Why identity has become the primary entry point
Attackers prefer logging in over breaking in. A valid password requires no vulnerability, no malware, and leaves almost no trace.
Credentials are sourced from phishing sites that mimic Microsoft login pages, from passwords reused on services that have suffered a breach, or from MFA fatigue, where a user eventually approves one of many push notifications just to silence their phone.
MFA raises the bar but is not a foolproof defense. Session tokens can be stolen after the login has already been approved, meaning the attacker never needs to bypass MFA again.
What ITDR actually monitors
Login patterns. Impossible travel, unknown devices, anonymization services, and activity at times that deviate from the user's normal workday.
Email rules. New forwarding rules and filters that hide replies are among the clearest signals of an ongoing compromise – and something almost no one detects manually.
Permission changes. Accounts being assigned new roles, new administrators being added, and applications being granted access to mailboxes.
MFA events. Registration of new methods, removal of existing methods, and repeated denied attempts.
Unusual data behavior. An account that begins reading or downloading data at a volume it has never done before.
There is a difference between protection and detection
The two layers are often confused.
Password and access management reduces the likelihood of credentials being stolen or reused. It is preventative.
ITDR assumes that it will happen anyway. It monitors what is done with the identity after it has been used.
You need both, and they should be implemented in that order – prevention first, because it is cheaper and eliminates a large portion of the volume.
Detection is not enough
A breach that is detected but not stopped within minutes is still a breach.
Therefore, check what the solution does automatically: terminates active sessions, blocks the account, removes the created rule. And who receives the alert when it happens outside of office hours – which is when it usually happens. That is where the SOC layer comes in.
For MSPs
Identity monitoring is one of the services that is easiest to package as a separate add-on in the agreement: the value is understandable to the customer, and the ongoing workload is low once the monitoring is in place.
Demand multi-tenancy with customer separation, and connect the alerts to your ticketing system so that they end up in the same queue as everything else.
.png)


