top of page
24unet-cyber-first-hour-cover.webp
IDENTITY THREAT DETECTION AND RESPONSE

Would Your Setup Catch a Microsoft 365 Account Takeover at 2am on a Saturday?

The fastest-growing attack against businesses your size doesn't involve malware, and it doesn't trip your antivirus.

​

Someone signs in to a partner's Microsoft 365 mailbox using a stolen session. They quietly add an inbox rule that hides replies from the bank, then draft a "new wiring instructions" email to a client. Nobody is back at a desk until Monday.

​

This page explains identity threat detection and response (ITDR), why MFA alone doesn't stop this attack, and what to ask whoever protects you today.

THE SHORT VERSION

ITDR (identity threat detection and response) watches what user accounts do after they sign in: risky sign-ins, stolen sessions, new inbox rules and exposed passwords. When behavior turns hostile, it contains the account, for example by revoking sessions and disabling hostile inbox rules. It works alongside multi-factor authentication (MFA) and endpoint protection. It doesn't replace them.

THE OWNER'S VERSION

They don't break in anymore. They just log in.

ITDR watches the one thing your other tools don't: what an identity actually does after it signs in.

Screenshot_14.png
MFA is not a wall

Adversary-in-the-middle kits steal the session token after a legitimate MFA prompt. The login looks perfectly valid, because it is.

Screenshot_15.png
Email filters don't watch sessions

Email filters read messages. Once an attacker is inside the account, every message they send comes from your real mailbox, in a real thread. There's nothing for a filter to catch.

cloud.png
By then, money is gone

Hidden inbox rules bury the replies. In 2025 the FBI's IC3 logged more than $3 billion in reported business email compromise (BEC) losses, the second-largest category after investment fraud. That's about $123,000 per complaint, by our math from IC3. Source: FBI IC3 2025 report

WHAT IS ITDR

What is ITDR (identity threat detection and response)?

ITDR is security for your logins. It watches Microsoft 365 accounts for signs that someone other than the real user is in control, and it acts when they are.

Screenshot_14.png
Detect

Spots unusual sign-ins, risky behavior and passwords that have leaked online. It reads what the account does, not just whether the password was right.

Screenshot_15.png
Investigate

Checks whether it's really your employee. A new laptop on a business trip looks different from a stranger reading the CFO's inbox.

cloud.png
Respond

Contains the account: sessions revoked, hidden inbox rules disabled, sign-in blocked and the password reset.

WHAT YOU GET

Detection, containment and answers you can hand over

Screenshot_14.png
Behavioral detection

Reads behavior, not just the password. Flags stolen credentials, session abuse, password spray and impossible travel, and alerts when your people's passwords turn up in breach data.

Screenshot_15.png
Automatic containment

Ends the attacker's sessions, disables hidden inbox rules, blocks sign-in and forces a password and MFA reset before anyone reaches for the phone.

cloud.png
Answers you can hand over

A plain-English timeline of exactly what was touched: the report your insurer, your auditor and your attorney will ask for on day one.

No new vendor, no project, no downtime. We deploy it into your Microsoft 365 tenant in under an hour and monitor it alongside everything else we watch for you.

WHY MFA ISN'T ENOUGH

Why MFA alone doesn't stop a Microsoft 365 account takeover

Screenshot_14.png
Device-code phishing

The attacker starts a real Microsoft sign-in meant for TVs and printers, then emails you the code with a lure like "Action Required: Password Expiration." You type it on Microsoft's real page, and that signs them in. Microsoft says the EvilTokens campaign "compromised more than 12,000 inboxes in over 10,000 organizations worldwide." Source: Microsoft, September 2026

Screenshot_15.png
MFA fatigue and leaked passwords

Some attackers send push prompt after push prompt until someone taps "approve." Others use passwords reused from old breaches.

cloud.png
What actually closes the gap

Phishing-resistant MFA such as passkeys or security keys, which Microsoft and CISA both recommend. Blocking device code flow where you don't need it. And something watching what accounts do after sign-in. That last part is ITDR.

Keep MFA. Microsoft calls it "an essential pillar in identity security" that is "highly effective at stopping a variety of threats." But attackers have learned to work around it.

ILLUSTRATIVE TIMELINE

The 2am Saturday takeover, step by step

Screenshot_14.png
00:00 Signed in

The attacker signs in with a stolen session token. MFA never prompts.

Screenshot_15.png
00:34 Flagged

Behavior flagged: an unusual sign-in, and a new mailbox rule created.

cloud.png
00:56 Contained

Sessions revoked, rule disabled, account contained automatically.

headphones-with-mic.png
Same day: the report

You get a plain-English report of everything that was touched.

Detection and containment figures reflect published performance of the ITDR platform 24uNet deploys and monitors; results vary by tenant configuration. Attack timeline is illustrative.

HOW 24UNET DELIVERS IT

How 24uNet delivers ITDR

Screenshot_14.png
<1 min

Median detection time.

Screenshot_15.png
56 sec

Average containment.

cloud.png
24/7

Autonomous response, day or night.

headphones-with-mic.png
<1 hr

To deploy, with no downtime.

ITDR VS EDR VS MDR

ITDR vs EDR vs MDR: what's the difference?

Screenshot_14.png
EDR: protects devices

Watches laptops and servers. It catches things like malware or ransomware running on a machine.

Screenshot_15.png
ITDR: protects identities

Watches Microsoft 365 and Entra ID sign-ins. It catches stolen sessions, risky sign-ins, hostile inbox rules and leaked passwords.

cloud.png
MDR: the people who respond

Managed detection and response (MDR) is a service, not a tool. It's a 24/7 security operations center (SOC) that watches these tools and acts on what they find. Most small firms have EDR. Fewer have anything watching the identity layer after hours.

ASK YOUR PROVIDER

Three questions to ask whoever protects you today

You don't need to switch providers to get a straight answer. Ask these three questions, and ask for proof.

Screenshot_14.png
1. Who sees the alert at 2am?

A person, an automatic response, or an inbox nobody reads until Monday? An alert only helps if something acts on it.

Screenshot_15.png
2. Who is allowed to act?

Can the account be locked, sessions ended and a hostile rule disabled without waiting for you to wake up? Get the answer in writing.

cloud.png
3. What will you get on Monday?

A written record of what was accessed and what was done, plus the logs behind it. Look for 90 days of retained security logs, enough history to scope a real incident.

ALREADY COMPROMISED?

Think an account is already compromised? The first steps

Move quickly, and write down what you find. Microsoft's guide to a compromised email account covers each step.

​

1. Block sign-in for the account, or disable it for now.

2. End all of its active sessions.

3. Reset the password and set up MFA again.

4. Check inbox rules and forwarding, and note where mail was going.

5. Review recent sign-ins and sent mail.

6. Tell your IT or security provider and your cyber insurer early. 

​

For the rest of that first hour, read the first hour of a cyberattack.

people (1).png
What ITDR doesn't replace

It isn't a substitute for MFA, email filtering, endpoint protection, tested backups or a callback rule for payment changes.

BY INDUSTRY

Why this matters for your industry

Attackers use the same takeover playbook everywhere. What they do once they're inside depends on your industry.

clock.png

ITDR for law firms

Protecting client trust and trust-account wires.

right.png

Law firms

Inside an attorney's mailbox, the attacker can read privileged threads, learn how closings and settlements are paid, and send new wire instructions from the real account. One hidden inbox rule can bury the client's "did you send this?" reply until the money is gone. ITDR watches for that rule, contains the account, and gives you a plain-English record of what was read. This is general information, not legal advice.

clock.png

ITDR for wealth managers and RIAs

They don't steal the money. They ask you to send it.

right.png

Financial firms

Inside an adviser's mailbox, the attacker learns who approves wires, how requests are worded, and which threads the client already trusts. Then they send the request from that thread. There is no bad domain to catch. SPF, DKIM and DMARC all pass, because the mail is authentically yours. Reg S-P as amended requires an incident response program reasonably designed to detect, respond to, and recover from unauthorized access to customer information. A policy is not a control. ITDR gives the written program a working detection and response layer.

clock.png

ITDR for engineering and design firms

They don't forge the invoice. They wait for yours.

right.png

Engineering firms

Inside a project manager's mailbox, the attacker learns the billing cycle, who approves what, and how your pay applications are worded. Then, in a thread that has run since design development, they send updated banking details from your real account. The mailbox is also the project record: proposals, RFIs, change orders and sealed drawings. ITDR contains the account before the banking change ever gets sent, and leaves a record for the owner and your carrier.

clock.png

ITDR for defense contractors

The affirmation has a name on it.

right.png

CMMC Level 1 readiness

CMMC Level 1 asks for the 15 basic safeguarding requirements in FAR 52.204-21, a self-assessment every year, and an annual affirmation in SPRS by a senior official of your company. Three of those 15 are about identity. FCI lives in mailboxes, Teams threads and shared SharePoint folders, and an account takeover you never detect is a gap you never knew to fix. ITDR gives your self-assessment evidence instead of assumptions: a record of who signed in, from where, and what was done when a sign-in looked wrong.

TALK TO US THIS WEEK

See what's already happening in your Microsoft 365 tenant

Screenshot_14.png
Sign-in patterns

Where and how your people sign in, and anything that doesn't fit.

Screenshot_15.png
Forwarding and inbox rules

Rules that move, hide or forward mail outside your firm.

cloud.png
Apps with access to mail

Third-party apps that have been given access to your accounts.

headphones-with-mic.png
MFA gaps

Accounts where MFA is switched on but isn't really enforced.

We'll review the identity side of your Microsoft 365 environment and walk you through what we find, in plain English.

No obligation, and no rip-and-replace conversation unless you want one.

1. Who or what responds to a Microsoft 365 account takeover after hours?

​

2. What can you do to a compromised account without reaching us first?

​

3. What written record and logs do we get after an incident?

FAQ

Frequently asked questions about ITDR

What is ITDR in cybersecurity?

ITDR (identity threat detection and response) watches user accounts and sign-ins for signs of takeover, and responds by locking the account, ending its sessions or resetting the password. It protects identities the way EDR (endpoint detection and response) protects devices.

​

Does MFA stop account takeover?

It stops many attacks, but not all of them. Stolen session tokens, device-code phishing and MFA fatigue can all get past standard MFA. Keep MFA, move to phishing-resistant MFA where you can, as Microsoft and CISA advise, and add someone watching what accounts do after sign-in.

​

What is device code phishing?

An attacker starts a real Microsoft "device code" sign-in, then tricks you into typing the code on Microsoft's real sign-in page. That signs the attacker in, not you. Microsoft recommends blocking device code flow wherever possible.

​

How does a Microsoft 365 account takeover happen?

Usually a phishing link steals a password or a session token. The attacker then signs in, hides replies with inbox rules, and sends payment requests from the real mailbox.

​

What is the difference between ITDR and EDR?

EDR protects devices, and ITDR protects identities and sign-ins. You want both, because an attacker with a stolen session never has to touch your laptop.

​

What is the difference between ITDR and MDR?

ITDR is the technology that spots identity threats. MDR (managed detection and response) is the 24/7 team of people who watch those alerts and respond.

​

What should I do if my Office 365 account is compromised?

Block sign-in, end all sessions, reset the password and MFA, and check inbox rules and forwarding. Then tell your IT or security provider and your cyber insurer. Microsoft's compromised account guide has the full steps.

​

What are hidden inbox rules and why do attackers create them?

They are rules that move or delete certain emails, often replies from a bank or a client, so the real user never sees the fraud. Microsoft recommends alerting on suspicious inbox rules.

 

Do small businesses need ITDR?

If your firm runs on Microsoft 365 and moves money or sensitive client data by email, the identity layer is where these attacks start. The FBI's IC3 logged more than $3 billion in reported business email compromise losses in 2025. Ask whether anyone watches your sign-ins after hours today.

​

How fast does ITDR detect and contain an account takeover?

The ITDR platform 24uNet deploys and monitors has a published median detection time under 1 minute and average containment of 56 seconds, with 24/7 automatic response. Detection and containment figures reflect published performance of the ITDR platform 24uNet deploys and monitors; results vary by tenant configuration.

​

Does ITDR work at night and on weekends?

Yes. Containment happens automatically, at 2am on a Saturday as readily as on a Tuesday morning: sessions are revoked, hidden inbox rules disabled and sign-in blocked, without waiting for someone to pick up the phone.

​

How long does it take to add ITDR?

Under an hour. We deploy it into your Microsoft 365 tenant with no downtime, no new vendor and nothing for your staff to learn.

​

Why didn't SPF, DKIM and DMARC stop the fake wire request?

Because it came from your real mailbox, inside a real thread. Email authentication proves the mail is yours, and in a takeover it is. ITDR watches what the signed-in identity does.

​

Does Reg S-P require account takeover detection for RIAs?

Reg S-P as amended requires an incident response program "reasonably designed to detect, respond to, and recover from" unauthorized access to customer information. SEC examiners are also checking Reg S-ID programs for red flags "particularly during customer account takeovers and fraudulent transfers." ITDR is one way to back that written program with a working control. This is general information, not legal advice.

​

What does CMMC Level 1 ask for on accounts and sign-ins?

Among the 15 basic safeguarding requirements in FAR 52.204-21: limit system access to authorized users, identify those users, and verify their identities before allowing access. ITDR gives you a record of who signed in to Microsoft 365 and what was done about risky sign-ins, which you can use in your annual self-assessment before the SPRS affirmation.

​

What report do I get after an incident?

A plain-English, timestamped timeline of which accounts were used and what was touched. It's what your insurer, auditor, attorney, examiner or assessor will ask for first.

ABOUT THE AUTHOR

Dane Gray, CEH, CompTIA Security+

Cofounder, 24uNet. Dane leads 24uNet's independent security reviews, SEC exam preparation for RIAs, and CMMC Level 1 readiness work for firms in Colorado and Texas.

Dane Gray on LinkedIn

Last reviewed: October 2, 2026

bottom of page