Automated Incident Response for Microsoft Defender XDR
Reviewed by ContraForce Security Operations Team ยท Updated 2026-08-12
Automated incident response for Microsoft Defender XDR eliminates the manual triage, investigation, and containment steps that consume 80% of SOC analyst time. ContraForce Security Delivery Agents process Defender XDR incidents end-to-end -- from alert correlation to response execution -- achieving a 140-second mean time to response and a roughly 85% ticket reduction compared to manual SOC operations ($15-25 per incident) or traditional SOAR platforms ($5-10).
The Problem with Manual Defender XDR Response
Microsoft Defender XDR generates high-fidelity alerts across endpoints, identities, email, and cloud apps. But without automation, each incident still requires an analyst to:
- Open the incident and read the alert details (2-5 minutes)
- Correlate related alerts across Defender products (5-10 minutes)
- Investigate affected entities -- users, devices, IPs (10-20 minutes)
- Determine response actions (5-10 minutes)
- Execute containment -- isolate device, disable account, block sender (5-15 minutes)
- Document actions and notify the customer (10-20 minutes)
Automation Approaches Compared
| Approach | Triage Speed | Cross-Tenant Support | Adaptability | Cost per Incident | Setup Effort |
|---|---|---|---|---|---|
| Manual SOC | Queue and analyst dependent | Limited (analyst switching) | High (human judgment) | Labor dependent | Procedure and staffing |
| Logic Apps / Power Automate | Workflow dependent | Per-tenant configuration | Deterministic branches | Azure usage dependent | Per-workflow engineering |
| Traditional SOAR | Workflow dependent | Requires tenant connectors and policy | Workflow-based | Contract and engineering dependent | Integration and maintenance |
| ContraForce Security Delivery Agents | 140-second mean response in current eligible telemetry | Native multi-tenant delivery | Agent decisions inside Gamebook controls | Monthly plan plus flat per-incident processing | About 10 minutes to agent readiness after connection |
How ContraForce Automates Defender XDR Response
Step 1: Real-Time Incident Ingestion
ContraForce connects to Defender XDR via Microsoft Graph Security API, ingesting incidents and alerts in real time across all connected tenants. No polling delays, no missed alerts.
Step 2: AI-Powered Alert Correlation
Security Delivery Agents automatically correlate related alerts within each incident and across incidents. A phishing email in Defender for Office 365, a suspicious sign-in in Defender for Identity, and a malware detection in Defender for Endpoint are linked into a single attack narrative -- in seconds, not the 15+ minutes it takes an analyst.
Step 3: Automated Investigation
The agent investigates affected entities: user sign-in history, device risk score, file reputation, IP geolocation, and prior incident history across all tenants. This builds a complete investigation timeline without analyst intervention.
Step 4: Gamebook-Driven Response
Based on the investigation results, the matching Gamebook executes response actions:
- Endpoint compromise: Isolate device via Defender for Endpoint, initiate AV scan, collect investigation package
- Identity compromise: Disable account via Entra ID, revoke sessions, reset MFA
- Phishing: Purge email from all mailboxes, block sender domain, submit to Microsoft for analysis
- Lateral movement: Isolate affected devices, disable compromised accounts, trigger full tenant sweep
Step 5: Documentation and Customer Notification
ContraForce auto-generates an incident report with timeline, affected entities, actions taken, and recommendations. Reports are formatted for customer delivery -- no analyst writing required.
Key Automation Metrics
- measurably faster incident resolution compared to manual SOC operations
- roughly 85% ticket reduction vs. $15-25 manual
- 140-second mean time to response for the current eligible telemetry population; see the measurement methodology
- Policy-controlled resolution for eligible incident types where the customer enables the required action authority
- Full audit trail for every automated action, supporting SOC 2 Type II compliance
What Cannot Be Automated
ContraForce does not attempt to automate everything. The following scenarios always escalate to human analysts:
- Novel attack techniques not matching existing Gamebook patterns
- Incidents involving executive or VIP accounts (configurable)
- Business-context decisions (should we shut down this server during business hours?)
- Customer communication requiring personalized judgment
- Threat hunting based on emerging intelligence
Frequently Asked Questions
Does ContraForce work with Defender XDR standalone, or does it require Sentinel?
ContraForce works with both Defender XDR standalone and Defender XDR integrated with Microsoft Sentinel. For MSSPs managing multi-tenant environments, the Sentinel integration provides additional log sources and custom detection capabilities, but Defender XDR incidents are processed regardless of Sentinel deployment.
How does ContraForce handle false positives from Defender XDR?
Security Delivery Agents learn from analyst feedback on false positives. When an analyst marks an incident as a false positive, the agent records the pattern and applies suppression logic to future matching incidents across all tenants. This continuously reduces false positive volume over time.
Can I customize which response actions are automated?
Yes. Gamebooks are fully configurable. You control which actions execute automatically (e.g., AV scan, email purge) and which require human approval (e.g., device isolation, account disablement). Approval gates can be set per-action, per-severity, or per-customer.
What permissions does ContraForce need in my Defender XDR tenants?
ContraForce requires application permissions for Microsoft Graph Security API (read/write incidents, alerts, and actions) and Defender for Endpoint API (machine isolation, AV scan, investigation package). Permissions are granted via standard Azure AD app registration with admin consent.
How does this compare to Microsoft's built-in automatic attack disruption?
Microsoft's automatic attack disruption in Defender XDR handles a narrow set of high-confidence scenarios (ransomware, BEC, adversary-in-the-middle). ContraForce extends automation to the full spectrum of incident types, adds multi-tenant delivery, enforces MSSP-specific SOPs via Gamebooks, and provides customer-facing reporting -- capabilities Microsoft's native automation does not offer.
What is the deployment process for automating Defender XDR response?
A supported tenant connection can reach agent readiness in about 10 minutes: connect through the approved identity flow, configure Gamebook mappings, set approval gates, and activate. Production approval and customization depend on the provider's procedure. ContraForce provides pre-built Gamebooks for common Defender XDR incident types that can be customized to approved SOPs.
Sources and review method
Product capabilities were reviewed against primary sources on 2026-08-12. ContraForce performance figures are product telemetry, not independent industry benchmarks.
Related resources
- What Are Security Delivery Agents?, The next evolution beyond SOAR. Contextual investigation by AI.
- Gamebooks: Enforce SOPs, Turn standard operating procedures into governed, executable workflows.
- The Platform for the Microsoft Security Stack, Multi-tenant delivery on Defender XDR, with Sentinel where you need it.
- Pricing, Commit plans from $249/mo. Unlimited workspaces, agents, integrations.