Hey everyone. I'm Elle — just joined the community, but I've been lurking for a bit. Recently moved to a new company where we're evaluating our entire security stack from scratch, and Defender for Endpoint is on the table.
I have to get this off my chest: the automated investigation feature feels... oversold? At least from what the sales team promised versus what I'm seeing in our pilot. They painted this picture of a near-autonomous system that would hunt down threats and remediate with minimal human input. In reality, we're still spending a *lot* of time triaging the alerts it *does* generate and then babysitting the "automated" actions.
For example, it'll quarantine a file but then leave a tangled web of related processes and registry entries that you have to manually untangle. Or the investigation will flag something as "suspicious" but stop short, requiring a security analyst to jump in and make the final call anyway. It feels more like a fancy, context-aware alert aggregator than true automation.
I'm coming from a background heavy in marketing automation and CRM workflows, where true "automation" means a defined trigger leading to a complete, hands-off action sequence. Maybe my expectations are skewed? 😅
I'd love to hear from others running MDE in production: What's your actual analyst workload reduction? Are we just misconfigured, or is this the common experience? How much are you still relying on third-party tools or scripts to get to a truly "automated" state?
Your marketing automation comparison is spot on. That's the gap I've seen too. These security tools call a workflow "automated" when it stops at a judgment point, but in true business automation, the system would either complete the loop or escalate within a defined protocol without dropping the ticket.
The real cost isn't just the license fee, it's the hidden labor of the analyst who has to pick up the half-finished investigation. It's like buying a self-driving car that still needs you to steer at every intersection.
Have you looked into what percentage of your "automated" investigations actually resolve without human approval? That metric alone can be a powerful tool for pushing back on vendor claims.
CloudCostHawk
Totally agree on tracking that resolution percentage. We did exactly that for a similar "automated" lead scoring feature. The vendor said 95% automation, but the metric showed 40% of "high-score" leads required manual review to avoid junking up the pipeline.
That hidden labor cost is brutal. It turns a CapEx software buy into a variable OpEx headcount problem. Makes ROI calculations a moving target.
Your self-driving car analogy is perfect. It's not automation if it just hands you the wheel at the hard part.
Attribution is my middle name
The comparison to marketing automation is incredibly apt, because it exposes the core issue: a broken process definition. In marketing automation, a workflow that halts for manual approval at a key branch is considered a design failure for high-volume streams. The system is engineered to handle the exception, not create it.
Applying that "completion percentage" metric is vital, but you need to segment it. A raw 40% resolution rate might obscure that 95% of low-severity items auto-close, while 100% of critical threats stall. That's the real ROI killer: the automation fails precisely when the cognitive load on the analyst is highest and time is most critical. It becomes an expensive alert sorter, not an investigator.
We track something similar for our sales engagement "automated" sequences. If a sequence can't handle a simple "out of office" reply without dumping the lead into a manual review queue, its automation claim is void. The vendor's definition of "automated" is often just "we automated the first, easiest step."
You've hit on the key expectation gap. Sales pitches often frame features by the ideal, fully-tuned end state, not the starting point.
Coming from marketing automation, you're absolutely right to expect a complete trigger-to-resolution loop. In security, the "automated investigation" is often a foundational step that consolidates evidence for you, but the final disposition judgment is frequently left to the analyst. It's meant to reduce mean time to triage, not necessarily to eliminate the analyst.
The registry/process cleanup example you gave is a common pain point. The automation scope is limited to what Microsoft defines as the "primary artifact." Tuning the automation levels in your security settings can help, but it's rarely a set-it-and-forget-it system. What's your experience been with adjusting those thresholds in your pilot?
Keep it constructive.