MDR partner · Microsoft Defender XDR

MDR for Microsoft Defender XDR: the incident queue, handled 24·7.

For teams that already own Defender and Sentinel but have an incident queue nobody closes at night, or an MSSP that forwards alerts instead of revoking sessions. The Fortgale MDR service works in your Defender portal with analysts who have the mandate to contain, at a median TTC of <30 minutes.

<15 minMedian TTD
<30 minMedian TTC
24·7·365SOC in Milan since 2017
Fortgale × Defender
MDR · live
Defender sensor activeEndpoint · cloud · identity telemetry
Defender
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced >90% by day 30
Fortgale
Native Defender responseHost isolation in seconds
Live
Proprietary intelligence287 tracked adversary groups and attack tools
Fortgale
MDR live, Defender + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
Microsoft Defender XDR
MITRE ATT&CK aligned
OpenCTI
Coverage

What we cover on Defender.

The Defender workloads and Sentinel sources the SOC operates in the Defender portal. If your Microsoft agreement does not cover what is needed yet, licensing is part of the service.

01

Defender for Endpoint

Windows, macOS and Linux endpoints and servers, with KQL custom detection rules and Fortgale indicators loaded as custom indicators.

02

Defender for Identity

Active Directory and Entra ID: lateral movement, Kerberos abuse and LDAP reconnaissance in the same incident as the endpoint.

03

Defender for Office 365

Phishing, malicious attachments and links on Exchange Online, with remediation of messages already delivered across every affected mailbox.

04

Defender for Cloud Apps

Anomalous activity in SaaS applications and suspicious OAuth apps, with governance actions on the accounts.

05

Defender for Cloud

Azure, AWS and GCP workload alerts correlated in Defender XDR with endpoint and identity activity.

06

Microsoft Sentinel in the Defender portal

Firewalls, VPNs and on-prem sources in Sentinel, operated in the Defender portal, where Microsoft is moving it for good: management from the Azure portal ends on 31 March 2027.

07

Threat hunting in KQL

Advanced hunting sessions led by Fortgale analysts on persistence, silent lateral movement and token abuse that automatic detections miss.

What we add

What Fortgale adds on top of Defender.

What no vendor supplies is the part that turns a platform into a defence. Fortgale detection engineering is built on 287 tracked adversary groups and attack tools: every custom rule is mapped to MITRE ATT&CK and every alert reaches the analyst already enriched with proprietary CTI. Noise drops by more than 90% by day 30, and the decision stays with an analyst who acts: median TTD <15 minutes, median TTC <30 minutes.

On Defender the analyst acts from the portal with native actions: device isolation and containment, app execution restriction, investigation package collection and a Live Response session for artefacts and remediation. Containment, restriction and Live Response require Defender for Endpoint Plan 2.

On identity, response goes through Defender for Identity and Entra ID: disabling the user, forcing a password change and revoking sessions. On email, with Defender for Office 365 Plan 2, delivered messages are moved or deleted. Blocking an IP on a third-party firewall is not a Defender action: it runs through a Sentinel playbook agreed at onboarding.

Fortgale CTI indicators, 34,000 IOCs a week, enter Defender as custom indicators and Sentinel as threat intelligence: infrastructure already attributed to an actor opens an incident even before its behaviour on the device is complete.

Takeover

How we take over your Defender environment.

Takeover happens on your Microsoft tenant: sensors, policies and workspaces stay where they are, with no migration and no reinstallation.

Monitoring starts as soon as roles and access are live, and technical onboarding closes in one week: Defender XDR permissions, Sentinel workspace, playbooks and response authorisations.

On your side: an administrator to assign the agreed roles to our analysts, the device and user groups where response is pre-authorised, and the escalation list.

From the field

Supercar: phishing that lands in the mailbox, not on the endpoint.

In September 2024 Fortgale documented the Supercar phishing kit, used against employees of several Italian companies: fax or employee benefit themed emails with HTML attachments that carry a fake Microsoft 365 login page, or PDFs with QR codes. Credentials are sent to one of more than 4,000 domains in the infrastructure, active since May 2024 and attributed to the Supercar Nebula group.

The article is not about Defender, but a kit like this crosses exactly the workloads the SOC operates. Defender for Office 365 sees the HTML attachment and lets the message be pulled from every mailbox that received it; if a credential has already been entered, the next sign-in shows up in Entra ID logs and response runs through a forced password change and session revocation.

FAQ

What buyers running Defender actually ask.

Do we need Defender Experts to work with Fortgale?

No. Microsoft Defender Experts MDR, the current name of Defender Experts for XDR, is the managed service of Microsoft; Plan 2, which extends it to third-party data in Sentinel, requires Sentinel and at least 1,500 seats. Fortgale works independently on the Defender tenant you already have, from a SOC in Milan that operates in European time zones.

What happens to our tenant and our access?

The tenant, its policies, the Sentinel workspace and the data remain yours. Our analysts work with the roles agreed at onboarding, and every response action is recorded in the Defender Action center and in audit logs, where your team can review it.

How do we move from another provider without a gap in coverage?

Defender sensors and existing rules stay untouched: only roles and response authorisations change hands. Our monitoring starts as soon as access is live, so the previous contract can end once technical onboarding is complete, after one week.

Do we buy the Microsoft licences, or do you?

Both models work. If Defender and Sentinel are already in your Microsoft agreement, Fortgale operates your tenant; if not, licensing is part of the service. At onboarding we check what your plan enables: without Defender for Endpoint Plan 2, for example, containment and Live Response are not available.

Does the service help with NIS2 obligations?

NIS2 does not mandate an MDR, and the service alone does not make you compliant. It covers capabilities you have to answer for: continuous monitoring, incident handling and, for a significant incident, the technical evidence for the early warning within 24 hours and the notification within 72 hours. On Defender that evidence starts from the incident history in Defender XDR and the logs retained in Sentinel.

See a real runbook

A real runbook on your Defender tenant.

We walk through a Defender XDR incident step by step: the alert correlated across endpoint, identity and email, the analyst's KQL query, the device isolation and the session revocation. Alongside it, the Report on the actors most likely to target your sector.

Response time: < 1 business day.