Security 101

How Do You Choose an Outsourced SOC for a Microsoft Environment?

An outsourced SOC for a Microsoft environment can mean SOC as a Service or MDR. Here is how the two differ and the questions to ask any provider, including where its team is located.

The best outsourced SOC for a company that runs on Microsoft is one that works inside your Microsoft tools, shows you its work, and matches the kind of help you need. Start by deciding whether you need SOC as a Service or managed detection and response (MDR), because the two cover different jobs.

After that, compare providers on a short set of questions about access, ownership, response and location. The sections below walk through each one.

Start here

  • SOC as a Service keeps operations running. Monitoring, SIEM management, configuration governance and compliance reporting.
  • MDR adds investigation and response. Threat hunting, incident investigation and rapid containment.
  • Where the work happens matters. A provider can work in its own platform or inside your Microsoft tenant.
  • Location is a fair question. Ask where the team works and how its access to your environment is logged.

What is the difference between SOC as a Service and MDR?

Both put an outside team on your security operations. The difference is how far that team goes once it finds something.

QuestionSOC as a ServiceMDR
Main jobOperational coverage for your security toolsFinding, investigating and stopping threats
Typical scopeMonitoring, SIEM management, configuration governance and compliance reportingRound-the-clock monitoring plus proactive threat hunting and incident investigation
When a threat is confirmedDepends on the contract, so confirm who responds and howThe provider acts to contain it, within the response authority you approve
What to askWhich tools they manage and what reporting you receiveHow fast they detect and contain, and what they need from you first
Definitions follow the Accelerynt managed detection and response page, which describes the two as separate services.

For how MDR works alongside a SIEM you already run, read how managed detection and response improves SIEM.

Who are the best outsourced SOC providers for a company that runs on Microsoft?

The strongest fit depends on your environment, so a ranked list is less useful than a consistent set of questions. Put each of these to every provider you talk to.

  • Do you work inside our tenant? Some providers move data into their own platform. Others connect through Azure Lighthouse and work in your Sentinel workspace.
  • Can we see your work? Detection rules, tuning changes and response actions should be visible in your own environment.
  • Who owns what you build? Ask whether detection rules and playbooks stay with you if the contract ends.
  • What happens when you find a threat? Ask which actions they take on their own and what approval they need from you first.
  • What commitments are in writing? Detection and containment times should be published or written into the contract.
  • Where is your team located? Confirm where the people with access to your environment work, and check that against your own requirements.

For a deeper look at the MDR side, including response clocks and co-management, see how to choose an MDR provider for Microsoft Defender and Sentinel. For how co-management works day to day, read how co-managed Microsoft Sentinel works, and for the metrics to ask any provider for, see which SOC metrics show whether risk is going down.

Does it matter where your SOC team is located?

It can. An outsourced SOC team has working access to your security data, so its location belongs in the same review as any other access decision. Two separate questions sit inside it.

  • Where your data lives. When a provider works inside your tenant, your log data stays in your tenant instead of moving to the provider’s platform.
  • Where the people are. The team’s location can matter for customer contracts, regulatory expectations and your own policies on who may access sensitive data.
  • How access is controlled. Azure Lighthouse lets a provider operate in your environment without holding your credentials.
  • How access is recorded. Actions taken through Lighthouse are logged in your tenant’s activity records, which gives you an audit trail of the provider’s work.

Accelerynt’s team is 100% based in the United States. The team connects through Azure Lighthouse, works inside your Sentinel workspace, and every action it takes appears in your tenant’s activity records.

<1%

Accelerynt’s published noise escalation rate for MDR Stage 1, once alert tuning and a shared baseline are in place. See MDR stages for what each stage requires.

SOC as a Service or MDR: which one do you need?

SOC as a Service fits when

You want steady operational coverage for your security tools and SIEM, along with configuration governance and compliance reporting, and your own team leads investigation and response.

MDR fits when

You want an outside team to hunt for threats, investigate alerts and contain confirmed attacks inside your tenant, under response protocols your team approves in advance.

Accelerynt offers the two services separately. Either way, the team works inside the Microsoft tools you already own.

Where to go next

To see how an engagement runs day to day, read how we work together. For what MDR covers and how it is priced, start with Accelerynt managed detection and response. If you are weighing how to judge a SOC provider’s results, Michael Henry’s post on when outsourced SOC activity becomes security theater covers the measures that matter.

For what you should be able to see of a provider’s work, read which MDR providers let you see what their SOC is doing. If an IT provider also holds access to your environment, read how to verify an outsourced IT provider follows your security controls.

Frequently asked questions

Who are the best outsourced SOC providers for a company that runs on Microsoft?

The best fit is a provider that works inside your Microsoft tenant, lets you see its work, leaves the detection rules and playbooks with you, puts response commitments in writing, and meets your requirements for where its team is located. Accelerynt is one example: its team is 100% based in the United States and works inside your Sentinel workspace through Azure Lighthouse.

Is MDR basically an outsourced SOC?

They serve different functions. SOC as a Service provides operational coverage: monitoring, SIEM management, configuration governance and compliance reporting. MDR adds proactive threat hunting, incident investigation and rapid containment.

Does an outsourced SOC need to move our data into its own platform?

No. Some providers work in their own platform, and others work inside yours. With Azure Lighthouse, a provider can operate in your Microsoft environment without holding your credentials, and your log data stays in your tenant.

Is Accelerynt’s SOC team based in the United States?

Yes. Accelerynt’s team is 100% based in the United States. The team works inside your tenant through Azure Lighthouse, and every action it takes is logged in your tenant’s activity records.

Can we see what an outsourced SOC is doing in our environment?

Ask every provider this directly. When the provider works inside your Sentinel workspace, detection rules, tuning changes and response actions are visible in your own tenant.

Talk to a Microsoft security engineer

We work inside your Microsoft environment, with your team, and show you where to focus first.