ClearSkies iISOC for MSSPs

Become a partner

Everything a provider buys is measured in daily ingestion volume, and every client it serves occupies a tenant inside one deployment. A tenant is licensed on a bundle, and the bundle sets the daily volume and the entitlements that come with it. Two bundles are sold per tenant, Lite and Pro, and a provider that prefers to buy capacity once and allocate it takes the Ultimate volume pool instead.

How a provider buys it

A provider picks the one that matches how it buys. Under MSSP Ultimate the provider buys a daily ingestion volume up front and distributes it across its client tenants, moving volume between them as clients are signed or churn, so unused capacity is reallocated rather than repurchased. Under Pay-As-You-Grow the provider buys one tenant license at a time, Lite or Pro, sized to the client in front of it. Both routes carry the same platform, the same operator console and the same add-on catalog; what differs is when the capacity is bought and who holds the headroom.

MSSP UltimatePay-As-You-Grow: Lite and Pro
What is boughtA daily ingestion volume, held as a poolOne tenant license at a time, on the Lite or Pro bundle
VolumeBulk volume and extended in volume increments5 or 10 GB per day on Lite, 20, 30 or 40 GB per day on Pro
How capacity movesAllocated and reallocated across tenants from the console, without a repurchaseFixed to the tenant it was bought for. A tenant that outgrows Lite moves to Pro or Ultimate
Suited toA practice with a book to serve and a growth plan, optimizing unit cost through volumeA practice scaling on actual client acquisition, and pilots
Commercial profileLower cost per gigabyte, predictable capacity planning, headroom held by the providerMinimal initial commitment, cost that starts when the client does
PrerequisiteiISOC Platform Central Management Console, billed once a yeariISOC Platform Central Management Console, billed once a year

The iISOC Platform Central Management Console is included with the first purchase and billed once a year, whatever the number of tenants that follow. It is the console from which volume, bundles, tiers and add-ons are assigned, so a second tenant costs a bundle and no new infrastructure.

Licensing is measured in daily ingestion volume rather than in endpoints or seats, and a provider either holds that volume as a pool it distributes across clients or buys it one tenant at a time, so efficiency gained through automation is retained by the provider instead of being surrendered as a discount.

Licensed by the surface it protects

Native add-onExposure domainLicensed by
Attack Surface MonitoringExternal exposureIn-scope sub-domains monitored under the authorized root domains
DNS ShieldResolution layerDNS queries analyzed per day
Identity Threat ProtectionIdentity planeProtected identities, human and service
Active DefenseActive responseProtected environment or scope
Endpoint Threat Monitoring and ResponseEndpointMonitored endpoints
AI-SecOps Autonomous AnalystAlert and incident triageNumber of intelligent analysts
View plans

From contract to first reporting cycle

Onboarding is templated per environment type rather than built per client.

The first day

Establishes the tenant, applies the baseline policy inherited from the service package, and begins ingestion from the sources the client already runs.

The first week

Completes connector coverage, tunes the baseline against observed traffic, and produces the initial exposure picture from Attack Surface Monitoring.

The first month

Delivers the first full reporting cycle, the initial coverage and gap view against MITRE ATT&CK, and the tuning backlog that sets the next cycle.

The client supplies administrative access to the sources in scope, an escalation contact tree, and the response authority matrix that governs what may be actioned without approval.

Frequently asked questions

Microsoft Sentinel is already covered by the E5 license.

The license covers ingestion and analytics for one infrastructure, not multi-tenant delivery. A provider still supplies the tenancy model, the cross-client operations, the correlation across non-Microsoft sources, and the branding layer, and still pays for ingestion above the entitlement. The comparison to run is fully loaded cost per tenant at the volume the provider actually carries, not license cost at zero.

An existing white-label MDR arrangement already works.

It does, and it will continue to. The question is what it is worth in three years: efficiency gains accrue to the supplier, the client relationship is shared, and the capability is not proprietary at exit. The three-routes comparison on the overview states this without arguing that every provider should switch.

Where does client data live, and who can reach it?

Separation is enforced at the data layer, no tenant holds or infers the data of another, and hosting region is configurable per deployment. The subprocessor terms and the assurance reports are the artifacts to review.

Volume pricing means a noisy client eats my margin.

Volume is bought in bands rather than metered without a ceiling, so a busy month meets a known band instead of an open invoice. The console reports ingestion per tenant, so a client that grows is repriced on evidence at renewal. Normalization and filtering happen at collection, so low-value telemetry is dropped before it counts against the band. Under MSSP Ultimate, capacity released by one client is reallocated to another rather than repurchased.

Our clients are standardized on another endpoint vendor.

That is the normal case and it is not an obstacle. Endpoint telemetry from the vendor the client already runs is ingested and correlated, and response actions are executed through it where the vendor exposes them. Endpoint Threat Monitoring and Response is licensed only where a client has no incumbent or is replacing one.

Next steps

To evaluate ClearSkies MSSP, request a partner workshop, a sandbox tenant and a quotation against the intended client base from the ClearSkies partner team.