Why identity is the new endpoint
For most of the last two decades, security tooling focused on the endpoint. Antivirus, then EDR, then MDR. The attacker model has shifted. According to the Huntress 2026 Cyber Threat Report and the ACSC Annual Cyber Threat Report, attackers in 2025 increasingly avoided malware altogether. They bought credentials on infostealer logs, used Adversary-in-the-Middle phishing kits to steal session tokens, and signed into Microsoft 365 like a normal user.
Once an attacker has a valid token or password, traditional endpoint tools see nothing. The login looks like work. That is why identity-focused detection has become a category in its own right.
37.2%
Of 2025 identity incidents were suspicious logins. Source: Huntress 2026 report
18.9%
Involved Adversary-in-the-Middle attacks. Source: Huntress 2026 report
10.1%
Involved malicious OAuth or app abuse. Source: Huntress 2026 report
What ITDR actually detects
ITDR sits across your identity provider (Microsoft Entra ID, Google Workspace) and watches sign-in activity, mailbox configuration, OAuth grants and admin actions. It looks for the patterns attackers use rather than the malware they used to drop.
Suspicious logins
Impossible travel, unusual locations, anonymising VPNs, and sign-ins from known malicious IP ranges.
Adversary-in-the-Middle (AiTM)
Detects the telltale token-replay patterns produced by phishing kits like Evilginx and Tycoon 2FA.
Session hijacking
Stolen session tokens replayed from a different device or country, the way attackers bypass MFA.
Malicious inbox rules
Rules that auto-forward, hide or delete emails containing words like "invoice", "remittance" or the attacker's domain.
Rogue OAuth apps
Unauthorised applications granted access to your tenant by phished users, used by attackers for persistence.
Mass outbound phishing
Compromised mailboxes used to phish your customers, often the first sign your domain is being abused.
Credential theft signals
Password spray, MFA fatigue prompts, and credentials appearing on infostealer logs.
Privilege abuse
Newly elevated accounts, abnormal use of break-glass identities, and changes to global admin role assignments.
EDR vs ITDR. You need both
EDR and ITDR are complementary, not competing. The way modern attacks unfold, you need visibility on both surfaces.
| Capability | EDR / MDR | ITDR |
|---|---|---|
| Watches | Endpoints (laptops, servers) | Identity provider, mailboxes, OAuth |
| Detects malware | Yes | No |
| Detects stolen tokens | No | Yes |
| Detects malicious inbox rules | No | Yes |
| Detects AiTM phishing | Limited | Yes |
| Detects OAuth abuse | No | Yes |
| Detects ransomware payload execution | Yes | No |
Where ITDR fits in the Australian regulatory picture
ACSC Essential Eight
ITDR supports several Essential Eight controls, particularly Multi-Factor Authentication and Restrict Administrative Privileges, by detecting when those controls are bypassed or abused. Reference: cyber.gov.au essential-eight.
Privacy Act 1988
ITDR materially shortens the time to detect unauthorised access to personal information, which is the trigger for assessment under the Notifiable Data Breaches scheme.
APRA CPS 234
For regulated entities, CPS 234 expects information security capability commensurate with vulnerabilities and threats. Identity attacks are now a primary threat vector, so identity detection capability is in scope.
Getting started with ITDR
Want to see what ITDR would catch in your tenant?
Real Bytes can run a no-cost identity posture review against your Microsoft 365 environment and show you exactly which signals an ITDR platform would surface.

Remote Support