
IDENTITY THREAT DETECTION AND RESPONSE
Would Your Setup Catch a Microsoft 365 Account Takeover at 2am on a Saturday?
The fastest-growing attack against businesses your size doesn't involve malware, and it doesn't trip your antivirus.
​
Someone signs in to a partner's Microsoft 365 mailbox using a stolen session. They quietly add an inbox rule that hides replies from the bank, then draft a "new wiring instructions" email to a client. Nobody is back at a desk until Monday.
​
This page explains identity threat detection and response (ITDR), why MFA alone doesn't stop this attack, and what to ask whoever protects you today.
THE SHORT VERSION
ITDR (identity threat detection and response) watches what user accounts do after they sign in: risky sign-ins, stolen sessions, new inbox rules and exposed passwords. When behavior turns hostile, it contains the account, for example by revoking sessions and disabling hostile inbox rules. It works alongside multi-factor authentication (MFA) and endpoint protection. It doesn't replace them.
THE OWNER'S VERSION
They don't break in anymore. They just log in.
ITDR watches the one thing your other tools don't: what an identity actually does after it signs in.
MFA is not a wall
Adversary-in-the-middle kits steal the session token after a legitimate MFA prompt. The login looks perfectly valid, because it is.
Email filters don't watch sessions
Email filters read messages. Once an attacker is inside the account, every message they send comes from your real mailbox, in a real thread. There's nothing for a filter to catch.
By then, money is gone
Hidden inbox rules bury the replies. In 2025 the FBI's IC3 logged more than $3 billion in reported business email compromise (BEC) losses, the second-largest category after investment fraud. That's about $123,000 per complaint, by our math from IC3. Source: FBI IC3 2025 report
WHAT IS ITDR
What is ITDR (identity threat detection and response)?
ITDR is security for your logins. It watches Microsoft 365 accounts for signs that someone other than the real user is in control, and it acts when they are.
Detect
Spots unusual sign-ins, risky behavior and passwords that have leaked online. It reads what the account does, not just whether the password was right.
Investigate
Checks whether it's really your employee. A new laptop on a business trip looks different from a stranger reading the CFO's inbox.
Respond
Contains the account: sessions revoked, hidden inbox rules disabled, sign-in blocked and the password reset.
WHAT YOU GET
Detection, containment and answers you can hand over
Behavioral detection
Reads behavior, not just the password. Flags stolen credentials, session abuse, password spray and impossible travel, and alerts when your people's passwords turn up in breach data.
Automatic containment
Ends the attacker's sessions, disables hidden inbox rules, blocks sign-in and forces a password and MFA reset before anyone reaches for the phone.
Answers you can hand over
A plain-English timeline of exactly what was touched: the report your insurer, your auditor and your attorney will ask for on day one.
No new vendor, no project, no downtime. We deploy it into your Microsoft 365 tenant in under an hour and monitor it alongside everything else we watch for you.
WHY MFA ISN'T ENOUGH
Why MFA alone doesn't stop a Microsoft 365 account takeover
Device-code phishing
The attacker starts a real Microsoft sign-in meant for TVs and printers, then emails you the code with a lure like "Action Required: Password Expiration." You type it on Microsoft's real page, and that signs them in. Microsoft says the EvilTokens campaign "compromised more than 12,000 inboxes in over 10,000 organizations worldwide." Source: Microsoft, September 2026
MFA fatigue and leaked passwords
Some attackers send push prompt after push prompt until someone taps "approve." Others use passwords reused from old breaches.
What actually closes the gap
Phishing-resistant MFA such as passkeys or security keys, which Microsoft and CISA both recommend. Blocking device code flow where you don't need it. And something watching what accounts do after sign-in. That last part is ITDR.
Keep MFA. Microsoft calls it "an essential pillar in identity security" that is "highly effective at stopping a variety of threats." But attackers have learned to work around it.
ILLUSTRATIVE TIMELINE
The 2am Saturday takeover, step by step
00:00 Signed in
The attacker signs in with a stolen session token. MFA never prompts.
00:34 Flagged
Behavior flagged: an unusual sign-in, and a new mailbox rule created.
00:56 Contained
Sessions revoked, rule disabled, account contained automatically.
Same day: the report
You get a plain-English report of everything that was touched.
Detection and containment figures reflect published performance of the ITDR platform 24uNet deploys and monitors; results vary by tenant configuration. Attack timeline is illustrative.
HOW 24UNET DELIVERS IT
How 24uNet delivers ITDR
<1 min
Median detection time.
56 sec
Average containment.
24/7
Autonomous response, day or night.
<1 hr
To deploy, with no downtime.
ITDR VS EDR VS MDR
ITDR vs EDR vs MDR: what's the difference?
EDR: protects devices
Watches laptops and servers. It catches things like malware or ransomware running on a machine.
ITDR: protects identities
Watches Microsoft 365 and Entra ID sign-ins. It catches stolen sessions, risky sign-ins, hostile inbox rules and leaked passwords.
MDR: the people who respond
Managed detection and response (MDR) is a service, not a tool. It's a 24/7 security operations center (SOC) that watches these tools and acts on what they find. Most small firms have EDR. Fewer have anything watching the identity layer after hours.
ASK YOUR PROVIDER
Three questions to ask whoever protects you today
You don't need to switch providers to get a straight answer. Ask these three questions, and ask for proof.
1. Who sees the alert at 2am?
A person, an automatic response, or an inbox nobody reads until Monday? An alert only helps if something acts on it.
2. Who is allowed to act?
Can the account be locked, sessions ended and a hostile rule disabled without waiting for you to wake up? Get the answer in writing.
3. What will you get on Monday?
A written record of what was accessed and what was done, plus the logs behind it. Look for 90 days of retained security logs, enough history to scope a real incident.

ALREADY COMPROMISED?
Think an account is already compromised? The first steps
Move quickly, and write down what you find. Microsoft's guide to a compromised email account covers each step.
​
1. Block sign-in for the account, or disable it for now.
2. End all of its active sessions.
3. Reset the password and set up MFA again.
4. Check inbox rules and forwarding, and note where mail was going.
5. Review recent sign-ins and sent mail.
6. Tell your IT or security provider and your cyber insurer early.
​
For the rest of that first hour, read the first hour of a cyberattack.
BY INDUSTRY
Why this matters for your industry
Attackers use the same takeover playbook everywhere. What they do once they're inside depends on your industry.
ITDR for law firms
Protecting client trust and trust-account wires.
Law firms
Inside an attorney's mailbox, the attacker can read privileged threads, learn how closings and settlements are paid, and send new wire instructions from the real account. One hidden inbox rule can bury the client's "did you send this?" reply until the money is gone. ITDR watches for that rule, contains the account, and gives you a plain-English record of what was read. This is general information, not legal advice.
ITDR for wealth managers and RIAs
They don't steal the money. They ask you to send it.
Financial firms
Inside an adviser's mailbox, the attacker learns who approves wires, how requests are worded, and which threads the client already trusts. Then they send the request from that thread. There is no bad domain to catch. SPF, DKIM and DMARC all pass, because the mail is authentically yours. Reg S-P as amended requires an incident response program reasonably designed to detect, respond to, and recover from unauthorized access to customer information. A policy is not a control. ITDR gives the written program a working detection and response layer.
ITDR for engineering and design firms
They don't forge the invoice. They wait for yours.
Engineering firms
Inside a project manager's mailbox, the attacker learns the billing cycle, who approves what, and how your pay applications are worded. Then, in a thread that has run since design development, they send updated banking details from your real account. The mailbox is also the project record: proposals, RFIs, change orders and sealed drawings. ITDR contains the account before the banking change ever gets sent, and leaves a record for the owner and your carrier.
ITDR for defense contractors
The affirmation has a name on it.
CMMC Level 1 readiness
CMMC Level 1 asks for the 15 basic safeguarding requirements in FAR 52.204-21, a self-assessment every year, and an annual affirmation in SPRS by a senior official of your company. Three of those 15 are about identity. FCI lives in mailboxes, Teams threads and shared SharePoint folders, and an account takeover you never detect is a gap you never knew to fix. ITDR gives your self-assessment evidence instead of assumptions: a record of who signed in, from where, and what was done when a sign-in looked wrong.
TALK TO US THIS WEEK
See what's already happening in your Microsoft 365 tenant
Sign-in patterns
Where and how your people sign in, and anything that doesn't fit.
Forwarding and inbox rules
Rules that move, hide or forward mail outside your firm.
Apps with access to mail
Third-party apps that have been given access to your accounts.
MFA gaps
Accounts where MFA is switched on but isn't really enforced.
We'll review the identity side of your Microsoft 365 environment and walk you through what we find, in plain English.
No obligation, and no rip-and-replace conversation unless you want one.
FAQ
Frequently asked questions about ITDR
What is ITDR in cybersecurity?
ITDR (identity threat detection and response) watches user accounts and sign-ins for signs of takeover, and responds by locking the account, ending its sessions or resetting the password. It protects identities the way EDR (endpoint detection and response) protects devices.
​
Does MFA stop account takeover?
It stops many attacks, but not all of them. Stolen session tokens, device-code phishing and MFA fatigue can all get past standard MFA. Keep MFA, move to phishing-resistant MFA where you can, as Microsoft and CISA advise, and add someone watching what accounts do after sign-in.
​
What is device code phishing?
An attacker starts a real Microsoft "device code" sign-in, then tricks you into typing the code on Microsoft's real sign-in page. That signs the attacker in, not you. Microsoft recommends blocking device code flow wherever possible.
​
How does a Microsoft 365 account takeover happen?
Usually a phishing link steals a password or a session token. The attacker then signs in, hides replies with inbox rules, and sends payment requests from the real mailbox.
​
What is the difference between ITDR and EDR?
EDR protects devices, and ITDR protects identities and sign-ins. You want both, because an attacker with a stolen session never has to touch your laptop.
​
What is the difference between ITDR and MDR?
ITDR is the technology that spots identity threats. MDR (managed detection and response) is the 24/7 team of people who watch those alerts and respond.
​
What should I do if my Office 365 account is compromised?
Block sign-in, end all sessions, reset the password and MFA, and check inbox rules and forwarding. Then tell your IT or security provider and your cyber insurer. Microsoft's compromised account guide has the full steps.
​
What are hidden inbox rules and why do attackers create them?
They are rules that move or delete certain emails, often replies from a bank or a client, so the real user never sees the fraud. Microsoft recommends alerting on suspicious inbox rules.
Do small businesses need ITDR?
If your firm runs on Microsoft 365 and moves money or sensitive client data by email, the identity layer is where these attacks start. The FBI's IC3 logged more than $3 billion in reported business email compromise losses in 2025. Ask whether anyone watches your sign-ins after hours today.
​
How fast does ITDR detect and contain an account takeover?
The ITDR platform 24uNet deploys and monitors has a published median detection time under 1 minute and average containment of 56 seconds, with 24/7 automatic response. Detection and containment figures reflect published performance of the ITDR platform 24uNet deploys and monitors; results vary by tenant configuration.
​
Does ITDR work at night and on weekends?
Yes. Containment happens automatically, at 2am on a Saturday as readily as on a Tuesday morning: sessions are revoked, hidden inbox rules disabled and sign-in blocked, without waiting for someone to pick up the phone.
​
How long does it take to add ITDR?
Under an hour. We deploy it into your Microsoft 365 tenant with no downtime, no new vendor and nothing for your staff to learn.
​
Why didn't SPF, DKIM and DMARC stop the fake wire request?
Because it came from your real mailbox, inside a real thread. Email authentication proves the mail is yours, and in a takeover it is. ITDR watches what the signed-in identity does.
​
Does Reg S-P require account takeover detection for RIAs?
Reg S-P as amended requires an incident response program "reasonably designed to detect, respond to, and recover from" unauthorized access to customer information. SEC examiners are also checking Reg S-ID programs for red flags "particularly during customer account takeovers and fraudulent transfers." ITDR is one way to back that written program with a working control. This is general information, not legal advice.
​
What does CMMC Level 1 ask for on accounts and sign-ins?
Among the 15 basic safeguarding requirements in FAR 52.204-21: limit system access to authorized users, identify those users, and verify their identities before allowing access. ITDR gives you a record of who signed in to Microsoft 365 and what was done about risky sign-ins, which you can use in your annual self-assessment before the SPRS affirmation.
​
What report do I get after an incident?
A plain-English, timestamped timeline of which accounts were used and what was touched. It's what your insurer, auditor, attorney, examiner or assessor will ask for first.

ABOUT THE AUTHOR
Dane Gray, CEH, CompTIA Security+
Cofounder, 24uNet. Dane leads 24uNet's independent security reviews, SEC exam preparation for RIAs, and CMMC Level 1 readiness work for firms in Colorado and Texas.
Last reviewed: October 2, 2026
