A suitable managed EDR provider is one that combines complete endpoint coverage, 24/7 human investigation, clearly authorised response actions, transparent evidence and contractual service levels. The provider should be able to contain threats, not simply forward alerts to your IT team.
Last reviewed: ****
If your organisation already owns an EDR platform and has security staff, a co-managed service may be the best fit. If you lack round-the-clock security expertise, choose a provider that supplies the EDR technology, monitoring, investigation and remediation as one service.
Managed EDR Provider Selection at a Glance
| Decision factor | What to choose | Warning sign |
|---|---|---|
| Service model | Managed detection, investigation and response | Alert forwarding marketed as "fully managed" |
| Endpoint coverage | All relevant desktops, laptops, servers, operating systems and remote devices | Coverage limited to Windows workstations |
| Response authority | Written permission to isolate devices, quarantine files and take other agreed actions | Provider needs approval for every urgent action |
| Human expertise | 24/7 analysts, threat hunters and incident responders | "24/7" refers only to automated detection |
| Integrations | EDR, identity, email, cloud, SIEM, ticketing and IT tools | Requires replacing your entire technology stack |
| Transparency | Investigation timelines, evidence, analyst notes and action logs | Black-box verdicts with limited detail |
| Contract | Severity-based response and notification SLAs | Vague promises such as "rapid response" |
| Security of provider access | MFA, least privilege, activity logging and controlled subcontractors | Permanent broad administrator access |
| Commercial model | Clear pricing for endpoints, servers, retention and response | Important features sold as undefined add-ons |
First Decide Whether You Need Managed EDR, MDR or Co-Managed Security
The terms are often used interchangeably, but the operating models differ.
Managed EDR
Managed EDR focuses mainly on telemetry from laptops, desktops and servers. It can suit an organisation whose main security gap is endpoint monitoring, while identity, email, cloud and network security are handled separately.
Managed Detection and Response
MDR usually combines endpoint detection and response with additional telemetry and human-led investigation. Depending on the service, this may include identity, email, cloud workloads, SaaS applications, network data and SIEM logs.
Co-Managed EDR
Co-managed EDR uses your existing EDR platform while an external security operations team investigates alerts, hunts for threats and carries out agreed response actions. This is often practical when you have an internal security team but lack overnight or weekend coverage.
EDR technology provides visibility and response functions, but the provider determines how effectively those functions are operated. Microsoft Defender for Endpoint, for example, supports investigation, device isolation, file quarantine and other response actions. Your organisation still needs to configure automation and permissions correctly.
1. Match the Provider to Your Actual Endpoint Environment
Start with an asset and coverage list before speaking to vendors. Include:
- Windows, macOS and Linux endpoints
- Physical and virtual servers
- Cloud workloads
- Remote and travelling devices
- Virtual desktops
- Privileged administrator workstations
- Contractor and BYOD devices
- Devices in branch offices and subsidiaries
- Internet of Things and operational technology assets, if relevant
Ask each provider to identify exactly which assets are covered, monitored and eligible for response. A general statement that the provider supports your environment is not enough.
Ask:
- Which operating systems and versions are supported?
- Are servers priced separately?
- Are dormant or offline devices counted?
- How does the provider identify missing or unhealthy agents?
- What happens when an endpoint is in passive rather than active protection mode?
- Are devices covered during onboarding?
- What percentage of the environment must have an active agent before the service is considered operational?
Coverage can vary according to how a security product is deployed. Microsoft states that Defender Experts MDR can investigate and respond fully to products deployed in active mode, while passive deployments may receive guidance without direct remediation.
2. Test the Provider's Response Authority
The useful question is not whether a provider can respond to threats. Ask:
What specific actions can your analysts take without waiting for our approval?
Require a written response matrix that separates actions into three categories.
| Response category | Examples |
|---|---|
| Provider can act automatically | Isolate a device, stop a malicious process, quarantine a file |
| Provider acts with approval | Disable a user, revoke sessions, block a business application |
| Customer must act | Rebuild a server, restore from backup, notify regulators or customers |
Potential response actions include:
- Isolating an endpoint from the network
- Terminating malicious processes
- Quarantining files
- Blocking hashes, domains or IP addresses
- Disabling compromised accounts
- Revoking sessions and tokens
- Resetting credentials
- Collecting forensic evidence
- Removing persistence mechanisms
- Restricting application execution
- Coordinating server recovery
A provider that can only create a ticket or send an email is not delivering the same service as a provider with authority to contain an attack.
Microsoft's managed response documentation shows why permissions matter. Its service can investigate incidents and perform actions such as isolating machines, quarantining files and disabling users, but the customer must grant the permissions required for direct response.
3. Verify That "24/7 Monitoring" Includes People
Some providers use automation to detect threats outside business hours but do not provide continuous human investigation. Ask how the service operates at 3 a.m. on a weekend.
Confirm:
- Are analysts actively working every hour of the year?
- Are alerts investigated by employees, contractors or a third party?
- What analyst qualifications are available?
- Is threat hunting included?
- Does the team perform malware analysis and root-cause investigation?
- Is incident response included or sold separately?
- How are incidents escalated when the primary contact does not answer?
- Can you speak directly with the analyst handling the incident?
- Is there a dedicated team or a shared queue?
NIST identifies incident handlers as responsible for verifying incidents, analysing evidence, prioritising response activities and limiting damage. NIST also recognises that these functions may be outsourced to a managed security service provider.
The provider should demonstrate more than alert triage. Ask for an anonymised example that shows:
- The original detection
- The investigation timeline
- Evidence collected
- The scope of affected assets
- Containment actions
- Root cause
- Recovery recommendations
- Detection improvements made afterwards
4. Evaluate Visibility Beyond the Endpoint
A managed EDR provider may detect the initial endpoint event but miss the wider attack if it cannot investigate related identity, email or cloud activity.
Ask whether the provider can correlate endpoint events with:
- Microsoft Entra ID or Active Directory
- Okta or other identity providers
- Microsoft 365 or Google Workspace
- AWS, Microsoft Azure or Google Cloud
- Firewalls and VPNs
- DNS and network security tools
- SIEM platforms
- Vulnerability management systems
- IT service management platforms
- Backup and recovery systems
If the provider only sees endpoints, establish what happens when an incident involves stolen credentials, a malicious mailbox rule or a cloud access token.
A broader MDR service may suit an organisation whose main risk extends beyond malware on a laptop. Managed EDR may cost less when endpoint coverage is the specific gap and other security monitoring is already mature.
5. Demand Investigation Transparency
A managed EDR service should not operate as a black box. Your team should be able to see:
- Alert and incident timestamps
- Affected users and devices
- Process trees
- File and hash information
- Network connections
- Analyst reasoning
- Actions taken by the provider
- Actions awaiting customer approval
- Evidence supporting the final determination
- Audit records of provider access
Ask to see the live portal during a demonstration. Screenshots in a sales presentation are not enough.
The provider should also explain:
- How long it retains endpoint telemetry and investigation records
- Where the data is stored
- How you can export evidence when the contract ends
- Which users can view or change investigation records
- How provider access is recorded
6. Check Integrations Before Agreeing to Replace Tools
A provider should fit your operating environment unless replacing your existing EDR is a deliberate decision.
Ask whether the service supports:
- Your current EDR platform
- Your SIEM
- Your identity provider
- Your email security platform
- Your cloud platforms
- Your ticketing system
- Your remote monitoring and management tools
- Your incident response and communications process
If a provider requires its own EDR, compare the full migration cost with the operational benefit. Replacing an existing platform may be justified if the new service provides better coverage or response. It should not happen simply because the provider lacks integration capability.
7. Scrutinise Onboarding and Coverage Validation
Onboarding is where many managed EDR deployments fail. Require a documented implementation plan covering:
- Asset discovery and endpoint inventory
- Agent deployment
- Policy configuration
- Exclusions and approved applications
- Privileged account setup
- Integration with identity, cloud and ticketing systems
- Test alerts and response exercises
- Coverage reporting
- Incident escalation contacts
- Go-live acceptance criteria
Ask how the provider proves that the agent is installed, healthy and sending useful telemetry. A report showing installed agents is not enough if many devices are offline, misconfigured or excluded from response.
Include a ransomware scenario in the acceptance test. Ask the provider to demonstrate how it would:
- Detect suspicious encryption activity
- Identify other affected devices
- Isolate the endpoint
- Protect or disable compromised accounts
- Contact your team
- Document the investigation
- Recommend recovery actions
The test should also show who receives the escalation, how quickly they are contacted and which actions happen without approval.
8. Put Response and Notification SLAs in the Contract
Avoid vague wording such as "rapid response" or "prompt notification." The contract should define:
- Severity levels
- Initial investigation time
- Customer notification time
- Containment target
- Escalation process
- Communication channels
- Customer and provider responsibilities
- Service availability
- Reporting frequency
- Measurement method
- Remedies if service levels are missed
The National Cyber Security Centre recommends contracts that specify responsibilities, response times, incident notification, regular reviews and access controls.
Clarify whether the provider's incident response team is included in the subscription. Some managed EDR services investigate and contain threats but charge separately for forensic investigation, recovery, legal coordination or on-site response.
9. Assess the Provider's Own Security
A managed EDR provider receives powerful access to your environment. Treat the provider as part of your attack surface.
Require evidence of:
- Multi-factor authentication for provider personnel
- Least-privilege access
- Role-based administration
- Time-limited or just-in-time access where possible
- Logging of provider actions
- Separation between customer environments
- Secure remote access
- Background checks and analyst training
- Subcontractor controls
- Data encryption and retention policies
- Breach notification procedures
- Business continuity and disaster recovery
- Secure account removal when the contract ends
CISA recommends defining provider privileges before contract award, applying least privilege, logging provider activity, controlling subcontractor access and including the provider in incident response planning.
Ask the provider to explain how emergency access works. A process that gives analysts broad permanent administrator rights creates a different risk from one that grants limited access for a defined incident.
10. Compare the Full Cost, Not Just the Price Per Endpoint
Managed EDR pricing may depend on more than the number of laptops. Request a complete commercial breakdown covering:
- Workstations
- Servers
- Cloud workloads
- Users or identities
- Data sources
- Log ingestion
- Data retention
- Onboarding
- Custom detection rules
- Threat hunting
- Incident response
- Forensic investigation
- After-hours response
- Minimum contract quantities
- Overage charges
- Support and account management
- Early termination and data export
A lower per-endpoint price can cost more if isolation, identity response, threat hunting or incident recovery are excluded.
Use This Scorecard to Compare Finalists
Use the same evidence requirements for every provider. A practical weighting is:
| Category | Suggested weighting |
|---|---|
| Response authority and containment | 25% |
| Endpoint and identity coverage | 20% |
| Analyst expertise and 24/7 operations | 15% |
| Investigation transparency | 15% |
| Integrations and onboarding | 10% |
| Provider security controls | 10% |
| Commercial fit | 5% |
This weighting is a decision framework, not an industry standard. Increase the weight for compliance, cloud coverage or incident response if those areas matter more to your organisation.
Score each provider against evidence rather than presentation quality. For example, give more weight to a tested response matrix and sample investigation record than to a claim that the provider has a "next-generation SOC."
Questions to Ask During Vendor Demonstrations
Ask every shortlisted provider:
- What can your analysts do without contacting us?
- What happens when we do not answer an urgent escalation?
- Which endpoints, servers and operating systems are fully covered?
- How do you detect missing or degraded telemetry?
- Which identity, email and cloud signals can you investigate?
- Who investigates alerts overnight?
- Is threat hunting included?
- Is incident response included in the base price?
- Can we see analyst notes, evidence and action history?
- What are the response and notification SLAs by severity?
- How do you secure and audit your administrative access?
- What happens to our data and integrations when we leave?
Final Recommendation
Choose the provider that gives your organisation measurable response capability, not the provider with the longest feature list.
The strongest choice for most organisations is a managed EDR or MDR provider that:
- Covers the entire endpoint estate
- Uses human analysts for 24/7 investigation
- Has pre-agreed authority to contain threats
- Correlates endpoint, identity and cloud activity where needed
- Provides evidence and action logs
- Integrates with your existing tools
- Tests coverage before going live
- Commits to clear response and notification SLAs
- Protects its own privileged access
Run a realistic ransomware or compromised-account exercise before signing. The provider's performance during that exercise will tell you more than a product brochure or a generic "24/7 SOC" claim.