Home/Questions/Endpoint protection and patching/EDR with central monitoring
Endpoint protection and patching

Is endpoint detection & response (EDR) deployed with central monitoring?

Two words in this question do the work: deployed, which means everywhere rather than mostly, and monitored, which means someone reads what it produces.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether endpoints run detection and response tooling that reports to a central console, and whether that console is watched. Endpoint detection and response differs from traditional antivirus in that it records behaviour, allows an analyst to investigate retrospectively, and can isolate a device remotely. Antivirus blocks known bad files. Carriers know the difference and increasingly ask for both by name.

Why it is underwritten

Ransomware deployment is a sequence, not an event: credential theft, lateral movement, defence tampering, staging, then encryption. Endpoint detection and response is the control most likely to interrupt that sequence in the middle, and remote isolation is the control that limits how much of the estate is reached. Carriers that have run the numbers price this heavily, and a growing number treat it as a condition rather than a credit.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Insurance Posture reads the cloud and identity estate rather than an endpoint console, so fleet coverage numbers come from your endpoint tooling. What the tenant can show is whether the Microsoft components are enabled and whether devices are managed at all.

PlatformWhere the setting livesWhat has to be true
AzureDefender for Servers, and Defender for Endpoint integrationEnabled at subscription scope, so server workloads are covered rather than only user endpoints
AzureEndpoint protection extension state on virtual machinesInstalled across the virtual machine estate, including the machines built outside the standard pipeline
Microsoft 365Intune compliance policies and enrolment coverageDevices are enrolled and a compliance policy requires the security agent to be present and healthy
Entra IDConditional Access requiring a compliant deviceNon-compliant devices are actually denied, which is what turns a compliance policy from a report into an enforcement
Endpoint consoleAgent coverage, health, and unmanaged device discoveryA coverage percentage with the denominator explained. Attested, since Insurance Posture does not read the endpoint console
The denominator is the whole argument

Ninety-eight percent coverage means nothing until you know what the total was. Consoles report against devices they know about, which excludes exactly the machines an attacker will find first: the unmanaged laptop, the forgotten server, the acquisition that was never onboarded. Discovery of unmanaged devices is the part of this answer worth checking before you sign.

What a defensible yes requires

  • The tooling records behaviour and supports retrospective investigation and remote isolation, not only signature blocking.
  • Coverage is stated against a discovered denominator rather than against the console inventory alone.
  • Servers are covered as well as user endpoints.
  • Alerts reach a human on a defined schedule, whether internal or through a managed service.
  • Tamper protection is on, so the agent cannot be disabled by the credential that just compromised the device.

How this answer goes wrong

The frequent overstatement is answering yes for a licence that is deployed and unmonitored. Alerts accumulate in a console nobody opens, which is detection without response. The second is server coverage: user endpoints carefully managed while the virtual machine estate runs whatever was in the image. The third is tamper protection left off, which lets an attacker with local administrator quietly stop the agent before doing anything visible.

Frequently asked

Does Microsoft Defender count as EDR?

Defender for Endpoint does, in its plan that includes detection and response. The antivirus component alone does not. Name the specific plan on the application, because the distinction is exactly what the question is probing.

Does a managed detection service satisfy the monitoring half?

Yes, and it is often the strongest answer for organisations without a security operations function. State the provider and the coverage hours.

What coverage percentage do carriers want?

Most look for the high nineties and react more to how the number was produced. A stated ninety-four percent with a plan for the remainder reads better than an unexplained hundred.

What about servers and cloud workloads?

They are in scope and they are where coverage gaps concentrate. Defender for Servers or an equivalent agent on cloud workloads is the part of this answer people forget to describe.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture