Opens in a new tab
vmblog logo 2024 wht (updated)

inforcer Announces General Availability of its Threat Detection & Response Offering for Microsoft 365

Share: 

David Marshall | Published: September 1, 2026

inforcer announced the general availability of its Threat Detection and Response solution, inforcer TDR.

Built specifically for MSPs, inforcer TDR goes beyond traditional identity detection to reduce noise, rapidly identify threats, automate breach containment, and continually strengthen protection across every Microsoft 365 tenant.

Chief Product Officer at inforcer, Matthé Smit, stated: “We opened TDR to more than 700 MSPs, where it was tested against real tenants and real attacks before it was fully ready to be released. 

“Following this, users provided consistent feedback in three areas: First, TDR is surfacing threats in customer estates that partners did not know were there, which is sobering to hear and exactly why we built it. Second, it is quiet, so it earns a technician’s attention instead of draining it. And third, the reporting matters as much as the detection, because it enables our partners to show their customers what happened, in what order, and what was done about it. 

“We’re pleased that this feedback confirms that inforcer TDR meets the needs of our customers and further reinforces our reputation in the industry.”

Drawing on the depth of Microsoft telemetry for wider context

Having announced early access to inforcer TDR in June 2026, 500,000 users were onboarded in the first four weeks alone. To date, inforcer TDR has processed 20 billion logs – the equivalent of 3,000 years’ worth of logs. 

inforcer TDR has unparalleled depth of Microsoft telemetry. Detecting from across Entra ID, Exchange, SharePoint, Teams, Defender and Purview, it enables MSPs to understand the full context of an attack beyond identity alone. It can also analyse up to six months of historical Microsoft 365 logs to provide further context and uncover active compromises that may have gone unnoticed. 

inforcer TDR compiles this complex data into a clear dashboard that allows MSPs to see active incidents, trends, and preventions for every customer from one screen. Users can export jargon-free, customer-ready reports that clearly show every threat detected, every action taken, and the value of MSPs’ security services. 

MSPs are already seeing the benefit of this data. 

Ruben Ven, Modern Workplace Consultant at Yellow Arrow stated: “The timeline is chronological and the contain, remediate, and advise options are really clear. I also loved the export report function – it looks great visually. For a lot of MSPs, this would be a perfect product.”

AI analysis and automatic containment for faster response times

Often, the challenge for security teams is not a lack of data, but identifying the genuine threats hidden within it. Omdia research found that 57% of organisations cite alert fatigue as a major challenge, with excessive alert volumes increasing the risk that legitimate threats are missed.

TDR is already helping alleviate this burden. In just six weeks, the platform has detected thousands of real threats within minutes and reduced average containment time to less than 60 seconds.

Human analysts operating within a Security Operations Centre (SOC) simply can’t respond quickly enough or consistently around the clock, making it difficult to protect against AI-powered attacks that move through an environment in minutes. inforcer TDR does things differently than traditional Identity Threat Detection and Response solutions, using AI to fight AI. 

inforcer TDR has a behavioural engine that individually profiles every user, Entra application, tenant, and MSP, analysing every signal, spotting patterns, and anomalies, and intelligently reducing noise.  inforcer TDR can then act against threats immediately: automatically revoking active sessions, locking or disabling compromised accounts, and containing the breach in as little as just a few seconds. 

Feedback from customers has included the following:

  • Chad Williams, Senior Systems Engineer at Stability Networks stated that he was seeing threat responses ‘within minutes’ compared to 30 minutes with his current solution. 
  • Tom Lovell, CTO at Infinity Group stated: “It is plugging a real gap between unmonitored alerts and our expensive 24/7 service. The value-add of after-hours isolation and containment without a full 24/7 service fee is huge.”

The platform is not just using AI. It is also backed by oversight from a human SOC team that can advise on threats and provide additional threat verification where necessary, to reduce false positives, and streamline the alerting system.