Identity threat detection & response

Attackers do not break in.
They sign in.

ITDR watches Microsoft 365 and Entra ID for the identity attacks your other tools treat as normal activity — stolen sessions, quiet mailbox rules, consented rogue apps, and the persistence left behind afterwards.


Entra ID, Exchange, SharePoint, Teams
Microsoft 365
Users and system log, same detections
Okta
From sign-in event to triaged incident
Minutes

The real problem

Identity is the perimeter, and it is largely unwatched.

Endpoint and network tooling assumes an intruder who does not belong. Identity attacks look exactly like the people who do.

  • 01Attackers sign in rather than break in. A valid password and an approved MFA prompt leave almost no trace that looks like an attack.
  • 02The evidence is scattered. Sign-in logs, audit logs, mailbox rules, OAuth grants and device state each live behind a different screen.
  • 03Microsoft raises alerts you cannot action. They tell you something scored highly; they rarely tell you what happened next, or what to do.
  • 04Business email compromise is quiet by design. A forwarding rule and a consented app can sit unnoticed for months.
  • 05By the time it is obvious, the attacker has persistence — a new secret on an app, a second factor they control, a mailbox rule you did not write.

How it works

Connected in minutes, useful the same day.

01

Connect in a few minutes

A global admin approves once. ITDR provisions a dedicated application inside your own tenant with least-privilege permissions, then starts reading identities, devices, sign-ins, audit events and workload identities.

No agents. No credentials pasted into a form. The app lives in your tenant and you can revoke it there.

02

Correlate, do not just collect

Signals are normalised into one timeline per identity, so a risky sign-in, an MFA method change and a new inbox rule read as one story rather than three unrelated rows.

Raw provider payloads are retained alongside the normalised record, so every finding can be traced back to its source.

03

Act with a record

Revoke sessions, disable an account, contain a device — from the incident, with the target, the actor, the connector used and the provider response captured.

Destructive actions require approval, and the riskiest require a second admin. Nothing runs silently.

What it covers

Four surfaces, one investigation.

Findings from each surface land in the same incident timeline, so a rogue application and a suspicious sign-in are one story rather than two queues.

Identity threat detection

  • Credential-theft and password-spray patterns
  • Token replay and adversary-in-the-middle sign-ins
  • Device-code phishing, the Storm-2372 pattern
  • Successful sign-in following a burst of failures

Business email compromise

  • Malicious inbox rules and silent mail forwarding
  • Risky sign-in followed by an MFA method change
  • OAuth consent grants to unverified applications
  • The full chain, correlated as one incident

Workload identity

  • New secrets or certificates added to existing apps
  • Applications holding tenant-wide mail or file access
  • Dormant service principals that suddenly wake up
  • Ownerless privileged applications nobody governs

Posture and compliance

  • Continuous Microsoft 365 posture scanning
  • Conditional Access and MFA coverage gaps
  • Evidence mapped to CIS, ISO 27001, HIPAA and CMMC
  • Auditor-ready packages generated per framework

The full rule set, with the MITRE ATT&CK technique behind each one, is published at /detections.

Straight answers

What every vendor says, and what to ask next.

Including us. These are the questions worth putting to anyone selling you identity security, and our answers to them.

The claimWhat to ask
“We ingest your Microsoft logs.”Collecting is the easy half. The question is whether anything correlates a sign-in to the mailbox rule created eleven minutes later.
“AI-powered detection.”Ask what fires the alert. Ours are deterministic rules with named MITRE techniques, so you can read exactly why something triggered.
“Automated response.”Automation that disables accounts without approval is a liability. Destructive actions here need an approver, and the worst need two.
“Full coverage.”Some signals need Entra ID P1 or P2. We show you which detections your licence actually supports rather than failing quietly.
“Single pane of glass.”A pane you cannot act through is a report. Every incident here carries the response actions its evidence supports.

Who it is for

Built multi-tenant from the first commit.

Managed service providers

Every customer is an isolated tenant under your organisation. Switch between them, keep evidence separated, and report per client or across the whole book.

Internal security teams

One place for identity risk, from the sign-in that looked wrong to the containment action you took and can prove.

Teams preparing for audit

Posture findings map to framework controls automatically, with manual attestation where a control lives outside Microsoft 365.

See what your tenant is already telling you.

Connect a Microsoft 365 tenant and review your identity posture, workload identities and conditional access coverage.

Would rather talk first? Get in touch and we will walk you through it.