Identity threat detection & response
Attackers do not break in.
They sign in.
ITDR watches Microsoft 365 and Entra ID for the identity attacks your other tools treat as normal activity — stolen sessions, quiet mailbox rules, consented rogue apps, and the persistence left behind afterwards.
- Entra ID, Exchange, SharePoint, Teams
- Microsoft 365
- Users and system log, same detections
- Okta
- From sign-in event to triaged incident
- Minutes
The real problem
Identity is the perimeter, and it is largely unwatched.
Endpoint and network tooling assumes an intruder who does not belong. Identity attacks look exactly like the people who do.
- 01Attackers sign in rather than break in. A valid password and an approved MFA prompt leave almost no trace that looks like an attack.
- 02The evidence is scattered. Sign-in logs, audit logs, mailbox rules, OAuth grants and device state each live behind a different screen.
- 03Microsoft raises alerts you cannot action. They tell you something scored highly; they rarely tell you what happened next, or what to do.
- 04Business email compromise is quiet by design. A forwarding rule and a consented app can sit unnoticed for months.
- 05By the time it is obvious, the attacker has persistence — a new secret on an app, a second factor they control, a mailbox rule you did not write.
How it works
Connected in minutes, useful the same day.
Connect in a few minutes
A global admin approves once. ITDR provisions a dedicated application inside your own tenant with least-privilege permissions, then starts reading identities, devices, sign-ins, audit events and workload identities.
No agents. No credentials pasted into a form. The app lives in your tenant and you can revoke it there.
Correlate, do not just collect
Signals are normalised into one timeline per identity, so a risky sign-in, an MFA method change and a new inbox rule read as one story rather than three unrelated rows.
Raw provider payloads are retained alongside the normalised record, so every finding can be traced back to its source.
Act with a record
Revoke sessions, disable an account, contain a device — from the incident, with the target, the actor, the connector used and the provider response captured.
Destructive actions require approval, and the riskiest require a second admin. Nothing runs silently.
What it covers
Four surfaces, one investigation.
Findings from each surface land in the same incident timeline, so a rogue application and a suspicious sign-in are one story rather than two queues.
Identity threat detection
- Credential-theft and password-spray patterns
- Token replay and adversary-in-the-middle sign-ins
- Device-code phishing, the Storm-2372 pattern
- Successful sign-in following a burst of failures
Business email compromise
- Malicious inbox rules and silent mail forwarding
- Risky sign-in followed by an MFA method change
- OAuth consent grants to unverified applications
- The full chain, correlated as one incident
Workload identity
- New secrets or certificates added to existing apps
- Applications holding tenant-wide mail or file access
- Dormant service principals that suddenly wake up
- Ownerless privileged applications nobody governs
Posture and compliance
- Continuous Microsoft 365 posture scanning
- Conditional Access and MFA coverage gaps
- Evidence mapped to CIS, ISO 27001, HIPAA and CMMC
- Auditor-ready packages generated per framework
The full rule set, with the MITRE ATT&CK technique behind each one, is published at /detections.
Straight answers
What every vendor says, and what to ask next.
Including us. These are the questions worth putting to anyone selling you identity security, and our answers to them.
| The claim | What to ask |
|---|---|
| “We ingest your Microsoft logs.” | Collecting is the easy half. The question is whether anything correlates a sign-in to the mailbox rule created eleven minutes later. |
| “AI-powered detection.” | Ask what fires the alert. Ours are deterministic rules with named MITRE techniques, so you can read exactly why something triggered. |
| “Automated response.” | Automation that disables accounts without approval is a liability. Destructive actions here need an approver, and the worst need two. |
| “Full coverage.” | Some signals need Entra ID P1 or P2. We show you which detections your licence actually supports rather than failing quietly. |
| “Single pane of glass.” | A pane you cannot act through is a report. Every incident here carries the response actions its evidence supports. |
Who it is for
Built multi-tenant from the first commit.
Managed service providers
Every customer is an isolated tenant under your organisation. Switch between them, keep evidence separated, and report per client or across the whole book.
Internal security teams
One place for identity risk, from the sign-in that looked wrong to the containment action you took and can prove.
Teams preparing for audit
Posture findings map to framework controls automatically, with manual attestation where a control lives outside Microsoft 365.
See what your tenant is already telling you.
Connect a Microsoft 365 tenant and review your identity posture, workload identities and conditional access coverage.
Would rather talk first? Get in touch and we will walk you through it.