Huntress Managed ITDR

Stop Microsoft 365 account takeover in its tracks

Huntress Managed ITDR watches every Microsoft 365 sign-in, around the clock, for stolen sessions, MFA bypass and the inbox rules attackers set up to hide. When it finds one, the account is shut down.

Book Your Free Security Gap Check

Most attacks on small businesses now go after the login, not the laptop. Attackers phish a password, or steal a signed-in session to get around multi-factor authentication, then sit quietly in a mailbox. They set up rules to hide replies, and wait for the right invoice to redirect.

Identity threat detection and response (ITDR) watches for exactly that. Huntress Managed ITDR monitors your Microsoft 365 sign-ins and mailbox activity for signs of account takeover. When the Huntress SOC confirms one, it can disable the account and end its sessions within minutes, not after the money has gone.

DJC deploys and manages it, and handles the follow-up: resetting credentials, removing malicious rules and checking what the attacker touched. It is included in every managed cyber security tier and works hand in hand with Huntress Managed EDR.

What Huntress Managed ITDR watches for

Account takeover

Sign-ins from unusual locations, suspicious VPNs and hosting providers, and logins that do not match how the user normally works.

Session theft and MFA bypass

Stolen sign-in tokens that let attackers get around multi-factor authentication without ever knowing the code.

Rogue inbox rules

The forwarding and hiding rules attackers set up to intercept invoices and conceal their activity.

24/7 response

The Huntress SOC can disable a compromised account and revoke its sessions at any hour.

Clean-up by DJC

We reset credentials, remove malicious rules, check what was accessed and tell you in plain English what happened.

If IT is your responsibility

An owner, not an account manager

You deal with Daniel or Julian Church directly. We keep the client list deliberately short so the people who answer already know your environment.

Numbers you can defend

Every engagement starts with a costed IT roadmap: what technology should cost this year and next, in business terms you can take to a board or a budget meeting.

See what managed IT typically costs

Working alongside internal IT

If you already have an IT manager or a small team, we are not here to replace them. Co-managed IT adds tooling, escalation and after-hours cover around them.

How co-managed IT works

Why DJC

  • Built for how businesses actually get hit. Business email compromise and invoice fraud start with a hijacked Microsoft 365 account. ITDR is aimed squarely at that.
  • Response, not just an alert. The Huntress SOC contains the account and DJC does the remediation, so nothing is left sitting in an inbox.
  • Certified to the standard we advise on. DJC holds SMB1001 Diamond, ISO 27001 and ISO 9001 certification.
Book Your Free Security Gap Check

Quick answers

What is ITDR?

Identity Threat Detection and Response (ITDR) monitors user identities, in this case Microsoft 365 accounts, for signs of compromise such as suspicious sign-ins, stolen sessions and malicious mailbox rules, and responds by containing the account.

We already have MFA. Do we need ITDR?

MFA stops most password attacks, but attackers now routinely get around it by stealing a signed-in session token through a phishing page. ITDR detects the use of that stolen session, which MFA alone cannot.

What happens when Huntress detects a compromised account?

The Huntress SOC confirms the threat and can disable the account and revoke its active sessions. DJC then resets credentials, removes any malicious inbox rules and reviews what the attacker accessed.

Is Huntress ITDR included in DJC's managed cyber security?

Yes. Huntress ITDR is included in every managed cyber security tier, from Bronze up, and can also be taken on its own, priced per user.