{
  "kind": "unassessed-research-protocol",
  "version": "1.0",
  "publishedAt": "2026-09-19",
  "reviewDue": "2026-12-19",
  "slug": "edr-managed-endpoints",
  "segment": "edr",
  "title": "Response on managed endpoints",
  "profile": "A small team supporting a mixed Windows, macOS, and Linux fleet, with staged rollout and reversible containment.",
  "critical": [
    "Required operating systems and response actions are supported.",
    "A contained device can be safely restored.",
    "An action is attributable to an authorized responder."
  ],
  "missing": [
    "An agreed device and OS version matrix",
    "Repeatable endpoint behavior and recovery tests",
    "Sensor overhead, administration, and licensing evidence"
  ],
  "threshold": 70,
  "minimumCoverage": 0.8,
  "rubric": {
    "capability": [
      {
        "name": "Required functions",
        "weight": 40
      },
      {
        "name": "Representative effectiveness",
        "weight": 30
      },
      {
        "name": "Evidence and explainability",
        "weight": 15
      },
      {
        "name": "Required data exchange",
        "weight": 15
      }
    ],
    "operating": [
      {
        "name": "Staffing and administration",
        "weight": 30
      },
      {
        "name": "Environment and deployment",
        "weight": 25
      },
      {
        "name": "Integration maintenance",
        "weight": 20
      },
      {
        "name": "Portability and exit",
        "weight": 15
      },
      {
        "name": "Cost predictability",
        "weight": 10
      }
    ]
  },
  "products": [
    {
      "name": "Microsoft Defender for Endpoint",
      "scope": "Plan 2 candidate; device/server entitlements and platform feature differences require confirmation.",
      "source": "https://learn.microsoft.com/en-us/defender-endpoint/supported-capabilities-by-platform",
      "status": "unassessed",
      "capability": null,
      "operating": null
    },
    {
      "name": "Elastic Defend",
      "scope": "Endpoint protection integration; exact platform and subscription requirements remain unselected.",
      "source": "https://www.elastic.co/docs/solutions/security/configure-elastic-defend",
      "status": "unassessed",
      "capability": null,
      "operating": null
    }
  ]
}