Huntress Managed ITDR
Stop Microsoft 365 account takeover in its tracks
Huntress Managed ITDR watches every Microsoft 365 sign-in, around the clock, for stolen sessions, MFA bypass and the inbox rules attackers set up to hide. When it finds one, the account is shut down.
Book Your Free Security Gap CheckMost attacks on small businesses now go after the login, not the laptop. Attackers phish a password, or steal a signed-in session to get around multi-factor authentication, then sit quietly in a mailbox. They set up rules to hide replies, and wait for the right invoice to redirect.
Identity threat detection and response (ITDR) watches for exactly that. Huntress Managed ITDR monitors your Microsoft 365 sign-ins and mailbox activity for signs of account takeover. When the Huntress SOC confirms one, it can disable the account and end its sessions within minutes, not after the money has gone.
DJC deploys and manages it, and handles the follow-up: resetting credentials, removing malicious rules and checking what the attacker touched. It is included in every managed cyber security tier and works hand in hand with Huntress Managed EDR.
What Huntress Managed ITDR watches for
Account takeover
Sign-ins from unusual locations, suspicious VPNs and hosting providers, and logins that do not match how the user normally works.
Session theft and MFA bypass
Stolen sign-in tokens that let attackers get around multi-factor authentication without ever knowing the code.
Rogue inbox rules
The forwarding and hiding rules attackers set up to intercept invoices and conceal their activity.
24/7 response
The Huntress SOC can disable a compromised account and revoke its sessions at any hour.
Clean-up by DJC
We reset credentials, remove malicious rules, check what was accessed and tell you in plain English what happened.
If IT is your responsibility
An owner, not an account manager
You deal with Daniel or Julian Church directly. We keep the client list deliberately short so the people who answer already know your environment.
Numbers you can defend
Every engagement starts with a costed IT roadmap: what technology should cost this year and next, in business terms you can take to a board or a budget meeting.
See what managed IT typically costsWorking alongside internal IT
If you already have an IT manager or a small team, we are not here to replace them. Co-managed IT adds tooling, escalation and after-hours cover around them.
How co-managed IT worksWhy DJC
- Built for how businesses actually get hit. Business email compromise and invoice fraud start with a hijacked Microsoft 365 account. ITDR is aimed squarely at that.
- Response, not just an alert. The Huntress SOC contains the account and DJC does the remediation, so nothing is left sitting in an inbox.
- Certified to the standard we advise on. DJC holds SMB1001 Diamond, ISO 27001 and ISO 9001 certification.
Included in every managed cyber tier
Take it on its own, or get it included in any of our managed cyber tiers, together with the rest of the security stack and a quarterly review with a person.
Quick answers
What is ITDR?
Identity Threat Detection and Response (ITDR) monitors user identities, in this case Microsoft 365 accounts, for signs of compromise such as suspicious sign-ins, stolen sessions and malicious mailbox rules, and responds by containing the account.
We already have MFA. Do we need ITDR?
MFA stops most password attacks, but attackers now routinely get around it by stealing a signed-in session token through a phishing page. ITDR detects the use of that stolen session, which MFA alone cannot.
What happens when Huntress detects a compromised account?
The Huntress SOC confirms the threat and can disable the account and revoke its active sessions. DJC then resets credentials, removes any malicious inbox rules and reviews what the attacker accessed.
Is Huntress ITDR included in DJC's managed cyber security?
Yes. Huntress ITDR is included in every managed cyber security tier, from Bronze up, and can also be taken on its own, priced per user.