Identity
Most small-firm losses start with a mailbox, not a movie-style breach.
Managed ITDR watches the identities people use to read mail and open files. We collect sign-in and audit logs from Microsoft 365 or Google Workspace into the stack we run. On Microsoft 365, an account takeover can trigger an automatic response: revoke the session and remove a malicious inbox rule. Those logs can lag 60 to 90 minutes. We do not call that instant.
- Bundles
- Pro and Complete. Not included in Essentials.
- Coverage
- Continuous automated monitoring, with on-call response
- Price status
- Proposed — pending validation of hosting and staffing cost
What we watch
- Sign-ins that the logs can show as unusual: a new country, an impossible pair of locations, a burst of failures followed by success.
- Inbox rules that hide, delete, or forward mail. Wiring-instruction fraud often looks like this.
- New OAuth grants and enterprise applications.
- Legacy authentication, if the tenant still allows it, plus MFA gaps, guest users, and admin role changes.
What runs it
- The tenant’s own audit and sign-in logs, through Vector into Wazuh. We do not resell another company’s identity product under our logo.
- Shuffle for the automatic Microsoft 365 actions, and DFIR-IRIS for the case.
- MISP when an indicator from a real case is worth keeping.
What a person does
- Reviews what the automation already did, and calls when a person should hear it during published hours.
- Does not promise to see the event before Microsoft’s audit log does. That lag is often 60 to 90 minutes.
- Disables an account outright only with scoped access and written authority. Session revoke and malicious-rule removal are the automatic pair, and only on Microsoft 365.
What you decide
- Grant the scoped write that those two automatic actions need, or strike them from the order. Broader write access is still a separate line.
- Keep a break-glass admin that is not the same account we use every day.
- Tell us when someone is traveling, or when a contractor should have access, so we do not treat ordinary work as an attack.
Limits
- We see what the tenant logs, when Microsoft or Google emits them. A 60–90 minute Microsoft audit lag is normal. We will not write “real time” into a proposal for that tenant.
- Okta, Duo, or another identity provider as the system of record is a separate conversation. It is not silently included.
- We are not Microsoft support and we are not Google support.
- ITDR is not a full copy of every mailbox. We are not reading client matter files or patient charts as a routine.
We are not affiliated with or endorsed by the open-source projects named on this page.
The other services
- Managed EDRAn agent on the computers people work on, and a person who reads what it finds.
- Managed SIEMLog sources the endpoint agent does not already cover, kept and reviewed.
- Security Awareness TrainingShort simulations and a debrief a managing partner can read in a staff meeting.
- M365 Security PostureA written Microsoft 365 baseline, checked on a schedule, with drift called out.