Se alla lösningsområden

ITDR – identity protection and account takeovers

Why stolen credentials go unnoticed by endpoint protection, what ITDR monitors, and the signals that reveal a compromise.

Why identity has become the primary entry point

Attackers prefer logging in over breaking in. A valid password requires no vulnerability, no malware, and leaves almost no trace.

Credentials are sourced from phishing sites that mimic Microsoft login pages, from passwords reused on services that have suffered a breach, or from MFA fatigue, where a user eventually approves one of many push notifications just to silence their phone.

MFA raises the bar but is not a foolproof defense. Session tokens can be stolen after the login has already been approved, meaning the attacker never needs to bypass MFA again.

What ITDR actually monitors

Login patterns. Impossible travel, unknown devices, anonymization services, and activity at times that deviate from the user's normal workday.

Email rules. New forwarding rules and filters that hide replies are among the clearest signals of an ongoing compromise – and something almost no one detects manually.

Permission changes. Accounts being assigned new roles, new administrators being added, and applications being granted access to mailboxes.

MFA events. Registration of new methods, removal of existing methods, and repeated denied attempts.

Unusual data behavior. An account that begins reading or downloading data at a volume it has never done before.

There is a difference between protection and detection

The two layers are often confused.

Password and access management reduces the likelihood of credentials being stolen or reused. It is preventative.

ITDR assumes that it will happen anyway. It monitors what is done with the identity after it has been used.

You need both, and they should be implemented in that order – prevention first, because it is cheaper and eliminates a large portion of the volume.

Detection is not enough

A breach that is detected but not stopped within minutes is still a breach.

Therefore, check what the solution does automatically: terminates active sessions, blocks the account, removes the created rule. And who receives the alert when it happens outside of office hours – which is when it usually happens. That is where the SOC layer comes in.

For MSPs

Identity monitoring is one of the services that is easiest to package as a separate add-on in the agreement: the value is understandable to the customer, and the ongoing workload is low once the monitoring is in place.

Demand multi-tenancy with customer separation, and connect the alerts to your ticketing system so that they end up in the same queue as everything else.

A stolen password looks legitimate. ITDR monitors identities and detects the takeover. We help you put this layer in place.

Frequently asked questions about ITDR

What does ITDR stand for?
Identity Threat Detection and Response. Protection that monitors identities and accounts instead of devices.

Isn't MFA enough?
MFA raises the bar, but it doesn't stop session hijacking or MFA fatigue, where a user approves a push notification just to silence their phone.

Why doesn't our endpoint protection detect an account takeover?
Because there is nothing on the device to see. The attacker logs into the cloud with valid credentials and never touches a computer.

What is the clearest sign of a takeover?
A new email forwarding or filter rule, often combined with a login from an unknown location. That combination is rarely innocent.

How is this different from a password manager?
A password manager reduces the risk of credentials being stolen. ITDR detects when they are used by the wrong person anyway.

Can the account be blocked automatically?
Yes, and it should be. Specifically ask if the solution can terminate active sessions – just changing the password isn't enough if the attacker already has a valid session.

Does it work for Google Workspace?
Support varies between platforms. Most solutions are strongest on Microsoft 365 and Entra ID – check the coverage against your environment.

Produkter inom området

Nordlo

Nordlo builds scalable IT delivery with MSP Nordics

37% more efficient service management through standardised processes and automation
Läs mer
Läs mer
With the right platform and clear processes, we can scale our delivery without increasing administration at the same rate.
Nordlo

Want to hear more?

We are happy to tell you more about how we have adapted and tailored long-term solutions for our customers.