Cybersecurity

10 mins

Identity Threat Detection and Response (ITDR) for Microsoft 365

Last Updated
September 30, 2026

Key Takeaways

  • Identity threat detection and response (ITDR) catches attacks on user accounts and sign-ins, a gap that identity and access management (IAM) and endpoint tools leave open.
  • Password spraying tries a few common passwords across many accounts, while credential stuffing reuses username and password pairs leaked from other breaches.
  • Multifactor authentication (MFA) blocks most password attacks, but adversary-in-the-middle (AiTM) phishing and token theft can get past standard MFA.
  • Full risk detail and risk-based policies need Microsoft Entra ID P2, which comes with Microsoft 365 E5 or the Defender Suite for Business Premium, not Business Premium on its own.
  • Detection only helps if someone acts quickly, which means revoking active sessions as well as resetting the password.

Many Microsoft 365 compromises start with a working password rather than malware, so the attacker signs in looking like any other user. Identity threat detection and response (ITDR) is how security teams spot those sign-ins and shut the account down before the attacker settles in. This guide covers the main identity attacks, how Microsoft Entra detects them, what each licence shows you, and the response steps that actually lock an attacker out.

‍

What Is Identity Threat Detection and Response (ITDR)?

Identity threat detection and response (ITDR) is the practice of monitoring user accounts and sign-in activity for signs of attack, then acting on confirmed threats by blocking access, revoking sessions and resetting credentials. It covers the gap between identity management, which decides who is allowed to sign in, and endpoint security, which watches devices rather than accounts.

Microsoft describes effective ITDR as a joint job between identity administrators and security operations center (SOC) teams. Identity admins own the policies and settings that control access. The SOC investigates alerts, links identity signals to endpoint and email activity, and responds when an account is compromised.

The split matters because many attackers now sign in rather than break in. In the IBM X-Force Threat Intelligence Index 2026, stolen or misused credentials accounted for 32% of the incidents X-Force responded to in 2025. With a working password or session token, the sign-in itself looks legitimate. Only the behaviour around it gives the attacker away.

‍

ITDR vs IAM, EDR, XDR and MDR: What's the Difference?

Identity and access management (IAM) controls who can sign in. Endpoint detection and response (EDR) watches devices. Extended detection and response (XDR) connects signals across tools, and managed detection and response (MDR) is a service that runs detection for you. ITDR focuses on attacks against the identities themselves.

The five overlap, but each one leaves a gap the others cover.

What it protects What it catches What it misses Microsoft example
IAM Access rules Sign-ins that break policy, such as no MFA or a blocked location An attacker who passes the policy check, for example with a stolen session token Microsoft Entra ID, Conditional Access
EDR Devices Malware and suspicious processes Cloud sign-ins from the attacker's own device Microsoft Defender for Endpoint
ITDR Accounts and sign-ins Password spraying, token theft, risky sign-ins Attacks with no identity step, such as an exploited web app Microsoft Entra ID Protection, Microsoft Defender for Identity
XDR Signals from all of the above, correlated Multi-stage attacks that cross identity, email and devices Sources it is not connected to, and it still needs people to act Microsoft Defender XDR
MDR Not a tool, a service Whatever the provider monitors, around the clock Anything outside the agreed scope A provider running Defender XDR for you

The most common confusion is ITDR vs MDR. ITDR is a capability, the detections and response actions for identity attacks. MDR is who operates those capabilities. A good MDR service includes ITDR, but only if identity signals are in scope. For most 50 to 500 person companies, the practical answer is managed XDR across identity, email and endpoints, so an attacker cannot slip between the gaps.

‍

Credential Stuffing vs Password Spraying: How Attackers Get Into Accounts

Password spraying tries a few common passwords against many accounts, staying under the lockout threshold on each one. Credential stuffing tries real username and password pairs leaked from other breaches, betting that people reuse passwords. Both end the same way, with a successful sign-in that looks like the real user.

Neither attack needs any skill, which is why they dominate. In its Digital Defense Report 2025, Microsoft found that 97% of identity attacks were password spray attacks.

Attack How it works Why it works Main defence
Brute force Tries many passwords against one account Short or simple passwords Account lockout (Microsoft Entra smart lockout)
Password spraying Tries one or two common passwords across many accounts Low attempts per account avoid lockout, and someone always uses "Summer2026!" MFA, plus banned-password lists (Microsoft Entra Password Protection)
Credential stuffing Replays username and password pairs from other breaches Password reuse across work and personal sites MFA, plus leaked-credential detection (Microsoft Entra ID Protection)

Multifactor authentication (MFA) is the common answer to all three. The OWASP Credential Stuffing Prevention Cheat Sheet calls it by far the best defence against password-related attacks. MFA does not end the problem, though. Attackers who can't guess their way past it try to trick users into approving prompts or steal the session after sign-in, which the next section covers.

Find out what your Microsoft 365 licence actually shows you. A security assessment of your tenant's sign-in alerts and identity settings maps which attacks you can see today and which ones you can't.

‍

MFA Fatigue and Token Theft: How Attackers Get Past MFA

Attackers get past multifactor authentication (MFA) in two main ways. The first is MFA fatigue: flooding a user with approval prompts until one gets accepted. The second is adversary-in-the-middle (AiTM) phishing, where a fake login page relays the real sign-in and steals the session token after MFA is complete.

MFA fatigue is now largely a solved problem in Microsoft 365. Number matching is enabled for all Microsoft Authenticator push notifications. The user has to type the number shown on the sign-in screen, so a tired tap on "Approve" is no longer enough.

Token theft is harder to stop, because the attacker never needs the password or the MFA prompt again. Two Microsoft controls help:

  • Token Protection, a Conditional Access control, binds sign-in tokens to the registered device, so a stolen token fails from anywhere else. It covers Exchange Online, SharePoint Online and Teams in desktop and mobile apps. Browser support is limited, and AiTM phishing mostly targets browsers.
  • Continuous Access Evaluation (CAE) lets Microsoft 365 services reject a token soon after a password reset or account disable, rather than waiting for it to expire.

The strongest fix is phishing-resistant MFA, such as passkeys, which a fake login page cannot relay. Until that is everywhere, the job falls to detection and to revoking sessions fast, as in a real phishing-led Microsoft 365 account compromise.

‍

How Microsoft 365 Detects Identity Attacks (and Which Licence You Need)

Microsoft Entra ID Protection flags risky sign-ins and risky users. Microsoft Defender for Identity watches on-premises Active Directory, and Microsoft Sentinel connects those alerts with the rest of your environment. Most Entra ID Protection detections only show full detail with Microsoft Entra ID P2.

Attack Detection name in Entra ID Protection Licence needed
Password spraying Password spray Entra ID P2
Credential stuffing (leaked passwords) Leaked credentials Entra ID Free or P1
Token theft or session replay Anomalous token Entra ID P2
Adversary-in-the-middle phishing Attacker in the Middle Microsoft 365 E5 with Enterprise Mobility + Security E5
MFA fatigue or social engineering Suspicious MFA authentication approval; User reported suspicious activity Entra ID P2
Sign-in from an unusual place Unfamiliar sign-in properties; Atypical travel Entra ID P2
Mailbox takeover follow-up Suspicious inbox forwarding; Suspicious inbox manipulation rules Entra ID P2 plus Microsoft Defender for Cloud Apps, or Microsoft 365 E5 with Enterprise Mobility + Security E5

Two details change how you should read this table.

Without P2, most of these detections arrive with no detail. Tenants on Entra ID Free or P1 see a detection titled "Additional risk detected." You know something happened, but not what.

Password spray only fires after a correct guess. The detection triggers when an attacker successfully validates a user's password. Failed spray attempts generate nothing in Entra ID Protection. Catching a spray while it is still failing takes sign-in log analysis, which is what Microsoft Sentinel monitoring that catches failed spray attempts is for.

On licensing, Microsoft 365 Business Premium includes Entra ID P1, not P2. Entra ID P2 comes with Microsoft 365 E5 or the Defender Suite for Business Premium add-on. That means the typical 50 to 500 person tenant sees leaked credentials in full, and little else.

For organisations still running on-premises Active Directory, Defender for Identity covers attacks against domain controllers, such as Kerberos abuse. There is more on that in our guide to securing hybrid Active Directory identities.

‍

What to Do When a Microsoft 365 Account Is Compromised

When a Microsoft 365 account's credentials are compromised, contain the account first, then investigate. Every minute spent reading logs while the attacker still has a valid session is a minute they can use.

  1. Block sign-in. Disable the account in Microsoft Entra ID so the attacker can't start a new session.
  2. Reset the password. In a hybrid environment, Microsoft recommends resetting the on-premises password twice.
  3. Revoke all sessions. This invalidates refresh tokens so no new access tokens can be issued. Existing access tokens can stay valid for up to an hour, unless the app supports Continuous Access Evaluation.
  4. Confirm the user as compromised in Microsoft Entra ID Protection, so risk-based policies treat the account accordingly.
  5. Remove anything the attacker added. That includes MFA methods and registered devices. Have the user re-register MFA before you re-enable the account.
  6. Remove persistence. Delete malicious inbox rules and revoke OAuth app consents the attacker granted.
  7. Scope the damage. Review sign-in and audit logs to find what the attacker accessed and any other affected accounts, and block attacker IP addresses where that helps.

A password reset on its own doesn't end the attack. A stolen token or a malicious app consent can keep the attacker in, as in a BEC attack that survived a password reset. Microsoft's token theft playbook covers the investigation in detail, and the full incident response process covers what comes after containment.

‍

Real Example: Stopping a Credential Stuffing Attack in 6 Minutes

In one CyberQuell engagement, attackers made 2,400 failed sign-in attempts across three client tenants in two hours. CyberQuell's SOC responded within six minutes, and no account was compromised.

The tenants belonged to three separate small businesses, all monitored through a managed service provider (MSP) partnership. Each tenant streams its Microsoft Entra ID sign-in events into Microsoft Sentinel, with analytics run centrally. A burst of failures spread across three businesses therefore shows up as one pattern, not three small ones that each look like a user mistyping a password.

This is the gap described earlier: Entra ID Protection's password spray detection stays silent while attempts are still failing. Sign-in log analysis caught this attack before any guess succeeded. The details are in the full MSP partnership case study.

Not every burst of odd sign-ins is an attack, though. Investigating suspicious Microsoft 365 sign-ins in another case traced the alerts to network routing, and no account had been compromised.

‍

Managed ITDR: Should You Build It or Outsource It?

Identity alerts need a response within minutes, at any hour. That's why most companies with 50 to 500 employees use managed identity threat detection for the monitoring and keep ownership of identity policies and access decisions.

The staffing arithmetic explains why. A week has 168 hours, and one analyst working 40 of them covers less than a quarter. Covering every hour with even one person takes about 4.2 full-time staff, before holidays, sick leave or anyone quitting. A token stolen at 2 a.m. doesn't wait for the morning shift.

If you outsource, settle response authority first. Decide who can disable an account or revoke sessions in your tenant without calling you, and who approves out of hours. Then ask any provider four questions:

  • Which identity sources do you monitor: Entra ID sign-in logs, Entra ID Protection, Defender for Identity?
  • Can you contain an account without waiting for our approval?
  • What response time is in the contract, and when does the clock start?
  • Does our licence give you full detection detail, or only "Additional risk detected"?

CyberQuell's 24/7 managed SOC monitoring and response covers identity alongside endpoint and email, with a 15-minute response commitment. MSPs weighing platforms can see managed ITDR options for MSPs compared.

‍

Final Thoughts

For most 50 to 500 person businesses, ITDR comes down to three things.

  • Visibility into identity attacks. On Business Premium alone, most Entra ID Protection detections arrive as "Additional risk detected," and failed spray attempts don't appear at all.
  • Response in minutes, not hours. Detection only helps if someone revokes sessions and removes app consents, not just resets the password.
  • Someone on watch at 2 a.m. Without overnight coverage, the attacker has until morning.

A gap in any one of these is where your next account compromise starts.

Book a call with CyberQuell to find out what your tenant can and can't see today. Our 24/7 identity threat detection and response runs on the Microsoft 365 tools you already own, with sign-in monitoring that catches attacks your licence doesn't show.

Last Updated:
September 30, 2026

FAQs

Find answers to commonly asked questions about our cybersecurity solutions and services.

Does MFA stop password spraying?

Mostly, yes. Microsoft says multifactor authentication (MFA) blocks over 99% of password-based attacks, because a correct guess is useless without the second factor. The gap is legacy authentication: older email protocols can't perform MFA, so block them with Conditional Access, or a sprayed password still gets in.

‍

How do you detect password spraying in Microsoft Entra ID?

Microsoft Entra ID Protection has a Password spray detection, but it needs Microsoft Entra ID P2 and only fires once an attacker has correctly guessed a password. Failed attempts don't trigger it. To catch a spray while it is still failing, monitor Entra ID sign-in logs in Microsoft Sentinel for failed sign-ins spread across many accounts.

‍

Is ITDR included in Microsoft 365 E5?

Yes. Microsoft 365 E5 includes Microsoft Entra ID P2, which unlocks the full set of Entra ID Protection detections, and Microsoft Defender for Identity, which monitors on-premises Active Directory. Together they form Microsoft's ITDR capability.

‍

Can you get ITDR with Microsoft 365 Business Premium?

Partly. Business Premium includes Microsoft Entra ID P1, so most identity risk detections appear only as "Additional risk detected," with no detail. The Microsoft Defender Suite for Business Premium add-on adds Entra ID P2 and Defender for Identity for organisations of up to 300 users.

‍

What is the difference between credential stuffing and brute force?

Brute force tries many passwords against a single account until one works. Credential stuffing tries username and password pairs already leaked from other breaches, betting that people reuse passwords. Account lockout slows brute force, but it barely touches credential stuffing, because each account usually gets only one or two attempts.

‍

Protect Your Business from Cyber Threats

Get in touch with our cybersecurity experts to discuss your security needs and solutions.