inforcer - Experts & Thought Leaders
Latest inforcer news & announcements
inforcer, a provider of Microsoft 365 multi-tenant management software for Managed Service Providers (MSPs), has announces the general availability of its Threat Detection and Response solution, inforcer TDR. Built specifically for MSPs, inforcer TDR goes beyond traditional identity detection to reduce noise, rapidly identify threats, automate breach containment, and continually strengthen protection across every Microsoft 365 tenant. Providing consistent feedback Chief Product Officer at inforcer, Matthé Smit, stated: “We opened TDR to more than 700 MSPs, where it was tested against real tenants and real attacks before it was fully ready to be released.” “Following this, users provided consistent feedback in three areas: First, TDR is surfacing threats in customer estates that partners did not know were there, which is sobering to hear and exactly why we built it. Second, it is quiet, so it earns a technician's attention instead of draining it. And third, the reporting matters as much as the detection, because it enables our partners to show their customers what happened, in what order, and what was done about it.” Uncover active compromises “We’re pleased that this feedback confirms that inforcer TDR meets the needs of our customers and further reinforces our reputation in the industry.” Having announced early access to inforcer TDR in June 2026, 500,000 users were onboarded in the first four weeks alone. To date, inforcer TDR has processed 20 billion logs – the equivalent of 3,000 years’ worth of logs. inforcer TDR has unparalleled depth of Microsoft telemetry. Detecting from across Entra ID, Exchange, SharePoint, Teams, Defender and Purview, it enables MSPs to understand the full context of an attack beyond identity alone. It can also analyse up to six months of historical Microsoft 365 logs to provide further context and uncover active compromises that may have gone unnoticed. inforcer TDR compiles this complex data into a clear dashboard that allows MSPs to see active incidents, trends, and preventions for every customer from one screen. Users can export jargon-free, customer-ready reports that clearly show every threat detected, every action taken, and the value of MSPs’ security services. Excessive alert volumes Ruben Ven, Modern Workplace Consultant at Yellow Arrow stated: “The timeline is chronological and the contain, remediate, and advise options are really clear. I also loved the export report function – it looks great visually. For a lot of MSPs, this would be a perfect product.” Often, the challenge for security teams is not a lack of data, but identifying the genuine threats hidden within it. Omdia research found that 57% of organisations cite alert fatigue as a major challenge, with excessive alert volumes increasing the risk that legitimate threats are missed. Disabling compromised accounts TDR is already helping alleviate this burden. In just six weeks, the platform has detected thousands of real threats within minutes and reduced average containment time to less than 60 seconds. Human analysts operating within a Security Operations Centre (SOC) simply can’t respond quickly enough or consistently around the clock, making it difficult to protect against AI-powered attacks that move through an environment in minutes. inforcer TDR does things differently than traditional Identity Threat Detection and Response solutions, using AI to fight AI. inforcer TDR has a behavioural engine that individually profiles every user, Entra application, tenant, and MSP, analysing every signal, spotting patterns, and anomalies, and intelligently reducing noise. inforcer TDR can then act against threats immediately: automatically revoking active sessions, locking or disabling compromised accounts, and containing the breach in as little as just a few seconds. Providing additional threat verification Feedback from customers has included the following: Chad Williams, Senior Systems Engineer at Stability Networks stated that he was seeing threat responses ‘within minutes’ compared to 30 minutes with his current solution. Tom Lovell, CTO at Infinity Group stated: “It is plugging a real gap between unmonitored alerts and our expensive 24/7 service. The value-add of after-hours isolation and containment without a full 24/7 service fee is huge.” The platform is not just using AI. It is also backed by oversight from a human SOC team that can advise on threats and provide additional threat verification where necessary, to reduce false positives, and streamline the alerting system.
inforcer, a provider of Microsoft 365 multi-tenant management software for Managed Service Providers (MSPs), has announced the release of its new Threat Detection and Response solution to help MSPs rapidly identify threats, contain breaches, and prevent recurrence of attacks, unifying left of boom and right of boom security. Having spent the last three years becoming the dominant player in left of boom tenant security, helping more than 1,200 MSP partners to secure and manage Microsoft 365 tenants at scale, inforcer is now branching into right of boom security. At Pax8 Beyond in Salt Lake City, held on 7-9 June, the company unveiled its new product: inforcer Threat Detection and Response. This latest release contributes to inforcer’s offering as the complete platform to manage and secure Microsoft 365 and Copilot for MSPs at scale. Management control plane The company’s solutions are designed to prevent and lessen the impact of attacks left of boom through a multi-tenant Microsoft 365 management control plane, while also enabling clients to rapidly and effectively manage attacks right of boom with real-time detection, incident management, and automated response. While customers expect MSPs to protect them from attacks by default, this is increasingly challenging. With widespread remote working and AI adoption, it is easier than ever for threat actors to launch attacks from anywhere in the world. Breaches are often invisible: once a malicious actor is inside the perimeter, they can lurk for months working to elevate their privileges before executing significant attacks. Additional revenue stream Left of boom preventative security measures are essential, but it is often difficult for MSPs to prove the value of preventative tenant management to their customers. Even the most security-forward and threat-conscious MSPs are still reliant on threat detection and response tools. To win clients and retain recurring revenue, MSPs need to visibly demonstrate how they are catching and preventing attacks – something that requires left and right of boom technologies to seamlessly work together. inforcer’s expansion into right of boom security management helps MSPs complete the security story: providing the visible evidence customers need to understand why left of boom tenant management is necessary. With inforcer’s single end-to-end security platform, MSPs can detect and respond to breaches effectively, while also demonstrating the potential impact and severity of each threat. This makes it easier to reinforce the value of preventative tenant security measures, which MSPs can also execute with inforcer, and then sell as an additional revenue stream. Minimising false positives inforcer started out as a multi-tenant management solution. As a result, the platform already has unique insight into the Microsoft tenant across all applications. Unlike most identity threat detection and response solutions on the market, which focus solely on identity as the threat vector, inforcer Threat Detection and Response continuously monitors signals from every layer of Microsoft 365 including Entra, Defender, Purview, Teams, and SharePoint. Examining every data entry point provides MSPs with unparalleled insight into the full context of an action, minimising false positives and alerts. Complete security platform “At inforcer, we’re building the complete security platform MSPs can use for the long-term,” said Jamie Daum, CEO at inforcer. “We’re consistently innovating and expanding, so MSPs can innovate and expand alongside us. With Threat Detection and Response, inforcer is now the single, centralised platform for multi-tenant Microsoft 365 management across the entire security lifecycle, both left of boom and right of boom."
Bulletproof, a GLI company and a pioneer in managed security and Microsoft-focused cybersecurity services, announced a strategic partnership with leading Microsoft multi-tenant management solution, inforcer, to deliver continuous configuration assurance for Microsoft security environments—addressing one of the most common and preventable sources of modern security incidents: misconfiguration and configuration drift. Configuration changes enable breach Across the cybersecurity industry, many breaches originate not from missing security tools, but from subtle configuration changes that weaken defenses over time. These changes often occur after initial deployment and can remain undetected for months, silently increasing risk. "This gap represents a critical limitation in traditional Security Operations Center (SOC) models,” said Steven Duguay, Vice President, MSSP at Bulletproof. “Misconfigurations and configuration drift are among the most common—and most preventable—drivers of security incidents, yet they’re frequently overlooked because most SOCs are designed to react to alerts, not continuously validate that security controls remain properly configured.” Software integration Through the integration of inforcer’s configuration assurance platform, Bulletproof extends its SOC services beyond detection and response to include continuous validation and enforcement of Microsoft security baselines. This ensures that when security settings drift from approved standards - whether due to routine changes, human error, or unauthorised activity - the deviation is identified immediately and remediated quickly. “By embedding continuous configuration assurance into our managed services, we’re giving clients confidence that their Microsoft security posture remains strong every single day,” Duguay added. Security settings This approach delivers more consistent and resilient security outcomes for clients year-round. Continuous monitoring significantly reduces breach risk by addressing configuration issues before they escalate into serious incidents. Daily backups of critical security settings enable rapid recovery from accidental or malicious changes. Additionally, automated enforcement accelerates remediation and minimizes manual effort, allowing security teams to focus on higher-value work. Clients also gain enhanced visibility into how their environments align with recognised benchmarks from organisations such as the Center for Internet Security (CIS), which supports both security maturity and compliance objectives. Partnership purpose and benefits From inforcer’s perspective, the partnership integrates configuration assurance directly into an operational SOC model. “Bulletproof’s SOC is renowned for its operational rigor and deep Microsoft expertise,” said Christian Nagele, Chief Strategy Officer, inforcer. “By pairing our configuration assurance capabilities with their managed security services, organisations can maintain a consistently secure and compliant environment while eliminating the drift, gaps, and manual effort that often undermine long-term protection.” The partnership also strengthens Bulletproof’s own managed security operations by improving efficiency and scalability. Automating configuration assurance minimizes manual drift investigations and enables more predictable service delivery in line with Bulletproof’s established SOC standards. This allows the SOC to support more clients and increasingly complex Microsoft environments without added operational burden, while also reinforcing a clear competitive advantage in a crowded MSSP market. “This partnership enhances our SOC efficiency, strengthens our differentiation, and elevates the protection we provide across our entire customer base,” Duguay said.
Security technologies promote real-time awareness in K-12 schools
DownloadTechnology's role in securing banks and financial institutions
DownloadIntegrated systems enable critical and compliant security for transportation
DownloadModernising physical access control
DownloadAccess. Intrusion. One estate.
Download