Microsoft 365 and identity monitoring
Account takeover and new inbox rules caught in minutes, which is where most business email fraud starts.
Coverage
Every sign-in and rule change, day and night
Price
Included in every plan
Most of the incidents we contain do not start with malware. They start with a password and an approved MFA push, followed within a minute by an inbox rule that hides the conversation from its owner.
What we watch
Sign-ins from new countries, new devices and impossible travel.
New inbox rules, forwarding addresses and mailbox permissions.
OAuth apps granted access to mail and files.
Changes to MFA methods and admin roles.
What we do when it fires
Revoke the sessions, remove the rule, hold outbound mail and lock the account until its owner confirms by phone. The median time from alert to contained on these cases last quarter was 16 minutes.
Is it right for you?
In a 30 minute risk review we look at what you run today and tell you whether this service would change anything. If it would not, we say so.
Other services in the plan
Managed detection and response
24/7, a person on it within 15 minutes
Managed SIEM and log retention
13 months of searchable logs
Incident response retainer
Response lead on the phone within 1 hour
Vulnerability management
Scanned monthly, reviewed on the call
Virtual CISO and compliance
4 hours a month from one named person
Thirty minutes to find out who is watching your network tonight.
Bring your last insurance questionnaire or audit finding. We tell you in plain words where you are exposed after hours and what closing it would cost, then send a written quote within two business days.