{"id":66614,"date":"2026-06-08T21:16:44","date_gmt":"2026-06-08T21:16:44","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/66614\/"},"modified":"2026-06-08T21:16:44","modified_gmt":"2026-06-08T21:16:44","slug":"inforcer-launches-threat-detection-and-response-platform-to-help-msps-thwart-microsoft-365-threats","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/66614\/","title":{"rendered":"Inforcer Launches Threat Detection And Response Platform To Help MSPs Thwart Microsoft 365 Threats"},"content":{"rendered":"<p>\u2018We\u2019ve spent the last few years helping MSPs protect Microsoft 365 tenants, and we\u2019re now working with more than 1,200 MSPs protecting over 60,000 tenants. But through all of those conversations, it became really clear that there\u2019s often a disconnect between what MSPs would love to do from a security perspective and what end customers are willing to accept,\u201d says Will Connor, co-founder of Inforcer.<\/p>\n<p>            <img decoding=\"async\" loading=\"lazy\" alt=\"Cyber Threat Hunting - The Methods and Techniques of Proactively Searching for Cyber Threats in a Network - Conceptual Illustration\" src=\".\/media_18de59f2670215e1d4de849c880a0e23a9a7dd301.jpg?width=750&amp;format=jpg&amp;optimize=medium\" width=\"523\" height=\"289\"\/><\/p>\n<p>After spending the last three years helping MSPs lock down <a href=\"https:\/\/www.crn.com\/news\/cover-story\/microsoft-s-judson-althoff-to-partners-managed-services-are-your-ai-superpower\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft 365 environments<\/a> before attacks happen, Inforcer is taking aim at what comes next.<\/p>\n<p>Today the London-based vendor unveiled its threat detection and response (TDR) offering, helping MSPs identify active threats, <a href=\"https:\/\/www.crn.com\/news\/security\/2026\/microsoft-s-vasu-jakkal-on-why-ai-agents-need-human-level-security-controls\" rel=\"nofollow noopener\" target=\"_blank\">investigate incidents and respond to attacks across Microsoft 365 environments<\/a>. The launch marks Inforcer\u2019s expansion from left of boom prevention into right of boom detection and response.<\/p>\n<p>For MSPs, the move is about more than adding another security tool, Inforcer executives said, and it completes a broader vision of giving partners a single platform to secure, manage and monitor Microsoft environments.<\/p>\n<p>[Related: <a href=\"https:\/\/www.crn.com\/news\/channel-news\/2025\/inforcer-accelerates-microsoft-ai-enablement-with-35m-funding-round-the-opportunity-was-now\" rel=\"nofollow noopener\" target=\"_blank\">Inforcer Accelerates Microsoft AI Enablement With $35M Funding Round: \u2018The Opportunity Was Now\u2019<\/a>]<\/p>\n<p>\u201cWe\u2019ve spent the last few years helping MSPs protect Microsoft 365 tenants, and we\u2019re now working with more than 1,200 MSPs protecting over 60,000 tenants,\u201d Will Connor, co-founder of Inforcer, told CRN. \u201cBut through all of those conversations, it became really clear that there\u2019s often a disconnect between what MSPs would love to do from a security perspective and what end customers are willing to accept.<\/p>\n<p>\u201cEvery MSP wants to lock everything down, but customers are balancing security against productivity,\u201d he added. \u201cThat means MSPs aren\u2019t always able to implement every protection they\u2019d like. When that happens, they need visibility into what occurs if something slips through the cracks. That\u2019s where threat detection and response comes in. We already had all of this telemetry and visibility across Microsoft 365, so it made sense for us to give MSPs one platform where they can protect tenants, detect incidents, respond to them and then use those insights to strengthen security across every customer they manage.\u201d<\/p>\n<p>Inforcer TDR monitors signals from across Microsoft\u2019s ecosystem, including Entra ID, Defender, Purview, Teams and SharePoint. Connor said one of the biggest advantages comes from combining detection with prevention.<\/p>\n<p>The launch also reflects the company\u2019s larger strategy around Microsoft security and AI readiness.<\/p>\n<p>Inforcer CEO Jamie Daum said MSPs increasingly need security, compliance and governance capabilities as foundational elements for future AI services.<\/p>\n<p>\u201cWe\u2019ve always believed an MSP should be able to run almost everything around Microsoft security and management from a platform purpose-built for MSPs,\u201d Daum told CRN. \u201cThe challenge has always been that Microsoft builds for enterprise first. There\u2019s no multi-tenancy. There\u2019s no way to manage these environments efficiently at scale. That\u2019s what we\u2019ve been solving.<\/p>\n<p>\u201cNow, with TDR, we\u2019re not just helping MSPs manage Microsoft\u2019s security stack,\u201d he added. \u201cWe\u2019re helping them secure it end-to-end. The easiest analogy is your home. Left of boom is the fences, the gates, the locks and the dog in the yard. Right of boom is the burglar alarm and the police response when someone breaks in. Both matter. Every customer has a different risk tolerance, and MSPs need the flexibility to balance protection and productivity. We\u2019re giving them both sides of that equation.\u201d<\/p>\n<p>He said that that capability becomes even more important as organizations embrace AI tools.<\/p>\n<p>Chris Pottrell, managing director at U.K.-based Nebula IT Service Ltd., said Inforcer\u2019s move into threat detection and response is \u201ca natural evolution.\u201d<\/p>\n<p>One of the key advantages is that the new capabilities are built on telemetry already collected within the platform, eliminating the need for additional agents or management tools.<\/p>\n<p>\u201cWe get meaningful detection without bolting on yet another agent or console,\u201d Pottrell told CRN. \u201cIt isn\u2019t just identity, we\u2019re getting visibility right across the M365 security stack.\u201d<\/p>\n<p>He added that the integration of detection and response data with existing security baselines will help MSPs better understand and address security gaps.<\/p>\n<p>\u201cWhat really excites us is that the detection and response information ties directly back to the baseline protections we already deliver,\u201d he said. \u201cWhen we spot something, we can point straight at the control that should have caught it or needs tightening.\u201d<\/p>\n<p>For Matthe Smit, chief product officer at Inforcer, one of the biggest challenges MSPs face today is signal overload.<\/p>\n<p>\u201cMicrosoft monitoring is notoriously noisy,\u201d Smit told CRN. \u201cMSPs know they need to monitor identities because identity has become the new perimeter, but many of the existing tools generate so much noise that people eventually stop paying attention. What we\u2019re focused on is context. An impossible travel alert by itself doesn\u2019t tell you much. But if we can show that a user was compromised, downloaded hundreds of files from OneDrive, created forwarding rules, installed enterprise applications and maintained access for weeks, suddenly you\u2019re looking at a complete attack story. That\u2019s what MSPs need. They need meaningful incidents, not endless alerts.\u201d<\/p>\n<p>He added that attackers often move gradually after gaining access which can make compromises harder to spot in their early stages. Inforcer correlates activity across the Microsoft stack to detect those patterns rather than relying on isolated identity events alone.<\/p>\n<p>\u201cThere are a lot of companies trying to solve security across every platform imaginable,\u201d Smit said. \u201cWe\u2019re incredibly focused. We live and breathe Microsoft 365. We think that allows us to build a lower-noise, better-fit solution for MSPs because that\u2019s all we do.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"\u2018We\u2019ve spent the last few years helping MSPs protect Microsoft 365 tenants, and we\u2019re now working with more&hellip;\n","protected":false},"author":2,"featured_media":66615,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[420,7829,8916,313,9955,9954,400,401,320,7828],"class_list":["post-66614","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-azure","tag-azure-ai","tag-cloud-security","tag-cybersecurity","tag-data-protection","tag-endpoint-security","tag-managed-security","tag-managed-service-providers","tag-microsoft","tag-microsoft-ai"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/66614","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=66614"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/66614\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/66615"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=66614"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=66614"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=66614"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}