Full Report
Huntress now delivers ITDR for Google Workspace to protect identities against BEC, inbox rule manipulation, and account takeover, all with a 24/7 SOC-led response.
Analysis Summary
# Industry News: Huntress Expands Identity Protection to Google Workspace
## Summary
Huntress has announced the launch of Managed Identity Threat Detection and Response (ITDR) for Google Workspace, extending its SOC-led security coverage to one of the world’s most critical identity infrastructures. This move aims to protect organizations against sophisticated identity-based attacks like Business Email Compromise (BEC), inbox manipulation, and session hijacking by providing 24/7 monitoring and human-led response.
## Key Details
- **Date:** March 24, 2026
- **Companies Involved:** Huntress
- **Category:** Product Launch / Service Expansion
## The Story
Recognizing that 79% of its critical incident reports in 2025 were identity-related rather than malware-based, Huntress is shifting its strategic focus further toward "Identity as the Perimeter." While the company previously offered ITDR for Microsoft 365 and Active Directory, this expansion covers the growing Google Workspace (GWS) ecosystem, which many small-to-midmarket organizations (SMBs) and MSPs use as their primary identity provider.
The service addresses the "visibility gap" where traditional endpoint security fails to see post-authentication malicious activity. Huntress’ 24/7 Security Operations Center (SOC) will now monitor GWS for signs of account takeover, unauthorized OAuth permissions, and malicious "Rogue Apps," offering a mean time to respond (MTTR) of just three minutes.
## Business Impact
### For the Companies Involved
- **Huntress:** Solidifies its transition from a pure-play Endpoint Detection and Response (EDR) provider to a comprehensive Managed Detection and Response (MDR) powerhouse that secures both the device and the identity.
### For Competitors
- **Competitive Landscape:** Increases pressure on traditional MDR and EDR vendors who lack deep SaaS-native identity monitoring. Huntress is positioning its human-led SOC as a differentiator against automated-only identity tools.
### For Customers
- **Impact on End Users:** SMBs and MSPs using Google Workspace now have access to enterprise-grade identity security that was previously difficult to manage without a large, dedicated internal security team.
### For the Market
- **Broader Market Implications:** Signals a definitive industry shift where identity security is no longer an "add-on" but a core requirement of a modern security stack.
## Technical Implications
The solution focuses on **Post-Authentication Monitoring**. Since attackers are increasingly "logging in" rather than "breaking in" (via session hijacking and token theft), the technical innovation lies in correlating Google Workspace logs with endpoint telemetry to identify anomalies that MFA might miss.
## Strategic Analysis
- **Market Positioning:** Huntress is positioning itself as the "SOC for the 99%," targeting the mid-market that is heavily reliant on SaaS tools like Google Workspace.
- **Competitive Advantage:** The integration of ITDR with their existing EDR platform creates a "unified" response, allowing the SOC to disable a compromised cloud identity and isolate the physical endpoint simultaneously.
- **Challenges:** Managing the sheer volume of Google API logs and maintaining a low false-positive rate (currently cited at <5%) across diverse GWS configurations will be a continuous operational challenge.
## Industry Reactions
- **Analyst Opinion:** Market analysts note that Huntress is successfully following the threat actors; as attackers pivot from ransomware to BEC and SaaS-based extortion, Huntress is moving its defense capabilities to match.
- **Market Response:** The expansion is expected to be highly welcomed by the MSP community, which has historically found Google Workspace security harder to monetize and manage compared to the Microsoft ecosystem.
## Future Outlook
- **Predictions:** Expect Huntress to continue expanding into other high-value SaaS targets (e.g., Salesforce, Slack) as "Identity Sprawl" continues.
- **What to watch for:** Increased consolidation of EDR and ITDR licensing into single "managed" bundles.
## For Security Professionals
Practitioners should view this as a reminder that **MFA is not a silver bullet**. The rise of session hijacking and OAuth abuse means that monitoring what a user does *after* they log in is now just as important as the login process itself. Organizations on Google Workspace should audit their internal visibility into "Rogue Apps" and inbox forwarding rules immediately.