What is it all about?
MDR (Managed Detection & Response) is a cybersecurity service that combines advanced technology with human expertise to help organizations:
Continuously detect threats across endpoints and identities.
Investigate and triage alerts to separate real attacks from noise and false positives.
Respond to incidents in real time, containing or remediating them before damage spreads.
Provide 24/7 monitoring, so organizations aren’t left exposed outside of business hours.
Please note:
Guardz operates a follow-the-sun SOC model with analysts distributed across North America, Europe, and Asia-Pacific. This structure ensures 24/7 monitoring with geographically distributed coverage.
MDR is only available for customers on the Ultimate & Elite plans.
The automated actions and SLAs are tailored to each incident type and analyst assessment (rather than documented in a single uniform list).
MDR service models
Guardz delivers MDR in two models. Both are run by the same dedicated SOC team.
1. MDR as Part of the SentinelOne Managed Package
Customers purchase and deploy SentinelOne agents directly through Guardz.
Once deployed, the Guardz SOC team provides continuous monitoring of all endpoint activity and security alerts.
Any suspicious activity or confirmed incidents are investigated and handled directly by the MDR team as part of the managed service.
2. MDR on Top of ITDR
In this setup, the SOC team monitors incidents detected by Guardz ITDR services
The MDR team performs full incident response, investigation, and escalation as needed, ensuring security incidents are actively managed rather than left unattended.
Activating the Service
Customers don’t need to take any special action to enable MDR. As soon as they purchase the Ultimate or Elite plans and have their SentinelOne agents deployed, the service is activated automatically.
The only requirement is to provide basic policy preferences and contact details (your own MSP contact details), which allow the Guardz SOC team to tailor responses and escalation paths to the organization’s needs.
Policies Configuration
Response Preferences
Response Preferences define which containment actions the 24/7 MDR team runs immediately, and which need your sign-off first.
Approved: MDR runs the action as soon as a true positive is confirmed, then notifies your Point of Contact.
Approval Required: MDR contacts your Point of Contact first and runs the action only after approval.
Action | Runs on | What it does | Guardz recommends |
Suspend Account | Entra ID | Disables sign-in for the account | Approval Required |
Isolate | SentinelOne | Network-quarantines the endpoint | Approved |
Revoke Sessions | Entra ID | Invalidates refresh tokens and sessions, forcing re-authentication | Approved |
Reset Password | Entra ID | Sets a new password and forces a change at next sign-in | Approved |
Reset MFA | Entra ID | Removes registered authentication methods so the user re-registers | Approved |
To configure Response Preferences:
In the Guardz console, open Security Controls.
Find Managed Detection and Response (MDR) and expand it with the chevron on the right.
Scroll to MDR Service Configuration and click the pencil icon.
Set each action to Approved or Approval Required.
Click Save.
Confirm the values under Response Preferences on the MDR card match your choices.
Please note: Isolate here is an action taken by the MDR team after an analyst confirms a threat. It is different from automatic network quarantine set in the SentinelOne policy, which is not recommended (see below).
Point of Contact
The Point of Contact is the person MDR contacts when an action needs approval or an incident needs more information. If any required field is empty, the MDR card shows Missing Details next to the contact name.
Field | Purpose | How to fill it |
Full Name | Person authorized to approve actions | Someone who can approve Suspend Account without escalating |
Approval requests and incident updates | A monitored mailbox, preferably outside the protected Microsoft 365 tenant | |
Phone Number (SMS compatible) | Urgent approval requests | International format with country code and no spaces, e.g. +12345678900 |
To update the Point of Contact:
In MDR Service Configuration, click the pencil icon. The panel opens on the right.
Under Point of Contact Details, expand Point-of-Contact Person (Default).
Confirm Full Name.
Enter or update Email.
Enter Phone Number (SMS Compatible) with the country code and no spaces.
Click Save.
On the MDR card, confirm the Missing Details flag is gone.
Please note: Avoid an onmicrosoft.com address in the tenant MDR protects. If that account is compromised or suspended, it is the first mailbox you lose.
Issue vs. Incident: MDR Involvement
Guardz differentiates between Incidents and Issues based on whether a threat is already mitigated or still requires action.
Issue (No Incident Created)
Created when a threat is automatically mitigated by the endpoint protection (e.g., SentinelOne).
Includes cases where actions like network isolation are triggered automatically by policy.
MDR reviews and may close the issue without escalation.
These events do not generate an Incident to avoid alert fatigue.
Incident (MDR Engagement)
Created when a threat is malicious and not fully mitigated.
Requires MDR investigation and response, such as manual containment or isolation.
Please note:
With regards to SentinelOne detections, only malicious detections are sent to the MDR queue. Agent health events (e.g., offline, crashes, anti-tamper) are not sent to MDR and must be monitored directly in the SentinelOne console.
Automatic isolation policies are not recommended, as they may not always trigger clear visibility or alerts within Guardz.
If isolation is triggered automatically by policy, Guardz may only generate an Issue, not an Incident.
There is currently no dedicated notification from Guardz specifically for device isolation in this scenario.
Customers should:
Review Issues (or sync them to PSA), and/or
Configure notifications directly in SentinelOne
MDR Workflow Overview (High-Level)
Below is the standard flow Guardz MDR follows from detection to closure:
1) Validation & Triage
The MDR team validates the alert to confirm whether it is:
No-impact
Or suspicious and requires action
At this stage, we determine: urgency, impacted user/device and initial scope and confidence.
2) Classification & Context Gathering
If action is needed, the MDR examines the broader context such as:
Incident type and classification
Related detections and indicators
Relevant user/device/account information
Whether it is a broader campaign (example: phishing campaign behavior)
3) Customer Contact Decision (when required)
Not every incident requires customer involvement.
The MDR team will take an action if permitted to, according to the customer defined policies. When the MDR team needs to reach you, the channel depends on the action:
We notify you via Intercom for response actions taken under your configured policy — including when a user is suspended. We do not place a phone call for suspensions.
A phone call to your emergency contact is reserved for cases where we need to confirm activity or get your decision before proceeding.
4) Response Actions
As detailed above, when a response is required, Guardz MDR takes action based on configured permissions. Typical actions may include:
Quarantining a file
Isolating a device (endpoint containment)
Suspending a user
Providing further remediation guidance to the admins
5) Resolution & Closure
MDR verifies:
The threat was contained
Risk is no longer present
Incidents are then may be formally closed.
Please refer to this article to learn more about SLAs.


