Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Microsoft Defender

Comprehensive IT security for your company with Microsoft Defender

We implement and operate the complete Microsoft Defender stack: from endpoint through identity and cloud workloads to email protection. As a Solutions Partner for Security.

Book a consultation
Smiling man in a striped shirt sits at a laptop in a bright meeting room.
Vorteile

Why companies entrust us with their Defender environment.

The complete stack, not just endpoint

We implement all Defender products as a connected system: from endpoint through identity to cloud workloads and email protection.

01

Operated as MDR, not as a one-off project

For us, Defender is not a set-it-and-forget-it job but an ongoing service with active monitoring, alert triage and incident response.

02

Security as core business, not an add-on

As a Solutions Partner for Security, Microsoft Defender is not one product among many but part of a consistent zero-trust architecture.

03

Expertise

Our Microsoft Defender portfolio at a glance.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M15.75 9.75L22.25 9.75V20.25H15.75V9.75Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M12.75 19.25H1.75V16.25H12.75" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M20.25 6.75V3.75H3.75V16" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Defender for Endpoint

Behavioral protection for all clients and servers. Detects attacks that signature scanners miss, responds automatically, and provides a central device inventory. Not a traditional antivirus scanner, but a true EDR platform.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M12 8.75C11.1716 8.75 10.5 9.42157 10.5 10.25C10.5 11.0784 11.1716 11.75 12 11.75C12.8284 11.75 13.5 11.0784 13.5 10.25C13.5 9.42157 12.8284 8.75 12 8.75ZM12 8.75V14.75M12 2.75L20.25 5.5V11.9123C20.25 16.8848 16 19.25 12 21.4079C8 19.25 3.75 16.8848 3.75 11.9123V5.5L12 2.75Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Defender for Identity

Monitoring Active Directory and Microsoft Entra ID for suspicious behavior. Detects attack techniques such as Pass-the-Hash, Kerberoasting, and Lateral Movement before they cause damage.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M9.5 12.25L11 13.75L14.5 10.25M3.75 3.75H20.25V17.75L12 22.25L3.75 17.75V3.75Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Defender for Office 365

Protection for email, Microsoft Teams, and SharePoint against phishing, malware, and Business Email Compromise. Automatic quarantine, real-time analysis of incoming links, and optional attack simulations for your team.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M8.25 13.25C6.17893 13.25 4.5 11.5711 4.5 9.5C4.5 7.60044 5.91237 6.03077 7.74426 5.78381C8.35237 4.01838 10.0281 2.75 12 2.75C14.4853 2.75 16.5 4.76472 16.5 7.25C18.1569 7.25 19.5 8.59315 19.5 10.25C19.5 11.9069 18.1569 13.25 16.5 13.25H8.25Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><circle cx="12" cy="18.75" r="2.5" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M9.5 18.75H2.75" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M21.25 18.75H14.5" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M12 16V13.5" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Defender for Cloud

Protection and visibility for Azure workloads, cloud applications, and shadow IT. Real-time vulnerability management, compliance score, and anomaly detection across your entire cloud environment.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M2 11.9999C6.82745 2.33329 17.1725 2.3334 22 12C17.1725 21.6666 6.82745 21.6665 2 11.9999Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M15.25 12C15.25 13.7949 13.7949 15.25 12 15.25C10.2051 15.25 8.75 13.7949 8.75 12C8.75 10.2051 10.2051 8.75 12 8.75C13.7949 8.75 15.25 10.2051 15.25 12Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Microsoft Sentinel

Azure-based SIEM and SOAR. All security logs in one place, automated playbooks for standard scenarios, and AI-powered threat intelligence. Defender XDR automatically correlates signals from Endpoint, Identity, Email, and Cloud into incidents.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M15.75 9.75L22.25 9.75V20.25H15.75V9.75Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M12.75 19.25H1.75V16.25H12.75" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M20.25 6.75V3.75H3.75V16" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Defender for Endpoint

Behavioral protection for all clients and servers. Detects attacks that signature scanners miss, responds automatically, and provides a central device inventory. Not a traditional antivirus scanner, but a true EDR platform.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M12 8.75C11.1716 8.75 10.5 9.42157 10.5 10.25C10.5 11.0784 11.1716 11.75 12 11.75C12.8284 11.75 13.5 11.0784 13.5 10.25C13.5 9.42157 12.8284 8.75 12 8.75ZM12 8.75V14.75M12 2.75L20.25 5.5V11.9123C20.25 16.8848 16 19.25 12 21.4079C8 19.25 3.75 16.8848 3.75 11.9123V5.5L12 2.75Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Defender for Identity

Monitoring Active Directory and Microsoft Entra ID for suspicious behavior. Detects attack techniques such as Pass-the-Hash, Kerberoasting, and Lateral Movement before they cause damage.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M9.5 12.25L11 13.75L14.5 10.25M3.75 3.75H20.25V17.75L12 22.25L3.75 17.75V3.75Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Defender for Office 365

Protection for email, Microsoft Teams, and SharePoint against phishing, malware, and Business Email Compromise. Automatic quarantine, real-time analysis of incoming links, and optional attack simulations for your team.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M8.25 13.25C6.17893 13.25 4.5 11.5711 4.5 9.5C4.5 7.60044 5.91237 6.03077 7.74426 5.78381C8.35237 4.01838 10.0281 2.75 12 2.75C14.4853 2.75 16.5 4.76472 16.5 7.25C18.1569 7.25 19.5 8.59315 19.5 10.25C19.5 11.9069 18.1569 13.25 16.5 13.25H8.25Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><circle cx="12" cy="18.75" r="2.5" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M9.5 18.75H2.75" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M21.25 18.75H14.5" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M12 16V13.5" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Defender for Cloud

Protection and visibility for Azure workloads, cloud applications, and shadow IT. Real-time vulnerability management, compliance score, and anomaly detection across your entire cloud environment.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M2 11.9999C6.82745 2.33329 17.1725 2.3334 22 12C17.1725 21.6666 6.82745 21.6665 2 11.9999Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M15.25 12C15.25 13.7949 13.7949 15.25 12 15.25C10.2051 15.25 8.75 13.7949 8.75 12C8.75 10.2051 10.2051 8.75 12 8.75C13.7949 8.75 15.25 10.2051 15.25 12Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Microsoft Sentinel

Azure-based SIEM and SOAR. All security logs in one place, automated playbooks for standard scenarios, and AI-powered threat intelligence. Defender XDR automatically correlates signals from Endpoint, Identity, Email, and Cloud into incidents.

Certified. Verified. Confirmed.

Baggenstos is a Microsoft Solutions Partner for Security with expertise in Defender, Sentinel and the entire security stack. This specialisation is reviewed and confirmed by Microsoft every year.

Microsoft Solutions Partner for Security certification logo

Microsoft Solutions Partner for Security

Certified for Identity, Endpoint, and Cloud Security, including the «Cloud Security» specialization. Proven on real-world projects across the Microsoft security stack.

Microsoft Solutions Partner certification logo

Microsoft Solutions Partner

Highest Microsoft Partner designation, re-certified annually. Baggenstos holds several Solutions Partner Designations.

Microsoft Solutions Partner for Modern Work certification logo

Microsoft Solutions Partner for Modern Work

Certified for Microsoft 365, Teams, and Collaboration. Evidenced by successful client projects, usage metrics, and current team certifications.

Microsoft Solutions Partner for Security certification logo

Microsoft Solutions Partner for Security

Certified for Identity, Endpoint, and Cloud Security, including the «Cloud Security» specialization. Proven on real-world projects across the Microsoft security stack.

Microsoft Solutions Partner certification logo

Microsoft Solutions Partner

Highest Microsoft Partner designation, re-certified annually. Baggenstos holds several Solutions Partner Designations.

Microsoft Solutions Partner for Modern Work certification logo

Microsoft Solutions Partner for Modern Work

Certified for Microsoft 365, Teams, and Collaboration. Evidenced by successful client projects, usage metrics, and current team certifications.

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund

Sounds like what you need?

Video

Maximale Clientsecurity mit Microsoft 365 Defender

Why Baggenstos

Why Baggenstos Should Be Your Partner

60,000+

Microsoft 365 users in the Managed Service Program

1'000+

Cloud projects successfully implemented

Since 1925

100 years of continuity in family ownership

Zwei Mitarbeiter im Gespräch an einem Tisch mit Laptop vor begrünter Fensterfront im Büro

Holistic consulting

We don't deliver individual products but a consistent security strategy: from risk analysis through implementation to ongoing operations as Managed Detection & Response.

Certified Microsoft excellence

As a Solutions Partner for Security, we deploy Defender, Sentinel and the entire stack at the level Microsoft recommends for its own enterprise customers.

Focus on security & compliance

From threat detection to incident response: security is not our add-on offering but our core business. Every solution is based on zero-trust principles.

Guiding the change (change management)

The best security architecture is worthless if employees bypass it. We combine technology with awareness training and pragmatic policies.

FAQ

Frequently Asked Questions, Honest Answers

What does Microsoft Defender cost as a managed service?

The costs are made up of the Microsoft licences and our MDR operating costs. As a CSP partner we optimise your licensing – many companies find that Defender features are already included in their existing Microsoft 365 licences. We clarify the scope and pricing in an initial consultation. You receive a transparent quote based on your actual requirements.

Does Baggenstos also offer monitoring of Microsoft Defender as a managed service?

Yes. We operate Defender as Managed Detection & Response from the Swiss SOC. 24/7 monitoring, alert triage, incident response and monthly reporting are included. We filter out false positives, escalate genuine threats immediately and deliver forensic analyses. Protection stays active even when you are not looking.

What does the term Microsoft XDR mean in practice for our IT security?

XDR (Extended Detection & Response) connects endpoint, identity, email and cloud security into one platform. Defender XDR correlates signals: a phishing click on the laptop is linked with an identity compromise in a cloud service. Instead of isolated alerts, you receive a holistic view of the attack chain.

What is the difference between Microsoft Defender and a classic antivirus program?

A classic antivirus program compares files with signatures. Defender for Endpoint goes further: behaviour-based detection with AI, endpoint detection & response, automatic isolation in case of incidents and integration with identity and cloud security. Enterprise versions replace third-party scanners and save on duplicate licence costs.

Why is a normal spam filter not enough and why do we need Defender for Office 365?

Modern attackers rely on phishing and business email compromise: deceptively genuine emails with no malicious attachment that trick people into making transfers. A classic spam filter does not detect this. Defender for Office 365 checks links and attachments in real time, simulates suspicious content in a sandbox and blocks manipulated senders.

How does Defender for Endpoint protect our company laptops in the home office?

Defender for Endpoint runs on the laptop, regardless of location. Suspicious processes are detected and isolated in real time: an infected endpoint is disconnected from the network before malware can spread. Conditional Access checks the device status before every access. Protection in the home office is just as strong as in the office.

Can we continue using our existing antivirus solution?

As a rule we recommend replacing it, because running them in parallel can cause conflicts and the synergies with the Microsoft stack are lost. For the transition phase we operate both solutions in parallel. Whether an existing solution should be kept is something we assess during the assessment. Most companies benefit from moving to an integrated Microsoft security platform.

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund
Schedule an appointment now

When do we close the gaps in your security architecture?

Let's analyse your attack surface together.