Managed MDR for Microsoft 365

A managed SOC for Microsoft 365. Agents investigate, people approve.

Reddome deploys and tunes Microsoft Sentinel in each customer tenant. AI agents triage and enrich every incident, around the clock. Reddome analysts sit on every approval gate, and nothing changes in a tenant without a human yes.

Sentinel deployed and tuned Agents on every incident, 24/7 Reddome analysts on every approval
  1. IngestSentinel incidents arrive as they fire.
  2. TriageSeverity, ATT&CK mapping, similar incidents.
  3. EnrichIdentity, device and mailbox context plus threat intel.
  4. ProposeThe case, the evidence and the proposed action.
  5. ApproveA person says yes, no, or ask for more.
  6. ExecuteMicrosoft Graph runs it. The audit trail records it.

agentSentinel raises an incident in a customer tenant. SocGenie picks it up the moment it fires.

What is included

Detection, investigation and response, with people on the gates.

Managed MDR is the whole loop run for you: the Sentinel deployment, the agents, the analysts and the audit trail, on every tenant in scope.

Detection and investigation

  • Microsoft Sentinel deployed in each customer tenant, with the SocGenie analytics-rule baseline
  • Microsoft Defender custom detections mapped to MITRE ATT&CK, updated continuously
  • AI agents triage and enrich every incident, 24/7, using Sentinel data and threat intelligence
  • Similar-incident lookup across your fleet, and an attack heatmap by technique
  • Live investigation stream, and replay of any investigation step by step

Response and people

  • Reddome analysts on every approval gate
  • Containment approved in Slack, Microsoft Teams or the portal, and executed through Microsoft Graph
  • PagerDuty escalation for whoever is on call
  • Cross-tenant SOC queue with severity and SLA tracking
  • Full audit trail of every agent action, tool call and decision
  • Dedicated onboarding engineer
Everything in Zerotouch is included. Intune, Conditional Access and Entra RBAC baselines deployed as code, drift detection, the coverage map, Jira tickets from findings, and the free compliance scanner on every tenant.

How an incident flows

From a Sentinel incident to a recorded decision.

An incident fires in Microsoft Sentinel in one of your customer tenants. It might be an unfamiliar sign-in, a new inbox forwarding rule or a risky consent grant. SocGenie ingests it the moment Sentinel raises it, whatever the hour.

An agent starts reading. It pulls the sign-in history, device compliance state, MFA methods and mailbox rules for the accounts involved. It checks every indicator against threat intelligence sources such as VirusTotal, AbuseIPDB, GreyNoise and urlscan, and maps what it sees to MITRE ATT&CK. It looks for similar incidents across your fleet, because the same campaign rarely stops at one tenant.

The agent writes up the case in plain English: what happened, what the evidence shows and what it means. If containment is warranted, it proposes the exact actions, such as revoking sessions, disabling the account or removing the forwarding rule.

Then it stops. The proposal goes to the approval channel in Slack or Microsoft Teams and to the portal, and PagerDuty reaches whoever is on call. A Reddome analyst reviews the case, and your team can weigh in too. Someone approves, rejects or asks for more. Until a person says yes, nothing in the tenant changes.

On approval, the action runs through Microsoft Graph. The incident, every tool call, the proposal, the decision and who made it are written to the audit trail. You can watch it live, replay it later, and the outcome feeds the SOC metrics and the weekly digest.

Who does what

Agents do the reading. Reddome analysts make the calls.

Read-only work is unlimited and automatic. Anything that changes a tenant waits for a person.

AI agents

What the agents do

They work every incident, on every tenant, without a queue and without getting tired. They never change anything on their own.

  • Read every Sentinel incident as it arrives
  • Pull sign-in, device and mailbox context from Sentinel and Microsoft Graph
  • Check indicators against threat intelligence, including VirusTotal, AbuseIPDB, Shodan, GreyNoise, urlscan, ThreatFox, AlienVault OTX and Have I Been Pwned
  • Map activity to MITRE ATT&CK and find similar incidents across the fleet
  • Write the case summary and propose containment
  • Record every step and tool call in the audit trail
Reddome analysts

What the analysts do

They hold the approval gates, tune the detections and keep the service honest. They are the people your customers are paying for.

  • Review the case and the evidence behind every proposed action
  • Approve, reject or ask the agent for more before anything changes
  • Take the PagerDuty escalation when a decision is needed out of hours
  • Deploy and tune the Sentinel analytics-rule baseline for each tenant
  • Run onboarding with a dedicated engineer and agree the SOC scope and SLA with you
  • Review SOC metrics and the weekly digest with you

What you see

Every investigation on screen, live or on replay.

Managed does not mean opaque. You and your customers see what the agents did, what the analysts decided and why.

Live investigation stream

Watch an investigation as it happens: each step, each tool call and each finding, in the order the agent took them.

Replay

Replay any past investigation step by step, for a customer review, a post-incident write-up or an auditor.

Similar incidents

See related incidents across the fleet, so a campaign that hits several customers is understood as one event.

Cross-tenant SOC queue

Every open incident across every tenant in one queue, filtered by severity, SLA and assignee.

SOC and incident metrics

Incident volume, severity mix and SLA performance per tenant, plus an attack heatmap mapped to ATT&CK techniques.

Weekly digest

A weekly email summarising incidents, decisions and fleet health across your tenants, so nothing waits for the monthly review.

How it is priced

Per tenant. Scoped with you on a call.

Onboard first, then we agree the scope.

Managed MDR is priced per tenant, with volume tiers for MSP partners. There is no self-serve checkout. You onboard, we have a short call to agree the tenants in scope, the SOC scope and the SLA, and Reddome activates the tier and issues a payment link.

Your customer relationship and your commercial terms stay yours. Reddome sits behind you on the approval gates, not between you and the customer.

Contact us
Per-tenant pricing, volume tiers for MSPs, custom scope

Questions

Managed MDR questions

Who approves containment, my team or Reddome?
Both can. Reddome analysts sit on every approval gate for Managed MDR customers, and your team can approve, reject or ask for more in the same Slack or Microsoft Teams channel or in the portal. Every decision is written to the audit trail with who made it.
What can the agents change on their own?
Nothing. Agents read Sentinel data, enrich with threat intelligence, write up the case and propose an action. Containment such as revoking sessions or disabling an account runs through Microsoft Graph only after a person approves it.
Do I need Microsoft Sentinel already?
No. Reddome deploys Sentinel and its detection baseline in the customer tenant as part of onboarding. If you already run Sentinel, the baseline and tuning are applied to what you have.
How does escalation work out of hours?
Agents work every incident around the clock. When an incident needs a decision, the approval request goes to Slack, Microsoft Teams or the portal, and PagerDuty escalation reaches whoever is on call. Reddome analysts are on the approval gates for Managed MDR customers.
Can I offer Managed MDR to my own customers?
Yes. Managed MDR is built for MSP partners. Customers connect through GDAP delegated access, every tenant appears in your partner console with the cross-tenant SOC queue, and you keep the customer relationship and the commercial terms.
Where does the data live?
SocGenie runs on Microsoft Azure in the UK. Telemetry stays in the customer's Microsoft tenant and Sentinel instance; SocGenie reads it through delegated, least-privilege consent and never uses it to train models.
See the partner programme Compare with an MSSP Security overview

Managed MDR

Put agents and analysts on every tenant you look after.

Onboard today. We scope the tenants, the SOC coverage and the SLA with you on a short call, then Reddome switches the service on.