answer
Defender is a good product and you should keep it. But Defender is a tool, and a tool doesn’t watch itself. Managed detection and response (MDR) is the team of people who watch it, plus your email and your Microsoft 365 logins, around the clock, and who act when something happens rather than sending you an alert to read on Monday. If your firm has more than a handful of people, or holds data you’d hate to explain losing, you want both.
What Defender actually does well
Defender for Business, the version bundled into Microsoft 365 Business Premium, is a real endpoint detection and response product. It blocks known malware, flags suspicious behavior on laptops and servers, records what happened so it can be investigated, and can isolate a machine from the network. For the price, it’s excellent. We deploy it on nearly every client device and we’d tell you to keep it even if you never hire us.
Where the gap is
Three places, and none of them are Defender’s fault.
- Nobody is watching. Defender raises alerts. Someone has to read them, decide whether they matter, and act, and attackers know most small businesses look at that console rarely if ever. A ransomware crew typically works nights and weekends for exactly that reason.
- Most attacks don’t start on the endpoint. The typical breach at a small firm today is a stolen password or a phished Microsoft 365 login, followed by a quiet month of reading email and setting up forwarding rules before anyone notices. That happens in the cloud, in your identity layer, not on a laptop where Defender lives.
- Detection isn’t response. Knowing a machine is compromised at 2:14 a.m. helps only if someone isolates it at 2:15. By the time a notification email is read in the morning, the attacker has had six hours.
What MDR adds
MDR is a security operations team, staffed 24/7/365, that plugs into the signals you already have: Defender on your devices, Microsoft 365 sign-in and mailbox activity, and often your firewall and email filter. When something looks wrong, a human investigates within minutes. If it’s real, they contain it, which usually means isolating the device or disabling the compromised account, and then they call your IT provider, who calls you.
The part that matters most for law firms is the identity piece. A good MDR service catches the impossible-travel login, the new mailbox rule that forwards everything to Gmail, the MFA prompt that got approved from a country you’ve never visited. Those are the things that turn into a wire fraud or a data breach notification, and Defender alone doesn’t see them.
How to tell if you need it
You probably do if any of these are true:
- You have more than ten people, or anyone works remotely.
- You hold client data with a duty of confidentiality, or you’ve signed a client’s security requirements.
- Your cyber insurance application asks whether you have 24/7 monitoring or MDR. Increasingly it does, and “no” affects your premium or your coverage.
- Nobody on your team looks at the Defender console at least weekly. Be honest.
You might be fine without it if you’re a two-person office, everyone is in one location, MFA is on everywhere, and someone genuinely reviews alerts. Even then, it’s worth pricing.
What to ask a provider
If you’re evaluating MDR, whether from us or anyone else, ask these and expect specific answers:
- Is it truly 24/7/365, with people, not just automated alerts?
- Does it cover Microsoft 365 identity and email, or only endpoints?
- What do they actually do when they find something? Isolate? Disable the account? Or just notify?
- What’s the response time commitment, in minutes?
- Who calls whom, and when, at 2 a.m.?
Why we wrote this
Raven Managed Services is a managed IT and cybersecurity provider in Marietta, Georgia, working with law firms and growing businesses across metro Atlanta and nationally. Every one of our managed clients runs Defender and MDR together, because we’ve watched what happens when only one of them is in place. If you want a straight answer on where your firm stands, send us a note or grab thirty minutes. We’ll tell you what we’d fix first, whether or not you hire us to do it.
Common questions
Defender for Business is a strong endpoint product, and for a very small office with a low profile it may be adequate on its own. The gap isn't the software. It's that nobody is watching the alerts at 2 a.m. and nobody is looking for the attacker who logged in with a real password. Past ten or so people, or for any firm holding client data it would hate to explain losing, MDR closes that gap.
Antivirus blocks known bad files. EDR (endpoint detection and response) watches behavior on the device and records what happened. MDR (managed detection and response) is EDR plus a team of people who monitor it around the clock, investigate, and act, usually across identity and email as well as endpoints. Defender is EDR. MDR is the humans on top.
No. Most MDR services sit on top of Defender and use its signals. You keep what you already pay for through Microsoft 365 and add the monitoring and response layer. Nothing gets ripped out.
It's priced per user or per device, and for a firm of 25 to 100 people it typically lands well below the cost of a single day of downtime. Ask for the number in writing and ask what response, not just detection, is included.

