Sourcepass Identity Threat Detection and Response (ITDR) for Microsoft 365
Sep 03, 2026 Mark Calzone Microsoft 365 | Cybersecurity | Email Security 4 min read
Identity has become the primary control plane for modern business operations. Email, collaboration, file sharing, and business applications all depend on trusted user accounts. As organizations continue to adopt Microsoft 365, protecting those identities has become just as important as securing endpoints and networks.
Sourcepass Identity Threat Detection and Response (ITDR) helps organizations detect and respond to malicious activity after an attacker gains access to a legitimate account. By continuously monitoring Microsoft 365 identities and user behavior, Sourcepass ITDR helps uncover compromised accounts, suspicious activity, and business email compromise (BEC) attacks that traditional security controls may miss.
What Is Identity Threat Detection and Response (ITDR)?
Identity Threat Detection and Response is a cybersecurity discipline focused on monitoring, detecting, investigating, and responding to threats targeting user identities.
Traditional security controls are highly effective at protecting the perimeter, blocking malware, and enforcing sign-in policies. However, modern attacks increasingly rely on compromised credentials, stolen session tokens, and legitimate user accounts rather than overt malware.
When attackers successfully authenticate to Microsoft 365, many security controls see a valid user performing authorized actions. ITDR helps security teams identify when those actions no longer match normal user behavior.
For organizations operating in Microsoft 365 environments, ITDR provides additional visibility into:
- Account takeover attempts
- Business email compromise attacks
- Suspicious sign-in activity
- Malicious mailbox rule creation
- Unauthorized application consent
- Insider misuse
- Privilege escalation activity
- Abnormal access to email, files, and collaboration tools
According to Microsoft's Digital Defense Report, identity-based attacks continue to grow as threat actors increasingly target user accounts rather than traditional infrastructure.
Why Identity Security Matters in Microsoft 365
Microsoft 365 provides strong security capabilities, including multifactor authentication (MFA), Conditional Access, Microsoft Defender, and Microsoft Entra ID protections.
These controls help prevent unauthorized access. However, attackers increasingly focus on techniques designed to bypass or exploit legitimate authentication.
Examples include:
- Credential phishing
- Adversary-in-the-middle attacks
- Session token theft
- OAuth application abuse
- Business email compromise
- Insider threats
Once attackers gain access to a trusted account, they can:
- Read sensitive email communications
- Download confidential files
- Create mailbox forwarding rules
- Impersonate executives or finance personnel
- Initiate fraudulent payment requests
- Access SharePoint, OneDrive, and Teams data
This is where identity threat detection becomes essential. Rather than focusing solely on authentication events, ITDR analyzes user behavior after access has been granted.
What Is Sourcepass Identity Threat Detection and Response (ITDR)?
Sourcepass Identity Threat Detection and Response (ITDR) is a managed security capability designed specifically to protect Microsoft 365 environments from identity-based threats.
By combining automated monitoring, behavioral analytics, threat detection, and security expertise, Sourcepass helps organizations identify suspicious activity associated with legitimate user accounts before significant damage occurs.
Rather than replacing Microsoft's built-in security controls, Sourcepass ITDR enhances them with an additional layer of visibility and response focused on user identity risk. This defense-in-depth approach helps organizations reduce the likelihood and impact of account compromise.
How Sourcepass ITDR Detects Identity Threats
Behavioral Analysis
One of the most effective ways to identify identity-based attacks is through behavioral analysis.
Sourcepass ITDR continuously evaluates user activity across Microsoft 365 environments to identify behavior that deviates from established patterns, helping security teams recognize threats that may otherwise appear legitimate.
Examples include:
-
Unusual account access patterns
-
Suspicious mailbox activity
-
Unexpected permission changes
-
Unauthorized application grants
-
Indicators of business email compromise
Detection of Business Email Compromise
Business email compromise remains one of the most costly forms of cybercrime.
Many BEC attacks involve legitimate user accounts rather than malware, allowing attackers to monitor conversations, impersonate employees, and manipulate financial processes while avoiding traditional security controls.
Behavior-based monitoring helps identify these threats before they result in financial loss or operational disruption.
Automated Response and Remediation
When suspicious activity is detected, response time matters.
Sourcepass ITDR includes automated response capabilities designed to contain identity threats quickly, helping organizations reduce risk and minimize the time security teams spend manually investigating incidents.
For organizations with limited internal security resources, automation improves consistency while reducing operational overhead.
Incident Investigation and Forensics
Security teams need more than alerts. They need context.
Sourcepass ITDR helps organizations understand:
- How a compromise occurred
- Which accounts were affected
- Actions performed by an attacker
- Remediation steps taken
- The overall business impact
This visibility supports security investigations, compliance initiatives, cyber insurance requirements, and executive reporting.
Common Microsoft 365 Risks Sourcepass ITDR Helps Address
Account Takeover
Account takeover occurs when attackers gain unauthorized access through phishing, password theft, token theft, or credential reuse.
Once authenticated, attackers often appear to be legitimate users.
Behavior-based monitoring helps identify abnormal post-authentication activity that may indicate compromise.
Business Email Compromise
BEC attacks frequently target:
- Executives
- Finance teams
- Human resources personnel
- Operations leaders
Identity threat detection helps identify suspicious behavior before fraudulent requests spread throughout the organization.
Malicious Mailbox Rules
Attackers commonly create hidden inbox rules that:
- Forward messages externally
- Delete security alerts
- Hide communications from victims
Because these changes often occur after successful account compromise, they can remain undetected for extended periods without visibility into user behavior.
Unauthorized Application Consent
OAuth abuse continues to grow in Microsoft 365 environments.
Attackers may trick users into granting permissions to malicious applications, providing ongoing access to organizational data without requiring password theft.
Monitoring permissions and behavioral anomalies helps reduce this risk.
How Sourcepass ITDR Fits Into a Microsoft 365 Security Strategy
No single security solution eliminates risk.
Organizations that achieve the strongest security outcomes typically combine:
- Multifactor authentication (MFA)
- Conditional Access
- Endpoint Detection and Response (EDR)
- Email security
- Security awareness training
- Backup and disaster recovery
- Identity Threat Detection and Response
Sourcepass ITDR complements these controls by providing visibility into identity-based threats occurring within Microsoft 365.
For small and mid-sized businesses, this additional layer helps bridge the gap between preventive security controls and effective incident response.
Measurable Business Value of Identity Threat Detection
The value of ITDR extends beyond technical security metrics.
Organizations benefit from:
- Faster detection of account compromise
- Reduced exposure to business email compromise
- Improved incident response efficiency
- Greater visibility into Microsoft 365 activity
- Reduced manual investigation effort
- Enhanced compliance support
- Improved cyber insurance readiness
- Increased executive confidence in identity security controls
Most importantly, ITDR helps organizations focus on meaningful risk reduction rather than simply generating more security alerts.
FAQ
What is Identity Threat Detection and Response (ITDR)?
Identity Threat Detection and Response is a cybersecurity practice focused on identifying, investigating, and responding to threats targeting user identities and authenticated accounts. ITDR helps organizations detect compromised accounts, suspicious behavior, and business email compromise activity that may occur after successful authentication.
How is ITDR different from multifactor authentication?
MFA helps prevent unauthorized access. ITDR helps identify malicious activity after authentication has already occurred. Both play important roles in a modern security strategy.
Does Microsoft 365 include identity security features?
Yes. Microsoft 365 includes identity and access management capabilities through Microsoft Entra ID, Conditional Access, MFA, and Microsoft Defender. Many organizations implement ITDR as an additional layer to improve behavioral monitoring and threat detection.
What types of threats can Sourcepass ITDR detect?
Sourcepass ITDR helps identify account takeover attempts, business email compromise, suspicious sign-ins, mailbox manipulation, unauthorized permissions, abnormal user behavior, and other identity-based threats within Microsoft 365 environments.
Is ITDR only for large enterprises?
No. Organizations of all sizes face identity-based attacks. ITDR is particularly valuable for small and mid-sized businesses that want enterprise-grade visibility and response capabilities without building a large internal security team.
Can ITDR replace Microsoft Defender?
No. ITDR is designed to complement Microsoft's security ecosystem. The strongest security posture combines preventive controls, threat detection, response capabilities, security awareness training, and ongoing monitoring.
Why is business email compromise difficult to detect?
Business email compromise often involves legitimate user accounts rather than malware. Since attackers operate using trusted identities, their actions can appear normal unless security tools continuously monitor user behavior and account activity.
Subscribe To
Sourcepass Insights
Sourcepass Insights
Stay in the loop and never miss out on the latest updates by subscribing to our newsletter today!