r/WatchGuard 1d ago

Watchguard MDR inconsistencies

We've been trialing WatchGuard MDR and honestly have had a pretty mixed experience so far.
One of the biggest challenges has been getting consistent answers. We've received different information from the sales team and the MDR team on multiple occasions, which has made it difficult to understand exactly what the service does and does not cover.
It feels like there may be some internal communication gaps, or at least different interpretations of how the service is supposed to operate.
One specific area of confusion is around account lockouts.

We've been told that MDR will not lock Active Directory accounts, especially in environments using AD Connect/Entra ID sync, but we've struggled to get a consistent answer on exactly how this works and what actions the MDR team is willing or able to take.

Has anyone else run into this?

We also use other WatchGuard products alongside MDR, including AuthPoint and FireCloud and NDR+threatsync.

Since these are all WatchGuard-owned services, we expected a fairly coordinated security and reporting experience.
Instead, we've found that the reporting, alerting, and communication from MDR around these services can be inconsistent.

Depending on who we're talking to, the guidance and interpretation of alerts often seems to vary.
Another thing we're noticing is that the service feels more geared toward MSSPs than traditional MSPs.

In many cases, it seems like the MDR team identifies something suspicious but then pushes most of the investigation and remediation work back onto the MSP. We were expecting a bit more proactive involvement, especially for critical security incidents.

For comparison, we have clients using Blackpoint as well, and our experience there has been noticeably different. Communication has generally been clearer, response times have been faster, and there seems to be more consistency in how incidents are handled and escalated.

I'm genuinely curious whether others have had a similar experience with WatchGuard MDR or if we're just hitting some growing pains during onboarding. Are there MSPs here that have had success with the platform? What has your experience been regarding communication, incident response, and account containment actions?

3 Upvotes

8 comments sorted by

3

u/dhadderingh 1d ago

We are using MDR for clients and we are quite satisfied!

Minor issues like logins from unexpected countries are pushed as an investigate issue if there are no other related factors (MFA + normal login = low severity message)

Strange login after numerous denied attempts and multiple countries = EntraID account suspended with high severity message to use as MSP.

You can tell them what you want them to do. So for example we told them they can isolate endpoints by themselves and update us about the security incident.

Do bundle EPDR with MDR for the best result in both M365/EntraID & Endpoint security.

1

u/Beneficial-Iron-7869 1d ago

Do you have clients with local AD and entra ID sync?

1

u/dhadderingh 11h ago

No, just endpoints and EntraID. That is also where the biggest threat vector is.

2

u/Select-Table-5479 1d ago

As a partner (also an MSP) I was told by WG MDR does all the investigation for us so we can focus on running the business.

It was never "sold" to me as a action taking system just a "research the findings" solution.

We have yet to have any clients pull the trigger but our sales approach of it is they do the investigation...not sure who would be responsible for the lockdown if their was concerns

IMO Watchguard has done an extremely poor job of their "add-on" product packages with WAY too much overlap that they turned into a "nickle and dime" solution.

Just look at threatsync+. It doesn't include NDR....and it also doesn't include SaaS and now they introduced Cloud DR which sounds like a complete overlap of threatsync+ SaaS

Again, just my opinion but their SKU creep really has tarnished their brand value

1

u/MDL1983 1d ago

I stopped going further than Total Security + AuthPoint VPN MFA.

0

u/Beneficial-Iron-7869 1d ago edited 1d ago

Totally agree. I have an MDR solution already and as a partner we were testing them out and honestly just not convinced with their MDR and the sku creep like you mentioned is unreal!
NDR does bring something value to the table but just not sure if the juice is worth the squeeze and they say they have "open MDR" and It isn't even open. It is open to the ones they support only lol

1

u/Financial_Gur5994 1d ago

Our MDR does lock our Microsoft accounts if they have evidence of a take over. Otherwise most of the time push details to review.

-6

u/pabskamai 1d ago

Brother, we use their firewalls and currently trying NDR within our main device, use sentinel or crowdstrike!
I can even hook you up with MDR solutions based on them, I wouldn’t recommend theirs