ITDR

Tenant-scoped identity detection and response for Microsoft operators

Microsoft inventory, Entra logs, detections, incidents, posture findings, remediation workflow, and auditability in one operator console.

What The Platform Helps With

Operational Graph

Inventory plus activity, not just object lists

The platform keeps tenant-scoped identities, devices, applications, service principals, permissions, owners, audit events, and sign-ins in one operational data layer.

Custom Detection

Correlated alerts and incidents built from your tenant data

Recent app changes, credential-theft spray patterns, datacenter sign-in fan-out behavior, and correlated Entra activity are turned into explainable alerts and grouped incidents inside the platform.

Positioning

Not just a scan viewer and not just a raw log screen.

The product now sits across inventory, Entra evidence, custom detection, incident workflow, containment, and posture governance. It is meant to be the operating layer between Microsoft source systems and the team that has to investigate and act.

Customers usually already have portals, logs, and scan output. The value is the normalized workflow: evidence, prioritization, ownership, exceptions, and response in one tenant-scoped system.

What A Customer Sets Up

Two connectors, one operating model

Microsoft ITDR Connector

OAuth-based Microsoft ingestion for Graph inventory/activity plus Office 365 Management events and mapped provider alerts.

IdentitiesDevicesApplicationsService principalsAudit eventsSign-in eventsO365 Management eventsMapped provider alerts

Posture Connector

Dedicated Microsoft 365 posture scans against a curated control benchmark, with normalized findings and remediation context.

Control failuresCompliance mappingArtifactsAssigned remediationAccepted risk

Built For MSP Operations

One login, every customer tenant

ITDR is structured around how MSPs actually work: a partner admin switches between customer tenants from one session while each customer workspace stays fully isolated. Each role gets exactly the access and tools it needs — nothing shared across tenant boundaries.

Partner Admin

Single login, all customers.

  • Switch between every managed tenant without re-logging in
  • Per-tenant connectors, posture, alerts, incidents, and AI assistant scope
  • Invite tenant admins and analysts to individual customer workspaces
  • Pull weekly reports and identity assessments across the portfolio

Tenant Admin

Owns one customer workspace end-to-end.

  • Connect and maintain Microsoft Graph and posture connectors
  • Run containment actions with full audit trail per tenant
  • Assign remediation, accept risk, and manage exceptions
  • Configure Slack, Teams, or PagerDuty notifications per event type

Analyst / Read-only

Scoped investigation access per tenant.

  • Investigate alerts, incidents, logs, and identity context within their tenant
  • Use the AI tenant assistant to query live posture and incident data
  • No cross-tenant data access — fully enforced server-side
  • SOC handoff workflow with evidence links and response history

Advanced Operations

Detection, automation, and intelligence built in

Custom Detection Rules

Build your own detections on top of ingested tenant data

Operators can author custom detection rules alongside built-in behavioral rules, with a full draft → active → disabled lifecycle. Rules are scoped to the tenant and evaluated against the same normalized evidence the platform already collects.

Automated Playbooks

Structured response workflows triggered by alert conditions

Playbooks define automated response sequences tied to alert severity or type. Approval boundaries, dry-run validation, and capability checks keep automation safe — no arbitrary remote execution.

Microsoft Secure Score

Ranked control recommendations inside the investigation context

Secure Score data from Microsoft is surfaced alongside posture findings and identity context, giving operators a prioritized list of control improvements without switching to a separate portal.

What The Customer Gets

Operational outcomes instead of isolated tools

Operational Graph

Inventory plus activity, not just object lists

The platform keeps tenant-scoped identities, devices, applications, service principals, permissions, owners, audit events, and sign-ins in one operational data layer.

Custom Detection

Correlated alerts and incidents built from your tenant data

Recent app changes, credential-theft spray patterns, datacenter sign-in fan-out behavior, and correlated Entra activity are turned into explainable alerts and grouped incidents inside the platform.

Response Workflow

Containment actions where incidents point to real users

Operators can review evidence, open incidents, and run controlled Entra response actions such as revoke sessions, disable user, re-enable user, and group removal.

Posture Governance

Static control debt stays tied to live tenant operations

Posture findings, exceptions, remediation tasks, and workload identity risk context stay in the same workflow instead of becoming a disconnected scan report.

Questions The Product Answers

Which identities, applications, and service principals exist in this tenant?
Which Entra audit or sign-in events matter operationally right now?
Which Microsoft provider alerts were ingested from Office 365 Management feeds?
Which findings are governance debt versus active operational risk?
Which incidents are backed by real evidence and which user or workload identity is affected?
What containment action can the operator take directly from the investigation flow?
What risk has been accepted, assigned, remediated, or left unowned?

Practical Operator Flow

Tenant Admin

  1. 1Connect Microsoft Graph and posture scanning
  2. 2Review inventory, logs, alerts, and incidents
  3. 3Assign remediation or approve exceptions
  4. 4Use containment actions when a user-linked incident requires response

Analyst

  1. 1Open Logs to inspect normalized audit and sign-in evidence
  2. 2Move into Alerts for scored detections and rationale
  3. 3Use Incidents to follow grouped timelines and linked entities
  4. 4Track outcomes through notes, status, and response history

Identity Or Cloud Admin

  1. 1Investigate service principals, app permissions, and ownership gaps
  2. 2Review recent app changes and sign-in context
  3. 3Handle remediation work from posture or incident workflows
  4. 4Verify exceptions and accepted risk stay visible and auditable

Current Strengths

Tenant-scoped Microsoft inventory and Entra evidence in one place
Normalized audit and sign-in logs instead of a raw JSON-only experience
Office 365 Management provider alerts mapped into the same alert and incident workflow
Correlated alerts and incidents that map to tenant entities
Behavior-based identity detections including credential-theft and suspicious datacenter patterns
Custom detection rule builder for tenant-specific alert logic on top of existing feeds
Automated response playbooks with approval controls and dry-run validation
Built-in response actions for user-linked incident containment with capability checks
Microsoft Secure Score ranked recommendations surfaced in the investigation workflow
Exception governance, remediation tracking, and auditability
Multi-tenant MSP operating model with partner admin, tenant admin, and analyst roles
AI tenant assistant for live posture and incident queries, scoped to the active tenant
Slack, Teams, and PagerDuty notification routing with per-channel event type selection
Weekly security reports, incident autopsy PDFs, and identity assessments for customer QBRs
Workload identity coverage: service principals, app permissions, consent grants, ownerless apps

Best Fit

MSPs managing multiple Microsoft tenants from one partner login with per-tenant isolation
Security teams that need more than raw Entra portals and CSV exports
Teams that want investigation, response, and posture governance in one system
MSP analysts who need to ask questions about a customer tenant without writing queries
Customers that need auditable operator workflow and exportable evidence for compliance

Automation Boundary

Controlled response, not arbitrary execution

The platform is designed around scoped Microsoft actions, approval boundaries, response history, and tenant auditability. It is built to support operator response without turning into unsafe generic remote execution.

Evidence Model

Raw payloads are preserved, normalized views stay usable

Raw Graph and Office 365 Management payloads are still retained for traceability, but operators work from normalized logs, linked entities, scored alerts, grouped incidents, and response history instead of reading raw JSON by default.