杏吧传媒

Search
searchclose icon

Making the Switch to 杏吧传媒 Managed Microsoft Defender: Partner Perspectives

Glitch effectGlitch effectGlitch effect
Glitch banner

A few months ago, we announced three exciting new features of The 杏吧传媒 Security Platform, including Managed Microsoft Defender, 24/7 Global SOC coverage and Host Isolation! 馃コ

We鈥檙e thankful to have partners like , Manager of Network Services at , and , President of , who are just as eager about our releases as we are.听

In fact, they were so eager to give our Managed Microsoft Defender solution a try鈥攅ven back in its days in beta鈥攖hat they joined us for a webinar to share their experiences. 馃槑

Check out highlights from our conversation below to learn about their respective journeys with 杏吧传媒鈥 Managed Antivirus feature.

The Vetting Process

Can you tell us a bit about the history and evolution of your security stacks? How do you vet the tools in it, and how often do you re-evaluate?

Jeff Harlan from United Systems (Jeff): We plan our base offerings on those core compliance standards that the government sets forth and go from there. We rarely stop there, but those standards give us a good place to start with our stack evaluations.听

Although a lot of folks live on the cloud now, we stress to our clients that we still need to be vigilant with the right tools on our own systems as well. One keylogger on the right computer can give threat actors all the access they need to break into your sensitive cloud data.

Jennifer VanderWier from F1 Solutions (Jennifer): Many of my colleagues hate having to talk about security stacks. There are just so many tools out there and it can be a pain to dive into them and talk about them鈥攂ut it鈥檚 a necessary evil.

We decided to re-evaluate our stack to align to a standard鈥攔egardless of whether that standard was internal to us or an external one in the industry. That alignment helped us choose the tools, processes and procedures to put in place.

Our vetting process doesn鈥檛 stop with our security stacks. We鈥檝e made it a habit to regularly vet our vendors, too. We ask about roadmaps, new features and their compliance standards. As an MSP, you鈥檙e obligated on behalf of your clients to regularly re-vet your vendors to ensure those partnerships still make sense.

Why Microsoft Defender?

Jeff: Microsoft Defender has definitely had its ups and downs, but it鈥檚 a solid solution as it stands now. We realized that Defender began catching the same鈥攊f not more鈥攊ncidents than other AV solutions were catching. Because of that, it gained our full confidence.

From a financial perspective, the move made sense, too. It鈥檚 a solution we鈥檙e already paying for as Microsoft users. By taking advantage of a tool we were already paying for, we were able to help our bottom line without sacrificing the quality of service we provide to our customers.

Jennifer: It was much the same thought process for us. I think, as MSPs, a lot of us get to a point where we ask ourselves, 鈥淥kay, how much of a relationship with Microsoft do we want?鈥 We at F1 Solutions made the decision many years ago to be a Microsoft house. Once we saw the 杏吧传媒 integration come in, it just clicked for us.

Check out to review independent rankings of top AV products for unbiased feedback on Windows Defender.

The Transition

Did your team make an abrupt move to Managed Microsoft Defender, or did you transition over time?

Jeff: We made the switch pretty immediately for all 1,100-1,200 of our endpoints. We鈥檇 done enough reading about 杏吧传媒鈥 Managed Microsoft Defender feature and improvements to Microsoft Defender that we were ready to take the plunge.

Jennifer: We鈥檝e been with a different antivirus solution for many years, and it worked just fine. We never had any issues or episodes while using it. But we wanted to increase our security posture, so we shopped around.

We鈥檇 been seeing some of the publicity and reporting about Windows Defender being a top-notch solution, and when 杏吧传媒 began managing it, that gave us more confidence in using it. The switch wasn鈥檛 something we chose to do lightly. The last time we switched RMM tools, it took us 800 hours to fully transition.听

But we did our research and talked to other companies. At the end of the day, we asked ourselves, who鈥檚 gonna pick up the phone when I call? Who鈥檚 gonna pick up the phone and call me when the worst happens? Who鈥檚 gonna care about my business as much as I care about my business?

That piece was missing with many of the folks at other companies we鈥檇 talked to, and we felt we were getting a good level of protection across the board with 杏吧传媒. Within 10 working days, we had nearly all 5,000 of our endpoints secured with 杏吧传媒鈥 Managed Antivirus.

Communicating with Customers

Did you communicate the changes to your security offerings to your customers? If so, what did that look like?

Jeff: In our contracts with customers, we have a clause that states that we can change products at any time. Our customers usually don鈥檛 even know what we do鈥攐r want to know what we do鈥攁lthough we do explain our operations to them. We鈥檙e an all-in-one solution, which gives us the ability to make changes to stacks without having to do a lot of communicating with customers. It鈥檚 all part of striking that perfect balance between transparency and over-communicating.

Jennifer: We started by holding a three-hour conversation with our stakeholders. We checked with our peers. Our aha moment was the Kaseya supply chain attack that happened over the summer. Luckily, it didn鈥檛 impact us, but it did make us think about what else we could be doing. Are we doing everything possible for the quality of service we鈥檙e trying to deliver to our clients?

At that point, we decided to make Managed Antivirus a standard security offering for all our clients. We were a bit concerned at first about what our customers鈥 reactions would be, but ultimately, we ended up getting one single phone call about it. That customer wanted us to write up a policy statement so they could add it into their written policies鈥攁nd that was for nearly 5,000 endpoints.

Results

And鈥攄rumroll please鈥攈ow鈥檚 it going so far? Any interesting threats showing up? Is there any benefit to Managed Microsoft Defender than, say, the traditional Defender interface?

Spoiler alert: The remediate button is a crowd favorite.

Jeff: Definitely. Any time a threat is caught, it shows up on our 杏吧传媒 dashboard, which is where we鈥檙e doing reviews of incidents anyway. A lot of our monitoring work happens right in that panel. If we ever have questions, we just pick up the phone and call 杏吧传媒 or email them for help.

We鈥檙e avid users of the remediate button within the platform. We push the button, and incidents are automatically remediated. We once got an email about a machine that had a persistent foothold on it, and within a few seconds, our phone rang. 杏吧传媒 was on the other end asking if we needed any help鈥攐n top of sending an email with the steps to remediate it.听

Our antivirus at the time didn鈥檛 catch that threat, and even if it had caught it, there wouldn鈥檛 have been a 鈥渞emediate this for me鈥 button. With 杏吧传媒, we get enough information that helps us deal with events ourselves鈥攅ven if that means hitting the 鈥渞emediate this for me鈥 button.

Jennifer: Absolutely. One incident off the top of my head relates to a client that鈥檚 a government contractor. Managed Microsoft Defender caught two potential landmines that we had no idea were present鈥攁nd due to who the client was, we鈥檇 have had to report this incident to the government had it gone unnoticed. However, we were able to see the threat, immediately remediate it and prove that there was no exfiltration.

We pride ourselves on having incredibly clean systems. The US Missile Defense Agency did our audit two years ago, and clean systems make up a sense of pride that we have. But Managed Microsoft Defender caught things that we鈥檇 have never seen otherwise.

We also love the remediation button. 杏吧传媒 catches things that other tools we have in place have missed. It truly feels like we have a partner in this.

Wrap-up

We鈥檙e grateful to United Systems and F1 Solutions for being early adopters of Managed Microsoft Defender and making this partner panel possible.听

You can watch the full partner panel webinar on-demand to hear more from Jeff and Jennifer regarding their respective journeys with Managed Microsoft Defender.

Categories
Share

Sign Up for 杏吧传媒 Updates

Get insider access to 杏吧传媒 tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy
Oops! Something went wrong while submitting the form.
杏吧传媒 at work