Security1 distinct publisher2 min readPublished
Microsoft's managed detection service now works third-party telemetry ingested into Sentinel, on the MDR P2 tier and with no published price. Anyone paying a separate provider to read those same tables has a renewal conversation.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Coverage here is keyed to the ingestion path, not to the vendor. If a log source lands in Microsoft Sentinel, Defender Experts analysts can work it [1]. Microsoft names Palo Alto Networks, Amazon Web Services and Okta, then writes "and more" without publishing a list [2]. So the scope of the service becomes a function of the customer's connector inventory rather than of a support matrix, which is the first thing to put to a Microsoft seller: which tables, and does the threat hunting reach third-party data or only the detection [4].
The announcement sits in a monthly roundup dated August 27, 2026, between an Entra tenant governance item and Intune device enrollment [5][8]. Same post: Purview auto-labeling moves from 100,000 to 500,000 SharePoint and OneDrive files per day [6], a fivefold ceiling increase [7]. Also in it, Windows Unattended Support with Remote Sign-In lets IT and support staff sign in to a device remotely without involving the user, with role-based permissions, compliance checks and session auditing built in [10] - a control set that puts all the weight on who holds the role and on whether anyone reads the session audit afterwards. And new Secure Now guidance tells customers to constrain agent-initiated actions that happen without explicit user approval [9]. A change in what a paid analyst queue watches got release-note treatment alongside all of that.
What the post does not carry is the part procurement needs. There is no price for MDR P2 and no delta against P1 [3]. There is no response commitment specific to third-party sources, and nothing on whether an Okta alert moves through the analyst queue the way a Defender alert does [1][4]. Those absences are where the repricing happens anyway. An operator running Sentinel plus a separate MDR contract has been paying two parties to read one set of tables, and one of those parties now sells the coverage as a tier upgrade [1][3]. That is enough to reopen the contract before anyone publishes a number.
Ranked by verification strength, evidence, and original report placement.
Microsoft Defender Experts MDR now covers third-party data sources ingested through Microsoft Sentinel.
Microsoft names the covered third-party sources as including Palo Alto Networks, Amazon Web Services (AWS), Okta, "and more", without publishing a full list.
Microsoft describes the change as extending around-the-clock managed detection and response and threat hunting across both Microsoft native and third-party data sources.
Auto-labeling policies in Microsoft Purview now process up to 500,000 SharePoint and OneDrive files per day, up from 100,000.
The third-party coverage is available through Microsoft Defender Experts MDR P2; the post states no price for P2 and no price difference against P1.
The MDR change was published in Microsoft's "What's new in Microsoft Security: August 2026" roundup post, dated August 27, 2026.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
Microsoft puts AI agents in Entra, which makes agent sprawl an identity team problem1 distinct publisher
security
More than 100 companies sign a letter dating the defenders' window at two to three years1 distinct publisher
product
Cisco and Nvidia go looking for the other third of AI spending1 distinct publisher
product
CrowdStrike cleared its own ARR guide by 17% while revenue beat by 2%1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary vendor document, no corroboration
Every claim traces to one first-party Microsoft blog post, which is authoritative for what Microsoft has announced but supplies no independent verification, no complete connector list, no availability stage, and no measured performance or detection efficacy. The facts about the announcement itself are solid; the operational facts behind them are asserted only.
Availability announced, zero usage evidence
The cluster documents shipped or announced availability of several capabilities on a dated vendor post, which is real product movement, but contains no deployments, customer counts, attach rates, tenant disclosures or third-party confirmations. Availability stage (preview versus GA) and region are not stated, so even the availability signal is partial.
Mildly overstated by omission
The post's individual statements are concrete and restrained rather than inflated, but the framing outruns the disclosure: 'around-the-clock' coverage 'across both Microsoft native and third-party data sources' is asserted with an open-ended connector list, no availability stage, no SLA or efficacy evidence, and no price for the tier that gates it. The AI-era framing around Purview and agentic containment likewise carries more promise than the supplied detail supports.
First-party announcement with direct upsell and displacement interest
The single source is the vendor's own marketing blog. Microsoft benefits directly in two ways: the new coverage is scoped to the paid Defender Experts MDR P2 tier, and extending analyst coverage to Palo Alto, AWS and Okta telemetry displaces standalone MDR providers whose selling point is multi-vendor coverage. The Purview throughput increase is explicitly framed as Microsoft 365 Copilot readiness. No countervailing or independent voice appears in the cluster.
High on what was said, low on what it means
Confidence is high that Microsoft made these statements on 2026-08-27, because the cluster contains the primary document verbatim. Confidence is low on scope, timing, cost and effectiveness, because there is one publisher, that publisher is the vendor, and the material omits price, connector enumeration, availability stage and any performance or adoption measurement.