Automated Incident Response for Microsoft Defender XDR

Reviewed by ContraForce Security Operations Team ยท Updated 2026-08-12

Automated incident response for Microsoft Defender XDR eliminates the manual triage, investigation, and containment steps that consume 80% of SOC analyst time. ContraForce Security Delivery Agents process Defender XDR incidents end-to-end -- from alert correlation to response execution -- achieving a 140-second mean time to response and a roughly 85% ticket reduction compared to manual SOC operations ($15-25 per incident) or traditional SOAR platforms ($5-10).

The Problem with Manual Defender XDR Response

Microsoft Defender XDR generates high-fidelity alerts across endpoints, identities, email, and cloud apps. But without automation, each incident still requires an analyst to:

A single medium-severity incident consumes 40-80 minutes of analyst time. At 50+ incidents per day across multiple tenants, this workload is unsustainable.

Automation Approaches Compared

ApproachTriage SpeedCross-Tenant SupportAdaptabilityCost per IncidentSetup Effort
Manual SOCQueue and analyst dependentLimited (analyst switching)High (human judgment)Labor dependentProcedure and staffing
Logic Apps / Power AutomateWorkflow dependentPer-tenant configurationDeterministic branchesAzure usage dependentPer-workflow engineering
Traditional SOARWorkflow dependentRequires tenant connectors and policyWorkflow-basedContract and engineering dependentIntegration and maintenance
ContraForce Security Delivery Agents140-second mean response in current eligible telemetryNative multi-tenant deliveryAgent decisions inside Gamebook controlsMonthly plan plus flat per-incident processingAbout 10 minutes to agent readiness after connection

How ContraForce Automates Defender XDR Response

Step 1: Real-Time Incident Ingestion

ContraForce connects to Defender XDR via Microsoft Graph Security API, ingesting incidents and alerts in real time across all connected tenants. No polling delays, no missed alerts.

Step 2: AI-Powered Alert Correlation

Security Delivery Agents automatically correlate related alerts within each incident and across incidents. A phishing email in Defender for Office 365, a suspicious sign-in in Defender for Identity, and a malware detection in Defender for Endpoint are linked into a single attack narrative -- in seconds, not the 15+ minutes it takes an analyst.

Step 3: Automated Investigation

The agent investigates affected entities: user sign-in history, device risk score, file reputation, IP geolocation, and prior incident history across all tenants. This builds a complete investigation timeline without analyst intervention.

Step 4: Gamebook-Driven Response

Based on the investigation results, the matching Gamebook executes response actions:

Step 5: Documentation and Customer Notification

ContraForce auto-generates an incident report with timeline, affected entities, actions taken, and recommendations. Reports are formatted for customer delivery -- no analyst writing required.

Key Automation Metrics

What Cannot Be Automated

ContraForce does not attempt to automate everything. The following scenarios always escalate to human analysts:

This hybrid model ensures AI handles volume while humans handle nuance.

Frequently Asked Questions

Does ContraForce work with Defender XDR standalone, or does it require Sentinel?

ContraForce works with both Defender XDR standalone and Defender XDR integrated with Microsoft Sentinel. For MSSPs managing multi-tenant environments, the Sentinel integration provides additional log sources and custom detection capabilities, but Defender XDR incidents are processed regardless of Sentinel deployment.

How does ContraForce handle false positives from Defender XDR?

Security Delivery Agents learn from analyst feedback on false positives. When an analyst marks an incident as a false positive, the agent records the pattern and applies suppression logic to future matching incidents across all tenants. This continuously reduces false positive volume over time.

Can I customize which response actions are automated?

Yes. Gamebooks are fully configurable. You control which actions execute automatically (e.g., AV scan, email purge) and which require human approval (e.g., device isolation, account disablement). Approval gates can be set per-action, per-severity, or per-customer.

What permissions does ContraForce need in my Defender XDR tenants?

ContraForce requires application permissions for Microsoft Graph Security API (read/write incidents, alerts, and actions) and Defender for Endpoint API (machine isolation, AV scan, investigation package). Permissions are granted via standard Azure AD app registration with admin consent.

How does this compare to Microsoft's built-in automatic attack disruption?

Microsoft's automatic attack disruption in Defender XDR handles a narrow set of high-confidence scenarios (ransomware, BEC, adversary-in-the-middle). ContraForce extends automation to the full spectrum of incident types, adds multi-tenant delivery, enforces MSSP-specific SOPs via Gamebooks, and provides customer-facing reporting -- capabilities Microsoft's native automation does not offer.

What is the deployment process for automating Defender XDR response?

A supported tenant connection can reach agent readiness in about 10 minutes: connect through the approved identity flow, configure Gamebook mappings, set approval gates, and activate. Production approval and customization depend on the provider's procedure. ContraForce provides pre-built Gamebooks for common Defender XDR incident types that can be customized to approved SOPs.

Sources and review method

Product capabilities were reviewed against primary sources on 2026-08-12. ContraForce performance figures are product telemetry, not independent industry benchmarks.

Related resources