Run the work. Not just the incidents.
Reviewed by ContraForce Security Operations Team ยท Updated 2026-08-12
Most AI stops at the investigation. ContraForce runs to the report.
MDR outsources the work. AI-SOC tools stop at the investigation verdict. ContraForce Security Delivery Agents run the whole loop and close it, so the ticket is updated, the report is ready, and your analysts review outcomes instead of writing them up.
Autonomy is earned, not assumed.
No team hands an agent the keys on day one, and ContraForce does not ask you to. Start in review mode: Security Delivery Agents investigate and recommend, your analysts approve every action. Watch the agents follow your Gamebooks on your real incidents.
When the verdicts hold up, expand autonomy one Gamebook at a time. Approval gates, guardrails, and a full audit trail stay in place at every level. AI that acts. Humans who decide.
Does ContraForce require Microsoft Sentinel?
ContraForce does not require Microsoft Sentinel. Sentinel not required. ContraForce runs full delivery on Defender XDR alone. Add Sentinel when and where a customer needs it. Security Delivery Agents also work against telemetry from other tools via API.
How does ContraForce relate to Microsoft Security Copilot?
ContraForce works alongside Microsoft Security Copilot. Copilot helps analysts ask better questions of their security data. ContraForce Security Delivery Agents execute the delivery loop itself: triage, investigation, response, tuning, ticket, report. Many partners run both.
The ContraForce platform runs the full delivery loop on the Microsoft Security platform. Security Delivery Agents handle triage, investigation, evidence gathering, response, ticketing, and customer reporting across every tenant. Gamebooks turn your SOPs into governed workflows. Every action is logged, attributed, and auditable.
How does ContraForce fit into an existing SOC workflow?
- Connect a workspace. Validate federated access, least privilege, and the configured workflow without duplicating customer logs into a ContraForce-owned SIEM.
- Agents triage every incident. Security Delivery Agents enrich the alert, run investigation steps, and classify the incident against your Gamebook policy.
- Gamebooks enforce your SOPs. The investigation and response procedure follows your documented standard. Human-in-the-loop gates approve any consequential action.
- Response, ticket, customer report. ContraForce executes approved actions across endpoints, identity, and ticketing systems. The customer-facing summary is generated automatically.
- Audit trail by default. Every decision the agent made, every action it took, and every approval gate is logged with full attribution.
What can the ContraForce platform do?
- Security Delivery Agents for triage, investigation, response, and reporting
- Gamebook Engine and SOP enforcement across every tenant
- EDR integrations: Microsoft Defender XDR, SentinelOne, CrowdStrike
- SIEM integration: Microsoft Sentinel
- Ticketing integrations: Autotask, ServiceNow, Jira
- Multi-tenant control plane with federated access
- Zero data custody, operates inside the customer tenant
- SOC 2 Type II certified, MISA member, Microsoft Security ISV of the Year three-time recognition
Who is ContraForce for?
ContraForce is built for MSSPs, MSPs, and security operations teams running Microsoft Sentinel and Defender XDR. Telecom and large enterprise security teams use the same ContraForce platform to manage thousands of tenants from one control plane.
What integrations does ContraForce support?
ContraForce integrates with Microsoft Defender XDR and Microsoft Sentinel, plus SentinelOne and CrowdStrike for XDR. Ticketing integrations include Autotask, ServiceNow, and Jira from the Growth plan upward. REST and webhook APIs are available on every ContraForce Cloud plan for custom workflows.
What is a Security Delivery Agent?
A ContraForce Security Delivery Agent performs security operations work end to end: it triages an incident, investigates across data sources, gathers and documents evidence, executes response actions, tunes the detection, updates the ticket, and produces the report. It follows your Gamebooks and stops at the approval gates you set.
Does ContraForce require Microsoft Sentinel?
ContraForce does not require Microsoft Sentinel. Sentinel not required. ContraForce runs full delivery on Defender XDR alone. Add Sentinel when and where a customer needs it. Security Delivery Agents also work against telemetry from other tools via API.
Does ContraForce replace my SIEM?
No. ContraForce runs on top of the Microsoft Security platform, with SentinelOne and CrowdStrike also supported. Your SIEM and EDR handle detection. ContraForce handles what happens next: investigation, response, tuning, ticketing, and reporting across every client, without duplicating customer logs into a ContraForce-owned store.
Can I control which actions a ContraForce agent takes?
Yes. In ContraForce you choose whether an agent may act at all: run it as investigation only, or as investigation and response. Response actions run only when "Allow Agent to run gamebooks" is enabled, and high-impact actions such as Isolate Endpoint and Reset User Password sit behind a named approver. Every action is logged.
Is autonomous response safe?
Autonomy is earned, not assumed. ContraForce starts in review mode: Security Delivery Agents investigate and recommend, and your analysts approve every action. When the verdicts hold up, expand autonomy one Gamebook at a time. Approval gates, guardrails, and a full audit trail stay in place at every level.
How does ContraForce relate to Microsoft Security Copilot?
ContraForce works alongside Microsoft Security Copilot. Copilot helps analysts ask better questions of their security data. ContraForce Security Delivery Agents execute the delivery loop itself: triage, investigation, response, tuning, ticket, report. Many partners run both.
How does ContraForce improve service provider margins?
ContraForce Security Delivery Agents run triage, investigation, response, tuning, ticketing, and reporting under your Gamebooks. Incident processing bills at a flat rate per incident, pay as you go, so you can model delivery cost against your own incident mix, analyst cost, and approval policy before quoting a customer.
How do I enforce per-customer rules of engagement in an AI SOC?
ContraForce scopes rules of engagement per workspace, so each customer gets its own. You upload that customer's standard operating procedures to the ContraForce SOP Knowledge Base as Markdown or plain text, tagged as classification or response procedures, and associate them with that workspace's agents. Approvers, run permissions, and notification settings are also per workspace.
Can I stop a ContraForce agent from resetting passwords for VIP users?
Not per user. ContraForce does not offer a VIP list, a protected-user group, or a per-user exclusion for response actions, and the endpoint exclusion list on the ContraForce roadmap does not cover users. Control Reset User Password at the workspace level: leave it out of that workspace's Gamebooks, or keep it behind a named approver.
Can I allow workstation isolation but block server isolation?
Not by device class today. ContraForce treats Isolate Endpoint as one workspace-level capability, so it is not scoped by operating system, device group, or machine tag. Gate isolation behind a named approver, or bind it only to the workspaces where you want it. An endpoint exclusion list is on the ContraForce roadmap and is not yet available.
How do I keep a human in the loop on AI security response?
ContraForce gives you four independent gates. Run an agent as investigation only, so it reports findings and takes no action. Leave "Allow Agent to run gamebooks" disabled. Set the trigger to Manual so the agent runs only when an analyst starts it. And keep high-impact actions behind a named approver, who authorizes each one before it executes.
Can I set different automation levels per tenant?
Yes. ContraForce deploys a separate agent per workspace, so trigger mode, severity scope, confidence threshold, and whether the agent may run Gamebooks are all set per customer. Gamebook approvers, run permissions, and SOPs are per workspace too, so one customer can run supervised while another runs autonomously.
Which incident severities should be automated and which need a human?
ContraForce does not impose a severity mapping, you choose it. By default automatic execution filters on incident status rather than severity, and you enable Advanced mode to scope an agent to specific severities and to switch between on-queue and manual triggering. Most providers start manual on every severity and expand as verdicts hold up.
Does ContraForce close incidents back in Microsoft Sentinel?
Yes, and not only Sentinel. ContraForce writes the closing verdict back to every connected module, translating to the nearest native value. A ContraForce True Positive becomes Sentinel TruePositive and a Benign Positive becomes BenignPositive, so the incident closes in both systems and an analyst does not close it twice.
Does ContraForce write incident verdicts back to Defender XDR, SentinelOne, and CrowdStrike?
Yes. ContraForce records one canonical verdict on every incident, True Positive, False Positive, Benign Positive, or Undetermined, whichever module it came from, and writes it back to Microsoft Sentinel, Microsoft Defender XDR, SentinelOne, and CrowdStrike Falcon. Analysts classify once, in one taxonomy, across a mixed estate rather than reclassifying the same incident in four consoles.
What happens when a vendor cannot store the classification reason I chose?
ContraForce keeps your exact choice. Vendors differ in how much of a reason they can store, so one with no native equivalent degrades to the nearest value that vendor accepts. The reason you selected is preserved in ContraForce, so your reporting stays accurate even where the vendor record cannot hold it.
Can ContraForce create a ticket in my PSA from an incident?
Yes. From a ContraForce incident an analyst can create a new ticket in the connected system, or link an existing one, so the investigation and its evidence stay attached to the ticket. ContraForce links tickets natively in Datto Autotask PSA, ServiceNow, and Jira.
Does ContraForce integrate with ConnectWise PSA, HaloPSA, Kaseya BMS, or Syncro?
Yes, through webhooks and the ContraForce API. ContraForce emits HMAC-signed webhook events when an incident is created, an agent investigation completes, a Gamebook runs, and an incident closes, with automatic retries and delivery logs. Your integration reads them with a service account and creates the ticket in any PSA with an API, ConnectWise PSA included.
How does ContraForce fit into an existing SOC workflow?
ContraForce sits on top of the tools a SOC already runs. Microsoft Sentinel incidents stream into ContraForce in near real time, and analysts work them from one dashboard filtered by workspace, severity, status, module, and assignee. Each incident carries its summary, rule, entities, timeline, logs, comments, and audit trail, and closes with a classification written back to the source system.
How accurate is AI incident triage?
ContraForce does not publish a triage accuracy figure, because the only number that means anything is the one your own alert mix produces. Run Security Delivery Agents in investigation-only mode, compare each agent verdict against your analyst's, and measure it on your incidents before widening autonomy.
How do I measure whether an AI SOC agent is correct?
Score it against your own analysts. ContraForce records one canonical verdict per incident, True Positive, False Positive, Benign Positive, or Undetermined, so an agent run and an analyst review produce directly comparable values. Run investigation-only first, then compare the two across a representative sample of your incidents.
Can I see how the agent reached its verdict?
Yes. The ContraForce Timeline gives a chronological view of every event and action from detection through resolution, Comments carry the agent's own notes and findings alongside your analysts', and Audit records every change with a timestamp and attribution. The raw events behind the verdict stay under Logs.
How verbose is ContraForce investigation output?
Every ContraForce incident carries seven views: Summary, Rule, Entities, Timeline, Logs, Comments, and Audit. Summary is the short read, covering severity, status, and affected assets. Timeline, Entities, and Logs hold the working detail, so an analyst can skim the verdict or read the whole investigation.
What happens when the AI verdict is wrong?
An analyst reclassifies it, and ContraForce keeps that choice as the canonical verdict and writes it back to the source. Autonomy is configurable for exactly this reason: agents can run investigation-only, and confidence thresholds plus Gamebook approval gates decide what an agent may do unattended.
What is the difference between Microsoft Sentinel and Microsoft Defender XDR?
Microsoft Defender XDR correlates first-party Microsoft signal across endpoints, identities, email, and apps into single incidents. Microsoft Sentinel is a cloud-native SIEM that ingests almost anything, including non-Microsoft and on-premises sources, through connectors, CEF, Syslog, or REST. Defender XDR covers the Microsoft estate; Sentinel covers what it does not reach.
Do I need Microsoft Sentinel if I already have Defender XDR?
Only if you need what Defender XDR cannot hold. Microsoft retains Defender data for 180 days in the portal but makes it queryable in advanced hunting for just 30 days, and its schema is a fixed set of tables. Sentinel takes arbitrary sources at whatever retention you configure.
What is the Microsoft unified security operations platform?
Microsoft Sentinel running inside the Microsoft Defender portal, so one incident queue and one hunting surface cover both products. Sentinel does not require Defender XDR or an E5 licence to run there. Once connected, Sentinel Microsoft incident creation rules turn off, because the Defender portal does its own correlation.
How does an MSSP get access to a customer's Microsoft Sentinel?
Through Microsoft Entra B2B guest access, not GDAP. Microsoft states that GDAP reaches Defender data only and that Sentinel does not support it at this time. Cross-tenant Sentinel queries additionally require Azure Lighthouse, and that holds inside the Defender portal, not only the Azure portal.
Which Microsoft licences does an MSP need to deliver managed detection and response?
Defender XDR access is licence-gated per tenant, and qualifying SKUs include Microsoft 365 E5 or A5, and Microsoft 365 E3 with the Microsoft Defender Suite add-on. Microsoft Sentinel is separate: it runs in the Defender portal without Defender XDR or an E5 licence, and bills on ingestion.
How does Microsoft Sentinel classify a closed incident?
Across two fixed fields. Classification accepts exactly four values: TruePositive, BenignPositive, FalsePositive, and Undetermined. The closing reason accepts four more: SuspiciousActivity, SuspiciousButExpected, IncorrectAlertLogic, and InaccurateData. Both enums are closed, so any tool writing a verdict back to Sentinel has to map into them.
How does Microsoft Defender XDR decide which alerts become one incident?
Defender XDR correlates signals from the Microsoft security products a tenant has licensed and provisioned access to, grouping related alerts into one incident. Correlation breadth therefore follows licensing: a tenant without Defender for Identity or Defender for Cloud Apps gives the correlation engine less signal to join.
What are the limits of Microsoft multitenant management for a service provider?
Multitenant management in Defender does not support Microsoft Defender for Business tenants, and Azure Lighthouse-delegated users are excluded from automatic workspace onboarding to the Defender portal. Lighthouse is still required to query a secondary workspace in another tenant, and for some automation rule and playbook scenarios.
Does ContraForce offer a self-hosted or customer-hosted deployment?
No. ContraForce does not offer Bring Your Own Cloud, customer-hosted, or self-hosted deployment. ContraForce Cloud is the single deployment model: ContraForce hosts and operates the platform, so there is no infrastructure to stand up and nothing to run in your own Azure subscription.
What permissions does ContraForce need in a customer tenant?
ContraForce registers scoped Microsoft Entra ID enterprise applications in each client tenant, consented separately for the modules that tenant enables, so a Defender-only tenant never grants Sentinel or email permissions. A Global Administrator grants the one-time admin consent. There are no endpoint agents, no infrastructure to stand up, and no log forwarding.
Does ContraForce require agents on endpoints?
No. ContraForce requires no endpoint agents. ContraForce connects through scoped Microsoft Entra ID enterprise applications and works against Microsoft Defender XDR telemetry directly through API. There is no software to deploy to endpoints, no collector to run, and no log forwarding to configure.
Where does ContraForce process and store data?
ContraForce operates regionally isolated deployments on Microsoft Azure. Each deployment runs its own application services, message bus, database, storage, and AI inference endpoint. Customer data assigned to a deployment is processed and stored entirely within that deployment and does not transit another region.
Which regions does ContraForce support?
ContraForce runs two deployments today, the United States and the United Kingdom, and a European Union deployment is scheduled for September 2026. Until it opens, ContraForce assigns EU customers to the United Kingdom, where transfers rest on the European Commission adequacy decision for the UK.
Does ContraForce offer EU data residency?
A ContraForce European Union deployment is scheduled for September 2026, after which EU customer data is processed and stored inside the EU. Today ContraForce serves EU customers from its United Kingdom deployment, where transfers rest on the European Commission adequacy decision for the UK.
Is customer security data used to train ContraForce AI models?
No. ContraForce does not train or fine-tune AI models on customer data or any other data. ContraForce Security Delivery Agents use existing models to perform triage, investigation, enrichment, and response on incident data at the time the work is performed, and inference runs inside the same regionally isolated deployment that holds that incident data.
What are ContraForce's compliance certifications?
ContraForce maintains an information security management system that is independently audited to SOC 2 Type II and aligned to ISO 27001:2022. The ISMS is aligned to ISO 27001, not certified against it. The SOC 2 Type II report and supporting control documentation are available on request under NDA.
Does ContraForce store customer security data?
ContraForce does not bulk-export, copy, or warehouse your security data, and does not operate a separate security data lake. Your logs and telemetry stay in your own SIEM or XDR platform under your retention settings. ContraForce holds the incident records, verdicts, and evidence its agents produce, inside your assigned regional deployment.