Skip to main content

Guardz MDR Services

What is it all about?

MDR (Managed Detection & Response) is a cybersecurity service that combines advanced technology with human expertise to help organizations:

  1. Continuously detect threats across endpoints and identities.

  2. Investigate and triage alerts to separate real attacks from noise and false positives.

  3. Respond to incidents in real time, containing or remediating them before damage spreads.

  4. Provide 24/7 monitoring, so organizations aren’t left exposed outside of business hours.
    ​

Please note:

  • Guardz operates a follow-the-sun SOC model with analysts distributed across North America, Europe, and Asia-Pacific. This structure ensures 24/7 monitoring with geographically distributed coverage.

  • MDR is only available for customers on the Ultimate & Elite plans.

  • The automated actions and SLAs are tailored to each incident type and analyst assessment (rather than documented in a single uniform list).


MDR service models

Guardz delivers MDR in two models. Both are run by the same dedicated SOC team.

1. MDR as Part of the SentinelOne Managed Package

  • Customers purchase and deploy SentinelOne agents directly through Guardz.

  • Once deployed, the Guardz SOC team provides continuous monitoring of all endpoint activity and security alerts.

  • Any suspicious activity or confirmed incidents are investigated and handled directly by the MDR team as part of the managed service.
    ​

2. MDR on Top of ITDR

  • In this setup, the SOC team monitors incidents detected by Guardz ITDR services

  • The MDR team performs full incident response, investigation, and escalation as needed, ensuring security incidents are actively managed rather than left unattended.
    ​


Activating the Service

​​Customers don’t need to take any special action to enable MDR. As soon as they purchase the Ultimate or Elite plans and have their SentinelOne agents deployed, the service is activated automatically.

The only requirement is to provide basic policy preferences and contact details (your own MSP contact details), which allow the Guardz SOC team to tailor responses and escalation paths to the organization’s needs.


Policies Configuration

Response Preferences

Response Preferences define which containment actions the 24/7 MDR team runs immediately, and which need your sign-off first.

  • Approved: MDR runs the action as soon as a true positive is confirmed, then notifies your Point of Contact.

  • Approval Required: MDR contacts your Point of Contact first and runs the action only after approval.

Action

Runs on

What it does

Guardz recommends

Suspend Account

Entra ID

Disables sign-in for the account

Approval Required

Isolate

SentinelOne

Network-quarantines the endpoint

Approved

Revoke Sessions

Entra ID

Invalidates refresh tokens and sessions, forcing re-authentication

Approved

Reset Password

Entra ID

Sets a new password and forces a change at next sign-in

Approved

Reset MFA

Entra ID

Removes registered authentication methods so the user re-registers

Approved

To configure Response Preferences:

  1. In the Guardz console, open Security Controls.

  2. Find Managed Detection and Response (MDR) and expand it with the chevron on the right.

  3. Scroll to MDR Service Configuration and click the pencil icon.

  4. Set each action to Approved or Approval Required.

  5. Click Save.

  6. Confirm the values under Response Preferences on the MDR card match your choices.

Please note: Isolate here is an action taken by the MDR team after an analyst confirms a threat. It is different from automatic network quarantine set in the SentinelOne policy, which is not recommended (see below).

Point of Contact

The Point of Contact is the person MDR contacts when an action needs approval or an incident needs more information. If any required field is empty, the MDR card shows Missing Details next to the contact name.

Field

Purpose

How to fill it

Full Name

Person authorized to approve actions

Someone who can approve Suspend Account without escalating

Email

Approval requests and incident updates

A monitored mailbox, preferably outside the protected Microsoft 365 tenant

Phone Number (SMS compatible)

Urgent approval requests

International format with country code and no spaces, e.g. +12345678900

To update the Point of Contact:

  1. In MDR Service Configuration, click the pencil icon. The panel opens on the right.

  2. Under Point of Contact Details, expand Point-of-Contact Person (Default).

  3. Confirm Full Name.

  4. Enter or update Email.

  5. Enter Phone Number (SMS Compatible) with the country code and no spaces.

  6. Click Save.

  7. On the MDR card, confirm the Missing Details flag is gone.

Please note: Avoid an onmicrosoft.com address in the tenant MDR protects. If that account is compromised or suspended, it is the first mailbox you lose.


Issue vs. Incident: MDR Involvement

Guardz differentiates between Incidents and Issues based on whether a threat is already mitigated or still requires action.

Issue (No Incident Created)

  • Created when a threat is automatically mitigated by the endpoint protection (e.g., SentinelOne).

  • Includes cases where actions like network isolation are triggered automatically by policy.

  • MDR reviews and may close the issue without escalation.

  • These events do not generate an Incident to avoid alert fatigue.

Incident (MDR Engagement)

  • Created when a threat is malicious and not fully mitigated.

  • Requires MDR investigation and response, such as manual containment or isolation.

Please note:

  • With regards to SentinelOne detections, only malicious detections are sent to the MDR queue. Agent health events (e.g., offline, crashes, anti-tamper) are not sent to MDR and must be monitored directly in the SentinelOne console.

  • Automatic isolation policies are not recommended, as they may not always trigger clear visibility or alerts within Guardz.

  • If isolation is triggered automatically by policy, Guardz may only generate an Issue, not an Incident.

  • There is currently no dedicated notification from Guardz specifically for device isolation in this scenario.

  • Customers should:

    • Review Issues (or sync them to PSA), and/or

    • Configure notifications directly in SentinelOne


MDR Workflow Overview (High-Level)

Below is the standard flow Guardz MDR follows from detection to closure:

1) Validation & Triage

The MDR team validates the alert to confirm whether it is:

  • No-impact

  • Or suspicious and requires action

At this stage, we determine: urgency, impacted user/device and initial scope and confidence.

2) Classification & Context Gathering

If action is needed, the MDR examines the broader context such as:

  • Incident type and classification

  • Related detections and indicators

  • Relevant user/device/account information

  • Whether it is a broader campaign (example: phishing campaign behavior)

3) Customer Contact Decision (when required)

Not every incident requires customer involvement.

The MDR team will take an action if permitted to, according to the customer defined policies. When the MDR team needs to reach you, the channel depends on the action:

  • We notify you via Intercom for response actions taken under your configured policy — including when a user is suspended. We do not place a phone call for suspensions.

  • A phone call to your emergency contact is reserved for cases where we need to confirm activity or get your decision before proceeding.

4) Response Actions

As detailed above, when a response is required, Guardz MDR takes action based on configured permissions. Typical actions may include:

  • Quarantining a file

  • Isolating a device (endpoint containment)

  • Suspending a user

  • Providing further remediation guidance to the admins

5) Resolution & Closure

MDR verifies:

  • The threat was contained

  • Risk is no longer present

Incidents are then may be formally closed.


Please refer to this article to learn more about SLAs.

Did this answer your question?