Full Report
An update on our MDR for Microsoft 365 product, some recent improvements, and what fixes and features are coming soon.
Analysis Summary
# Industry News: Huntress Doubles Down on Identity Threat Detection (ITDR) for Microsoft 365
## Summary
Huntress has released a comprehensive update on its Managed Detection and Response (MDR) for Microsoft 365, now categorized as Managed Identity Threat Detection and Response (ITDR). The announcement highlights significant scale—onboarding hundreds of thousands of identities—while providing a transparent look at product refinements aimed at combating sophisticated Business Email Compromise (BEC).
## Key Details
- **Date:** December 6, 2023
- **Companies Involved:** Huntress, Microsoft (Ecosystem Partner)
- **Category:** Product Update / Managed Security Services
## The Story
Following the initial launch of its Microsoft 365 security product, Huntress is pivoting to a "ruthless transparency" model regarding its progress in the identity security space. The core of the update focuses on three primary defensive capabilities: **Unwanted Logins**, **Shadow Workflows** (inbox rule manipulation), and **Malicious Applications** (OAuth abuse).
Huntress CEO Kyle Hanslovan acknowledged the limitations of traditional geofencing, noting that attackers are increasingly using token theft and faux-device registration to bypass location-based alerts. To counter this, Huntress is shifting toward behavioral analysis and "Impossible Travel" algorithms. The update also emphasizes the transition from reactive detection to proactive hygiene through Managed Identity Security Posture Management (ISPM), which aims to harden Microsoft 365 environments before an initial compromise occurs.
## Business Impact
### For the Companies Involved (Huntress)
- **Market Trust:** By openly discussing "what they got wrong" and technical missteps, Huntress strengthens its brand equity with Managed Service Providers (MSPs) who value transparency.
- **Product Expansion:** Validates Huntress’ evolution from an endpoint-centric company to an identity-centric security provider.
### For Competitors
- **Pressure on Transparency:** Huntress’ "no-BS" communication style sets a high bar for competitor communications in the MDR/ITDR space.
- **SMB Dominance:** Competitors targeting the SMB/MSP space must now contend with a more integrated Huntress stack that combines detection with posture management.
### For Customers (MSPs and SMBs)
- **Reduced Risk:** Access to 24/7 human-backed monitoring for M365 helps mitigate the high financial impact of BEC.
- **Operational Efficiency:** Managed ISPM helps small teams prioritize which security settings to fix first without needing deep Microsoft licensing expertise.
### For the Market
- **Shift to ITDR:** This reinforces the industry trend moving away from simple EDR (Endpoint) toward ITDR (Identity), recognizing that the identity is the new perimeter.
## Technical Implications
- **Beyond Geofencing:** The technical shift focuses on Autonomous System (AS) monitoring rather than just IP location, identifying logins originating from data centers known for malicious activity.
- **Remediation Automation:** Huntress is leaning into "Identity Isolation" to automatically lock out compromised accounts based on high-fidelity alerts.
## Strategic Analysis
- **Market Positioning:** Huntress is positioning itself as the "essential layer" for Microsoft 365, specifically for organizations that cannot afford or manage the complexity of Microsoft’s high-end E5 security suite.
- **Competitive Advantage:** The integration of human SOC analysts who verify alerts before notifying the customer reduces "alert fatigue," a major pain point for MSPs.
- **Challenges:** Sophisticated attackers are moving toward "living off the land" in the cloud; staying ahead of OAuth and token-based attacks requires constant R&D investment.
## Industry Reactions
- **Analyst View:** The shift toward Managed ITDR is seen as a necessary evolution as identity-based attacks now account for a significant portion of SMB breaches.
- **Market Response:** The onboarding of "hundreds of thousands of identities" suggests strong market fit and rapid adoption among Huntress’ existing partner base.
## Future Outlook
- **Predictions:** Expect Huntress to further integrate AI-driven behavioral baselining to detect "impossible travel" more accurately.
- **Watch For:** Further updates on automated remediation—moving from simple "alerts" to fully autonomous "active defense" within the M365 tenant.
## For Security Professionals
Practitioners should note the emphasis on **Shadow Workflows**. Attackers are increasingly using quiet inbox rules to redirect financial communications. Security pros should audit their M365 environments for legacy rules and ensure that MFA is not just "enabled" but protected against modern session-token theft.