Most cyber attacks on Australian businesses now start with a stolen login, not a virus. Once an attacker is inside a Microsoft 365 mailbox they can read emails, hide their tracks and send convincing fake invoices to your clients. ITDR (Identity Threat Detection and Response) from Sydney Technology Solutions watches your Microsoft 365 accounts for signs of takeover, and a 24/7 human-led Security Operations Centre (SOC) shuts the attacker out fast.

What is ITDR?
ITDR monitors your user accounts and sign-ins rather than your devices. It looks for the tell-tale signs that an account has been compromised and responds before the damage is done. It’s designed to stop business email compromise (BEC), invoice and payment redirection fraud, and attackers using a hijacked account to move further into your business.
What ITDR detects in Microsoft 365
- Suspicious sign-ins: logins from unusual countries, anonymising VPNs or impossible travel
- Malicious inbox rules: rules that hide, delete or forward emails, a classic sign of invoice fraud
- Session and token theft: attackers who steal a logged-in session to get around MFA
- Risky changes: new MFA methods, mailbox forwarding or permission changes the user didn’t make
- Rogue apps: malicious applications granted access to your mailbox or files
Don’t we already have MFA?
Multi-factor authentication is essential and we set it up for every client, but it isn’t bulletproof. Modern phishing kits can steal a login and the MFA session in real time, and users can be tricked into approving a sign-in. ITDR is the safety net: it spots the attacker after they get in and removes them before they can do harm.
| MFA alone | MFA + ITDR | |
|---|---|---|
| Stops simple password theft | Yes | Yes |
| Stolen session or token used to bypass MFA | Not detected | Detected and access revoked |
| Hidden inbox rules forwarding invoices | Not detected | Detected and removed |
| Someone watching 24/7 | No | Yes, a human-led SOC |
How it works when something happens
1. Detect
Unusual sign-in, inbox rule or account change is flagged.
2. Investigate
SOC analysts review it immediately, 24/7.
3. Respond
The account is disabled or sessions revoked, and malicious rules and apps removed.
4. Recover
We reset credentials, check for other changes, confirm whether anything needs reporting and help warn anyone affected.
A real-world example
A staff member enters their Microsoft 365 password on a convincing fake login page. Minutes later, someone signs in from overseas and creates a hidden rule to forward invoices. With ITDR, the unusual sign-in and the suspicious rule are flagged straight away, the attacker’s session is cut off and the rule removed, often before a single fake invoice is sent. Without it, attacks like this often go unnoticed for weeks.
Who needs ITDR?
Any business that uses Microsoft 365 for email, and especially businesses that send or receive invoices and payments. It pairs with managed EDR for your devices, so both your accounts and your computers are protected.
Why choose STS for ITDR
ITDR is most effective when someone acts on the alerts. Our ITDR service is monitored around the clock, and suspicious accounts are locked down quickly, then cleaned up with you. ITDR complements multi-factor authentication and the Australian Cyber Security Centre’s advice on protecting business email from compromise.
What our clients say
“They have saved my office from so many email attacks and recovered my data on numerous occasions.”
Robert Nap, Google review
STS is rated 4.8★ on Google. Read more client reviews.
Frequently asked questions
Does ITDR work with Microsoft 365?
Yes. ITDR connects to your Microsoft 365 environment and monitors sign-ins, mailboxes and account changes. There’s nothing to install on your computers.
Will my staff notice anything?
No, unless their account is compromised. Then the account may be locked while we secure it, and we’ll help them get back in quickly.
What’s the difference between ITDR and EDR?
EDR protects devices (laptops, desktops and servers). ITDR protects user accounts and logins. Most attacks involve both, so we usually recommend the two together.
What if our email has already been hacked?
Call us now on (02) 8212 4722 and see our cyber incident response page for what to do first.
How much does it cost?
It depends on the number of Microsoft 365 users you have. We’ll give you clear pricing with no surprises.
Protect your Microsoft 365 accounts
Talk to us about ITDR, or see our full cybersecurity services. Call (02) 8212 4722 or send us a message.
55 Park Road,