
EDR (endpoint detection and response) is software on each computer and server that records activity, spots attacker behavior and can isolate the machine. XDR (extended detection and response) adds signals from email, identities and cloud apps and groups them into single incidents, so one attack shows up as one story instead of four alerts. MDR (managed detection and response) is a service rather than a product: analysts who watch your EDR or XDR around the clock and act on what they find.
In other words, EDR and XDR are things you license, and MDR is who uses them at 2 a.m. For the layer underneath, antivirus and how it differs from EDR, see our guide to EDR vs antivirus vs MDR. This post covers what XDR adds, how vendors package it, and the staffing and escalation decisions that come with each choice.
What is the difference between EDR, XDR and MDR?
| EDR | XDR | MDR | |
|---|---|---|---|
| What it is | An agent on each endpoint plus a cloud console | A platform that correlates endpoint, email, identity and cloud signals | A service: people, procedures and the authority to act |
| What it covers | Laptops, desktops and servers: processes, files, network connections and sign-ins on each device | The endpoints plus the mailbox, the identity provider and the cloud apps the vendor connects | Whatever tools it is contracted to watch, usually EDR or XDR and sometimes logs |
| Who runs it | Whoever opens the console | The same, with one incident queue instead of several | The provider's analysts, working from your escalation list |
| Who it fits | Every business with computers and servers; cyber insurance applications ask about it | Businesses whose email and identity tools the XDR can read, usually from the same vendor as the EDR | Businesses without a security analyst on every shift |
| Cost drivers | Per device or per user license | Higher tiers or suites that include the email and identity products | License plus analyst labor, per endpoint, per user or quoted |
| Effort for your team | Tuning, triage and every response decision | Less triage per incident, the same need for someone to act | Approving the escalation list and the actions allowed without a call |
What is XDR vs EDR in practice?
Take a common sequence: a phishing email, a stolen password, a sign-in from an unfamiliar location, a new mailbox rule, then a malicious process on a colleague's laptop. EDR sees the last step. XDR can see all five and present them as one incident, with a response for each: isolate the laptop, revoke the user's sessions, remove the email from every inbox.
Microsoft's definition is typical: Microsoft Defender XDR is a unified suite that coordinates detection, prevention, investigation and response across endpoints, identities, email and applications. Two details matter to a buyer. It correlates only the Microsoft security products you have licensed. Business Premium includes access to the Defender XDR portal and EDR through Defender for Business, but Microsoft's email service description lists Defender XDR integration with Defender for Office 365 Plan 2, not Plan 1, and Defender for Identity and Defender for Cloud Apps are not in Business Premium, so the tenant owns EDR without the full cross-product view. And its cross-product hunting covers 30 days of raw data.
How do Microsoft, CrowdStrike and SentinelOne package EDR and XDR?
Vendor names blur the line, so check what each tier includes:
- Microsoft. Defender for Endpoint Plan 2 and Defender for Business are the EDR; Defender for Endpoint Plan 1 is prevention without EDR. Defender XDR joins the endpoint product with Defender for Office 365 Plan 2, Defender for Identity and Defender for Cloud Apps, which come with Microsoft 365 E5 or a Defender Suite rather than with Business Premium.
- CrowdStrike. On its pricing page, endpoint detection and response first appears in Falcon Enterprise, at $184.99 per device per year as of October 2026; Falcon Go and Falcon Pro center on next-generation antivirus without it. CrowdStrike calls its EDR module Falcon Insight XDR and describes it as EDR unified with identity, cloud and mobile telemetry; identity protection and Next-Gen SIEM are separate add-ons.
- SentinelOne. Its package table lists extended detection and response in Singularity Complete, at $179.99 per endpoint per year, and above, with 14 days of data retention; the lower Core and Control packages do not include it. Identity threat detection and 90-day retention start at Singularity Commercial.
Where do antivirus, SIEM and SOAR fit?
Antivirus, or an endpoint protection platform (EPP), is the prevention layer, and the EDR products above include it. A SIEM is a different tool: a log platform that collects records from firewalls, servers, cloud apps and security products, correlates them and keeps them for audits. SOAR runs automated playbooks on alerts. A small business tends to add a SIEM when a regulator or insurer wants centralized logs, and seldom needs a separate SOAR, because XDR products now include automated response, such as Microsoft's automatic attack disruption.
Who handles escalation at 2 a.m.?
This is the decision that separates the three. A week has 168 hours and a full-time employee works about 40 of them, so covering one seat around the clock takes more than four people before anyone takes a vacation. Whoever runs your EDR or XDR, write down:
- Who sees an alert outside business hours, and how fast they are expected to look at it.
- What they may do without calling you: isolate a laptop, disable an account, revoke sessions, block a sender.
- Who they call, and in what order, when a decision needs the business: the owner, the office manager, the outside IT provider.
- Who owns recovery once the threat is contained: rebuilding a device, restoring files, resetting credentials, notifying the insurer.
With EDR or XDR alone, every one of those answers is your own staff. With MDR, the provider takes the first three under rules you approve, and the agreement should say where its job ends and incident response or recovery begins.
Which fits a small team?
Illustrative situations, not client stories:
- Twenty people on Microsoft 365 Business Premium, no IT staff. You already own EDR in Defender for Business. Add MDR so someone acts on the alerts; buying a second platform changes nothing if nobody watches it.
- One in-house IT person who works 9 to 5. Keep the EDR or XDR you have and add MDR for nights, weekends and that person's vacations, with the handoff written down.
- Macs and Linux servers alongside Windows. Check platform coverage first. Huntress and SentinelOne list Windows, macOS and Linux agents, and Defender for Business covers Windows Server and Linux through its servers add-on.
- A security analyst on staff. XDR with hunting and longer history, such as Defender for Endpoint Plan 2 with the rest of the Defender suite, or SentinelOne Commercial, gives that person something to work with; MDR can cover the hours they are off.
- A regulator or insurer asks for log retention. Add a SIEM through a managed SOC; it sits beside EDR and MDR rather than replacing them.
What drives the cost?
EDR is licensed per device or per user. XDR costs more because it rides on higher tiers or suites that include the email and identity products. MDR adds analyst labor, priced per endpoint or per user and often quoted. Published list prices, as of October 2026:
- Microsoft Defender for Business, with EDR: $3.00 per user per month on its own, paid yearly, and included in Microsoft 365 Business Premium.
- CrowdStrike Falcon Enterprise, the first bundle with EDR: $184.99 per device per year. Falcon Complete, CrowdStrike's MDR service, is quote only.
- SentinelOne Singularity Complete, with XDR: $179.99 per endpoint per year, shown for 5 to 100 workstations and sold through partners.
- Huntress Managed EDR, with its 24/7 SOC included: an MSRP of $8.99 per endpoint per month on its pricing page.
Compare totals rather than line items. An EDR license plus a separate MDR service, a managed EDR with the SOC bundled, and a vendor's own MDR on top of its platform can price very differently for the same 30 laptops.
How does NetSys help?
Our managed detection and response service is the people side: EDR deployed to every device and tuned, every alert triaged by a NetSys engineer around the clock, weekends and holidays included, compromised devices isolated, malicious processes stopped, the accounts an incident touched reset with their sessions revoked, and a written root cause. Each client has a documented escalation path: who we call, in what order, and what we may do without waiting. When a compliance framework or insurer asks for centralized logs, our SOC monitoring service scopes the log sources, retention, coverage hours and response authority on top. The MDR agreement runs month to month.
Book a call with a NetSys engineer to map what you already license and who is watching it today.
Frequently asked questions
What is XDR vs EDR?
EDR watches endpoints: it records what happens on each computer and server and lets a responder isolate one. XDR extends detection and response to email, identities and cloud apps and correlates them, so a phishing email, a risky sign-in and an infected laptop appear as one incident. XDR products include EDR as their endpoint component.
Is XDR better than EDR?
It sees more, but only across products you own. Microsoft's XDR correlates only the Defender products you license, and CrowdStrike and SentinelOne sell identity protection and longer retention in higher tiers or add-ons. For a small business the bigger gap is usually not EDR versus XDR but whether anyone watches either one.
Do I need MDR if I have XDR?
You need someone to act on it at any hour. XDR automates some containment, such as Microsoft's automatic attack disruption, but it still raises alerts that need a person's judgment. That person can be on your staff, at the vendor (Microsoft's Defender Experts for XDR, SentinelOne's Wayfinder MDR, CrowdStrike's Falcon Complete) or at an MDR provider.
What does a small business need first?
EDR on every computer and server, then someone watching it. If you are on Microsoft 365 Business Premium, the EDR is already licensed, so the first purchase is usually monitoring, not software.
What affects cost, implementation and support?
Cost depends on device and user counts, the vendor tier that includes EDR or XDR, and whether monitoring is bundled. Implementation means removing the old agent, deploying the new one everywhere and tuning it so routine admin tools stop raising alarms. Support depends on the escalation list and the pre-approved actions you agree with whoever watches the alerts.
Related reading
SecurityXDR vs SIEM for Small Business: Which Do You Need?
Read Article
ComparisonSIEM vs EDR vs MDR: Technology and Service Responsibilities
Read Article
CybersecurityEDR vs. Antivirus vs. MDR: What Small Businesses Need
Read ArticleAlso on this topic: Entra ID vs Active Directory (Azure AD vs AD): What Small Businesses Should Run
Discuss managed detection & response (mdr) for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
