Short answer
No. Sophos XDR and MDR can ingest Microsoft Defender telemetry, so you can consolidate it into analyst-led detection and response rather than rip it out.
In detail
How it works:
- Defender telemetry feeds into Sophos XDR, which correlates it with signals from firewalls, identity, cloud and email
- Sophos MDR analysts monitor and hunt across that combined telemetry 24/7
- When Sophos raises an alert, FirstNet's Incident Response team works with you to contain, remediate and recover
- Third-party firewall, EDR and identity sources can also connect through XDR connectors, and Sophos connects to Microsoft 365, Azure, AWS and Google Workspace
This addresses the skills shortages and alert fatigue that in-house teams face, without discarding tools you have already deployed.
Standard MDR onboarding typically takes two to four weeks, covering discovery, a deployment plan, telemetry validation and an agreed incident response runbook. Integrating additional XDR or NG-SIEM data sources usually takes four to eight weeks, depending on how many sources are connected.
A FirstNet specialist can review your current Defender set-up and recommend which telemetry to connect first.
Source: FirstNet Managed Cybersecurity Services service page →
Didn’t answer your question?
