Full Report
Managed ISPM now offers two deployment modes. Choose fully automated hardening or full control over which Microsoft 365 controls roll out, and when. See how it works.
Analysis Summary
# Industry News: Huntress Expands Managed ISPM with Dual Deployment Modes
## Summary
Huntress has announced a significant update to its Managed Identity Security Posture Management (ISPM) solution, introducing two distinct deployment modes for Microsoft 365 hardening. The update allows organizations to choose between fully automated "Expert-Led" hardening or a "Customized" approach that grants granular control over policy rollouts and timing.
## Key Details
- **Date:** September 24, 2026
- **Companies Involved:** Huntress
- **Category:** Product Update / Managed Security Services
## The Story
The core challenge in identity security is the "implementation gap." Huntress data reveals that over 90% of organizations fail to update their security settings manually, and 60% of Microsoft 365 tenants are missing over half of the recommended identity controls. This hesitation usually stems from a fear of "breaking" business workflows or locking out users during critical hours.
To address this, Huntress has evolved its Managed ISPM to cater to two different operational philosophies:
1. **Fully Managed:** Designed for MSPs and lean internal teams who want Huntress experts to automatically deploy and maintain best-practice controls and remediate configuration drift without manual intervention.
2. **Modified Control:** Designed for high-compliance environments (such as those under CMMC) or organizations with strict change-control boards that require pre-approval and scheduled windows for any environment changes.
## Business Impact
### For the Companies Involved
- **Huntress:** Solidifies its position as a leading provider for the SMB and MSP market by removing the "fear of friction" that prevents product adoption. The move addresses the scalability issues inherent in manual security reviews.
### For Competitors
- **Competitive Landscape:** Increases pressure on SaaS Security Posture Management (SSPM) competitors who provide "alert-only" platforms. By offering a "managed-action" model with a low rollback rate (under 1%), Huntress differentiates itself from tools that merely identify problems without fixing them.
### For Customers
- **Efficiency:** MSPs can now manage hundreds of tenants without manual ticket creation for every policy change.
- **Compliance:** Organizations in regulated industries gain the "veto power" needed to satisfy auditors while still benefiting from expert-vetted security policies.
### For the Market
- **Standardization of Hardening:** Signals a shift in the market from "Visibility" to "Active Remediation." It acknowledges that mid-market organizations lack the bandwidth to act on the telemetry they receive.
## Technical Implications
The update tackles "Configuration Drift"—the phenomenon where security settings revert or become obsolete as Microsoft updates its platform. The technical innovation lies in the platform’s ability to automate drift remediation while maintaining a remarkably low <1% rollback rate, suggesting highly refined policy testing and vetting processes.
## Strategic Analysis
- **Market Positioning:** Huntress is positioning itself as an "extension of the team" rather than just a software vendor.
- **Competitive Advantage:** The dual-mode approach removes the primary sales objection for ISPM: the loss of control.
- **Challenges:** The primary risk is the inherent complexity of M365; even with a 1% rollback rate, a single high-profile lockout in a sensitive environment can damage brand trust.
## Industry Reactions
- **Market Response:** Generally positive, as identity-based attacks (OAuth abuse, RMM exploitation) are currently the primary vectors for initial access. Analysts view active hardening as a necessary evolution beyond simple MFA.
## Future Outlook
- **Predictions:** Expect Huntress to expand these managed deployment modes beyond Microsoft 365 into other critical SaaS silos (e.g., Google Workspace, Salesforce).
- **Watch For:** Integration of these hardening modes with Huntress’ SOC services to create a "closed-loop" system where threats detected by the SOC lead to immediate automated policy hardening.
## For Security Professionals
Practitioners should note the high rate of missing identity controls (60%+) cited in the report. This update provides a pathway to achieve "Zero Trust" milestones without the traditional overhead of manual policy management. If you operate under CMMC or similar frameworks, the "Modified" mode allows you to maintain the required human-in-the-loop oversight for environment changes.