---
title: 'Identity threat detection (ITDR)'
url: 'https://triplepoint.org.uk/security/detect-and-respond/identity-protection'
markdown: 'https://triplepoint.org.uk/security/detect-and-respond/identity-protection.md'
date: '2026-09-28'
description: 'Identity threat detection and response (ITDR) for UK businesses. Spot stolen credentials, risky Microsoft 365 settings and suspicious sign-ins before an attacker can use them.'
---

# Identity threat detection (ITDR)

The riskWhy break in when you can log in? Stolen passwords, phished sign-in codes and misconfigured Microsoft 365 settings give attackers access that looks like a normal user.

Sophos's incident responders report that the large majority of Microsoft Entra ID environments they examine have critical misconfigurations.

 What it does- More than 160 automatic checks of your Microsoft Entra ID set-up for risky settings and gaps
- Watches dark web marketplaces and breach data for your staff's leaked credentials, with a closer eye on key accounts
- Spots suspicious sign-ins and account behaviour that suggest stolen credentials
- Plain-English explanations of each detection, set against the user's normal behaviour
- Responds by forcing a password reset, locking the account or signing out active sessions
- Covers Microsoft Entra ID, Microsoft 365 and on-premises Active Directory

 Who it's forAny business that runs on Microsoft 365, which is most of them. It's especially worth having if you've never had your Microsoft 365 settings reviewed.

 How we supply itBy default we supply the licence and you (or your IT provider) deploy it. If you'd rather hand the whole job to us, we can configure and install it for you at our standard day rate — scoped and agreed with you up front, and invoiced separately.

 What's under the hood**Sophos ITDR** — works with Sophos XDR and Sophos MDR. With MDR, identity detections go straight to the 24/7 analyst team.

 Questions We have multi-factor authentication. Aren't we covered?+MFA is essential, but it isn't the end of it. Attackers now steal sign-in sessions and trick people into approving prompts, and misconfigured settings can leave gaps MFA doesn't cover.

 What is dark web monitoring?+Watching criminal marketplaces and leaked data for your staff's usernames and passwords, so you can change them before they're used.

 Does it change our Microsoft 365 settings?+It points out risky settings and how to fix them; you decide what to change. Responses such as locking an account are there for when a threat is found.

[← Back to Detect and respond](https://triplepoint.org.uk/security/detect-and-respond)

## Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

[Talk to us →](https://triplepoint.org.uk/contact?about=Identity%20threat%20detection%20%28ITDR%29) or [see every security area →](https://triplepoint.org.uk/security)

---

## Navigation

- Parent: [Threat detection and response](https://triplepoint.org.uk/security/detect-and-respond.md)
- Previous: [Network detection & response (NDR)](https://triplepoint.org.uk/security/detect-and-respond/network-detection.md)
