What We Do
How We Do
Get Started
Case study

Reducing Costs, Simplifying Operations and Increasing Security-eSentire Embraces Microsoft 365 Defender


5 minutes read


eSentire delivers MDR to organizations around the world, via a team that is itself distributed (and that became even more distributed by the COVID-19 pandemic). Safeguarding customers is the company’s number one objective and is dependent upon eSentire’s ability to secure itself and maintain 24/7 operations. To that end, eSentire’s takes serious measures to secure the company against cyber threats and has invested heavily in commercial solutions and proprietary technologies that meet the operational needs of the business as efficiently as possible without sacrificing enterprise security. In 2019, eSentire selected Microsoft’s Defender suite of enterprise security tools to accomplish this objective. The following is a summary of the process that lead to this decision.

Business and Security Outcomes

  • The team estimates they will realize 50% cost savings in security spend
  • Security operations were simplified and eliminated the need for 10 third-party security tools
  • Increased MITRE ATT&CK coverage with integrations eSentire has built for Microsoft 365 Defender
  • eSentire was able to successfully integrate with eSentire’s MDR platform, increasing detection and response capabilities

Company Snapshot:

eSentire is the Authority in Managed Detection and Response, protecting the critical data and applications of 2000+ organizations in 80+ countries from known and unknown cyber threats. Team eSentire’s mission is to hunt, investigate and stop cyber threats before they become business disrupting events. eSentire offers 24/7 Threat Hunting, SOC Cyber Analyst support and complete response with Managed Risk, Managed Detection and Response and Incident Response services.

The Challenge

Security Leadership Security Practitioner
  • Ensuring selection of security partners align with overall IT strategy, business objectives and eSentire’s brand
  • Ensuring that the security partner effectively integrates with and (ideally) improves day-to-day workflows

To protect the business and its ability to deliver MDR, eSentire’s Enterprise Security Team is responsible for ensuring the company’s defenses can withstand attacks from even the most determined adversaries. Needless to say, prospective solutions must meet extraordinarily high requirements. Over the years, eSentire’s enterprise security stack has become very deep as the company executed upon a full-spectrum, multi-layer cybersecurity strategy—including an “eSentire runs eSentire” operational paradigm. All evaluated security solutions must demonstrate an ability to work effectively under this operational paradigm.

Selection of Microsoft 365 Defender

Security Leadership Security Practitioner
  • Microsoft 365 Defender is included under Microsoft enterprise licensing which meets multiple business needs in a remote work operating model
  • Out of the box integration across four attack vectors, increasing MITRE ATT&CK coverage

Hardening defenses is an ever-evolving pursuit, and as part of this endeavor the Enterprise Security Team conducted a thorough review of the Microsoft Defender 365 platform. They understood that the range of solutions, their quality and their out-of-the-box integration would contribute to a defensive strategy capable of disrupting threats at every step of the attack chain:

By leveraging the integrations eSentire has built for Microsoft 365 Defender, I’m able to reduce my overhead by offloading investigations to the GSOC, and increase my ability to map breaches to the MITRE ATT&CK framework.

Jason Westhaver
Enterprise Security, Technical Security Lead


Third-party security-related products eliminated under Microsoft consolidation


Cost savings in security spend


Security Leadership Security Practitioner
  • Improved security coverage while reducing overallspend on tools
  • Successful integration with eSentire’s MDR platform, increasing detection and response capabilities

The team also recognized that introducing Microsoft’s solutions would allow them to eliminate 10 existing third-party security products (and the associated vendor relationships), simplifying operational overhead without sacrificing the security posture. In fact, the team concluded that consolidating under Defender 365 would improve upon what was already a world-class position. In commercial terms, it was also a “no brainer”—a cost analysis showed that implementing the full Microsoft 365 defender platform will reduce costs by at least 50%.

Once the decision was made, the Enterprise Security team worked closely with the Product team to integrate Defender’s capabilities into eSentire’s MDR platform, which overcomes the data challenge of modern cybersecurity to enabling rapid, effective response to threats—whether protecting eSentire’s clients or eSentire’s own assets. This internal integration upheld the “eSentire runs eSentire” philosophy and at the same time provides the scaffolding for commercial products that utilize Microsoft Defender.

Ready to Get Started?

We’re here to help! Submit your information and an eSentire representative will be in touch to help you build a more resilient security operation today.