Detect and respond

Identity threat detection (ITDR)

Attackers increasingly log in rather than break in. Find risky settings, leaked passwords and suspicious sign-ins before an attacker can use them.

The risk

Why break in when you can log in? Stolen passwords, phished sign-in codes and misconfigured Microsoft 365 settings give attackers access that looks like a normal user.

Sophos's incident responders report that the large majority of Microsoft Entra ID environments they examine have critical misconfigurations.

What it does
  • More than 160 automatic checks of your Microsoft Entra ID set-up for risky settings and gaps
  • Watches dark web marketplaces and breach data for your staff's leaked credentials, with a closer eye on key accounts
  • Spots suspicious sign-ins and account behaviour that suggest stolen credentials
  • Plain-English explanations of each detection, set against the user's normal behaviour
  • Responds by forcing a password reset, locking the account or signing out active sessions
  • Covers Microsoft Entra ID, Microsoft 365 and on-premises Active Directory
Who it's for

Any business that runs on Microsoft 365, which is most of them. It's especially worth having if you've never had your Microsoft 365 settings reviewed.

How we supply it

By default we supply the licence and you (or your IT provider) deploy it. If you'd rather hand the whole job to us, we can configure and install it for you at our standard day rate — scoped and agreed with you up front, and invoiced separately.

What's under the hood

Sophos ITDR — works with Sophos XDR and Sophos MDR. With MDR, identity detections go straight to the 24/7 analyst team.

Questions
MFA is essential, but it isn't the end of it. Attackers now steal sign-in sessions and trick people into approving prompts, and misconfigured settings can leave gaps MFA doesn't cover.
Watching criminal marketplaces and leaked data for your staff's usernames and passwords, so you can change them before they're used.
It points out risky settings and how to fix them; you decide what to change. Responses such as locking an account are there for when a threat is found.

Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

Talk to us → or see every security area →