ITDR: Identity Threat Detection and Response

Catch compromised accounts, impossible travel, and privilege abuse before they own your tenant.

Required for all clients

Identity Threat Detection and Response (ITDR) watches how people and accounts sign in, and how privileges change, across your Microsoft 365 world. Firewalls do not stop a stolen password. MFA helps a lot, then attackers steal sessions or spam approval prompts until someone taps Yes by mistake.

For Perth SMEs, identity is often the real perimeter. Staff work from home, from site, from phones. Email and Teams hold the business. If an account is taken over, the attacker can reset invoices, create mailbox rules that hide theft, or invite themselves into SharePoint as a “new contractor”.

Stride IT requires ITDR for every client under Continual Security Uplift (see /one-plan/). It pairs with EDR on devices and SIEM for correlated alerts. The dedicated page is at /security-standard/security-stack/itdr/.

What ITDR is, in plain terms

ITDR focuses on identity abuse in motion. Not only whether MFA is switched on in a policy screen, but whether sign-ins look normal for that person, from that place, on that device, at that time.

Classic examples: a bookkeeper who always signs in from Perth suddenly authenticates from another country at 3am. An admin account creates a new global admin at midnight. A user who never travels shows “impossible travel” between two cities in an hour. A dormant guest account wakes up and starts downloading files.

ITDR tools and managed processes flag those patterns. Analysts investigate. They force sign-outs, reset credentials, revoke sessions, and stop mailbox rules that forward mail to strangers. Then they feed the lesson back into hardening so the same path is harder next time.

It is different from Identity Security Posture Management (ISPM). ISPM is the tidy-up and continuous check: MFA gaps, stale guests, over-privileged accounts. ITDR is the alarm and response when an attack is underway. You want both. Posture reduces the blast radius. Detection stops the live fire.

Why Perth SMEs get hit without it

Password reuse is still common. People use the same phrase for a supplier portal and their work mailbox. Credential stuffing does the rest. Attackers do not need to “hack the server” if they can walk in as you.

Business Email Compromise hits WA firms hard because invoice fraud is quiet. Nobody notices until a payment went to the wrong account. The attacker did not encrypt anything. They just sat in the mailbox, watched payment patterns, then altered bank details in a thread that looked normal.

Many MSPs set MFA once and call identity “done”. MFA is necessary. It is not ITDR. Without monitoring for risky sign-ins, token theft, and privilege abuse, you only find out when the CFO asks why a supplier was paid twice.

Small teams often share admin accounts “just for convenience”. That convenience becomes a single key to everything. Without ITDR, there is no early signal when that key is used from the wrong place.

Perth’s mix of professional services, trades with office staff, and medical or allied health practices means lots of client data in email. Regulators and clients increasingly ask how you detect account takeover. “We have MFA” is the start of an answer, not the end.

What good looks like day to day

Quiet days mean risky sign-in alerts are few and explained. A staff member on holiday in Bali triggers a review; the analyst confirms it is them and closes it. A blocked legacy protocol attempt shows someone still has an old mail app; that gets fixed in uplift work.

When a real takeover starts, speed matters. The account is disabled or sessions revoked. Forwarding rules are removed. Recent sent items are checked for fraud. Conditional Access gaps that allowed the path get scheduled into the next uplift actions, not left as a footnote.

Directors get plain language: which account, what the attacker tried, what was stopped, what staff should do (reset, watch invoices, call the bank if needed). No unexplained portal screenshots.

Good ITDR also respects business rhythm. Finance period ends, tenders, and end-of-month are high-risk windows. Coverage does not take those weeks off.

What bad looks like

Bad is MFA fatigue with no coaching and no detection when someone finally approves a prompt they did not start. Bad is guest users lingering for years. Bad is “break glass” admin accounts with passwords in a shared spreadsheet.

Bad is identity alerts going only to an MSP ticket queue that treats them like password resets. Nobody correlates “weird login” with “weird endpoint behaviour” because ITDR and EDR are siloed or missing.

The ugly version is discovering compromise through a customer: “Did you mean to send this invoice?” By then the attacker may have weeks of mailbox history and every contact list you own.

If your provider cannot show identity investigations and response actions from the last quarter, you are not running ITDR. You are hoping passwords hold.

How it fits with Microsoft 365 Business Premium and Defender

Business Premium gives you Entra ID controls, Conditional Access foundations, and Defender signals for identity risk when configured. Those native tools are powerful. They still need finishing and watching.

Many tenants have Conditional Access policies that are incomplete, or exclusions that grew like weeds. Legacy authentication still sneaks through. Shared mailboxes become soft targets. Secure Score shows the gap; someone has to close it.

ITDR does not replace Conditional Access or MFA. It watches for the moments those controls are bypassed, misconfigured, or socially engineered. It works with ISPM so posture findings become fixes, and with EDR so a stolen session that lands on a device still gets caught on the endpoint side (see /security-standard/security-stack/edr/).

Common sense still applies. Separate admin accounts. No permanent standing global admins for daily work. Phishing training so staff pause before approving mystery prompts. Microsoft licences create the platform. Operating discipline and managed detection make it real.

What directors should ask their IT provider

Ask how account takeover is detected after hours. Ask who can revoke sessions and disable accounts without waiting for a board email. Ask for examples of impossible travel or risky privilege changes handled in the last six months.

Ask how many guest accounts you have and when they were last reviewed. Ask whether privileged roles use stronger controls than standard users. Ask how mailbox forwarding rules are monitored.

Ask how ITDR links to your Continual Security Uplift plan. A contained takeover that never tightens Conditional Access is a near miss you will repeat.

If the answer is “Microsoft handles that automatically”, push harder. Microsoft provides capabilities. Someone still has to operate them, respond, and prove the work in reviews you can read.

How ITDR ties to Continual Security Uplift

Under Continual Security Uplift, identity is a live control, not a project from 2022 (see /one-plan/). Baseline maps MFA coverage, Conditional Access gaps, and detection readiness. Stabilise closes the worst holes. Continual reviews track incidents and posture drift.

ITDR findings feed ISPM work and Secure Score movement. SIEM helps correlate identity events with endpoint and Microsoft 365 signals (see /security-standard/security-stack/siem/). The point is one story for directors: we detect abuse, we contain it, we harden so it is harder next time.

Refuse ITDR and you are asking us to leave the front door on a sensor with no night shift. We decline that engagement. The stack overview is at /security-standard/security-stack/, and this page lives at /security-standard/security-stack/itdr/.

Most modern breaches start with an identity problem, not a Hollywood exploit. ITDR is how you notice early and act while you still have options. Pair it with Business Premium done properly, EDR on devices, and an uplift program that does not stop at “MFA is on”. That is the Stride IT floor for Perth clients who mean it.

Further reading

What is ITDR? Identity attacks explained for Perth SMEs

A longer owner’s guide on the same topic, written for Perth businesses comparing providers.

Read the blog

WHAT YOU GET

Compromised accounts found and locked before mailbox rules empty the company.

Clear trail of what happened for your board and, if needed, your insurer.

Identity treated as a live control, not a set-and-forget MFA checkbox.

FREQUENTLY ASKED QUESTIONS

Is ITDR required for Stride IT clients?

Yes. Identity Threat Detection and Response (ITDR) is required for every client under the Stride IT Security Standard. It is not an optional add-on. If you will not run it, we decline.

How does ITDR fit Our One Plan?

ITDR is part of the required detection and posture stack inside Our One Plan. It sits on top of Microsoft 365 Business Premium. We baseline it in the Baseline Review, implement it during Stabilise and Uplift, and review it in quarterly Continual reviews.

Do you sell this as a standalone product?

No. This stack runs as part of Our One Plan with Continual Security Uplift. We do not cherry-pick detection controls while leaving the rest of the Standard unfinished.

THE REST OF THE STACK

APPLY FOR BASELINE

We confirm Business Premium readiness and the full required stack, including ITDR, before we start.

Apply for Our One Plan

Still here? Apply for Our One Plan.

Baseline is an application, not a shopping cart. We confirm Business Premium readiness, the required stack (EDR, ITDR, SIEM, SAT, ESPM, ISPM), map Secure Score to the Stride IT Security Standard, and show a tailored uplift plan and schedule. If you will not support the minimum, we decline. Early, clearly, and without drama.