All Guides
ITDR Explained

Identity Threat Detection and Response (ITDR), explained for business

If your team uses Microsoft 365 or Google Workspace, identity is now your most attacked surface. Most of the attacks Australian SMBs see in 2026 start with stolen credentials or hijacked sessions, not malware on a laptop. This guide explains ITDR, how it differs from EDR, and what it does for your business.

Last updated April 202611 min read

Why identity is the new endpoint

For most of the last two decades, security tooling focused on the endpoint. Antivirus, then EDR, then MDR. The attacker model has shifted. According to the Huntress 2026 Cyber Threat Report and the ACSC Annual Cyber Threat Report, attackers in 2025 increasingly avoided malware altogether. They bought credentials on infostealer logs, used Adversary-in-the-Middle phishing kits to steal session tokens, and signed into Microsoft 365 like a normal user.

Once an attacker has a valid token or password, traditional endpoint tools see nothing. The login looks like work. That is why identity-focused detection has become a category in its own right.

37.2%

Of 2025 identity incidents were suspicious logins. Source: Huntress 2026 report

18.9%

Involved Adversary-in-the-Middle attacks. Source: Huntress 2026 report

10.1%

Involved malicious OAuth or app abuse. Source: Huntress 2026 report

What ITDR actually detects

ITDR sits across your identity provider (Microsoft Entra ID, Google Workspace) and watches sign-in activity, mailbox configuration, OAuth grants and admin actions. It looks for the patterns attackers use rather than the malware they used to drop.

Suspicious logins

Impossible travel, unusual locations, anonymising VPNs, and sign-ins from known malicious IP ranges.

Adversary-in-the-Middle (AiTM)

Detects the telltale token-replay patterns produced by phishing kits like Evilginx and Tycoon 2FA.

Session hijacking

Stolen session tokens replayed from a different device or country, the way attackers bypass MFA.

Malicious inbox rules

Rules that auto-forward, hide or delete emails containing words like "invoice", "remittance" or the attacker's domain.

Rogue OAuth apps

Unauthorised applications granted access to your tenant by phished users, used by attackers for persistence.

Mass outbound phishing

Compromised mailboxes used to phish your customers, often the first sign your domain is being abused.

Credential theft signals

Password spray, MFA fatigue prompts, and credentials appearing on infostealer logs.

Privilege abuse

Newly elevated accounts, abnormal use of break-glass identities, and changes to global admin role assignments.

EDR vs ITDR. You need both

EDR and ITDR are complementary, not competing. The way modern attacks unfold, you need visibility on both surfaces.

CapabilityEDR / MDRITDR
WatchesEndpoints (laptops, servers)Identity provider, mailboxes, OAuth
Detects malwareYesNo
Detects stolen tokensNoYes
Detects malicious inbox rulesNoYes
Detects AiTM phishingLimitedYes
Detects OAuth abuseNoYes
Detects ransomware payload executionYesNo

Where ITDR fits in the Australian regulatory picture

ACSC Essential Eight

ITDR supports several Essential Eight controls, particularly Multi-Factor Authentication and Restrict Administrative Privileges, by detecting when those controls are bypassed or abused. Reference: cyber.gov.au essential-eight.

Privacy Act 1988

ITDR materially shortens the time to detect unauthorised access to personal information, which is the trigger for assessment under the Notifiable Data Breaches scheme.

APRA CPS 234

For regulated entities, CPS 234 expects information security capability commensurate with vulnerabilities and threats. Identity attacks are now a primary threat vector, so identity detection capability is in scope.

Getting started with ITDR

Confirm your identity provider audit logs are enabled and retained for at least 90 days
Move all admin accounts to phishing-resistant MFA (FIDO2 or Windows Hello for Business)
Review existing OAuth app grants in your Microsoft 365 tenant and remove any not in use
Enable Conditional Access policies blocking legacy authentication
Establish a process for detecting and removing malicious inbox rules
Choose an ITDR platform (we deploy Huntress Managed ITDR for Microsoft 365 and Google Workspace)
Define an incident response runbook for compromised identity events
Train finance and exec assistants on AiTM and BEC patterns

Want to see what ITDR would catch in your tenant?

Real Bytes can run a no-cost identity posture review against your Microsoft 365 environment and show you exactly which signals an ITDR platform would surface.