This document sets out what's included in our Identity Threat Detection and Response (ITDR) for Office 365 solution.
Our ITDR service is designed to enhance the security of Office 365 environments by providing advanced threat detection, 24/7 monitoring, and expert-led response. The service provides the following feature set:
Continuous monitoring of Office 365 activity, including email, SharePoint, OneDrive, and Teams
Advanced detection of sophisticated threats such as account takeovers, phishing attacks, and privilege escalations
Real-time incident response to contain and mitigate threats before they impact operations
Detailed reporting and analytics to track security incidents and improve defence strategies
The solution is jointly managed by our in-house team and the Huntress Security Operations Centre (SOC), ensuring threats are detected and mitigated proactively. Huntress is well known within the industry as a leading provider of threat response services, using a highly talented in-house team.
Customers can contact our dedicated support team for assistance with queries or incidents. Typically, cases are raised by the Huntress SOC when alerts are triggered, however the customer may raise issues where required. Likely topics are:
Investigating and responding to alerts related to suspicious Office 365 activities
Resolving issues with blocked or flagged legitimate activities
Providing guidance on improving security settings within the Office 365 platform
Service coverage is provided in line with the customer's existing Managed IT Service support contract.
Our team receives and manages alerts for a variety of events within the Office 365 environment, including:
Unusual login patterns or suspicious access attempts
Detection of phishing, malware, or ransomware attacks
Critical incidents such as account compromises or data breaches
Each alert is reviewed for impact, and if necessary, appropriate action is taken to mitigate risk. Communications are sent to customers detailing the incident and recommended steps.
The most common report is a post-incident report summarising the findings of the completed investigation, along with any next steps that should be undertaken.
Our team collaborates with Huntress to review generated incidents and alert data as required. Remediation steps and recommended actions are supplied by Huntress to our team, with further support available if needed. This process is fully managed by our team, with no additional cost to the customer.
When new features are introduced to the platform that could enhance customer security, these are evaluated for suitability. If any feature requires service disruption or adjustments to existing functionality, customers are notified in advance, and a collaborative approach is taken to implement the changes.
For significant customisations or integrations requiring extensive effort, these items will be scoped and discussed independently with the customer.
Initial assessment and configuration
Review the existing Office 365 environment, including licensing and security settings
Identify priority areas for protection, such as high-value accounts and sensitive data
Platform integration
Connect Office 365 to the ITDR platform for real-time monitoring and analysis
Policy and alert configuration
Define policies for detecting and responding to threats
Configure alerting and reporting
Baseline threat analysis
Perform an initial scan of the Office 365 environment to identify existing threats or vulnerabilities
Deliver a baseline report with recommendations for immediate improvements
Incident response planning
Establish protocols for responding to detected threats, including escalation procedures
Align response workflows with the organisation's existing incident response plan