Huntress Managed Identity Threat Detection & Response (ITDR)

Identity-based cyber attacks are now the number one cause of successful breaches in cloud environments such as Microsoft 365.
Once an attacker gains access to a user account, traditional security controls often do not detect what happens next.

Protecting Microsoft 365 Identities Against Modern Cyber Attacks

To address this risk, SOLVit recommends and deploys Huntress Identity Threat Detection & Response (ITDR) as part of our standard security baseline.


What Is Huntress ITDR?

Huntress ITDR is a security service designed to detect and respond to identity‑based threats within Microsoft 365, including:

  • Compromised user accounts
  • Business Email Compromise (BEC)
  • Malicious inbox rules
  • Suspicious logins and “impossible travel” events
  • Privilege escalation and unauthorised access
  • Data exfiltration indicators

Unlike automated tools alone, Huntress ITDR is backed by a 24/7 human‑led Security Operations Centre (SOC) that investigates alerts and provides clear remediation guidance when malicious activity is suspected.


Why SOLVit Recommends ITDR

Modern cyber attacks no longer rely on malware alone.
Most successful incidents now involve valid credentials obtained through phishing, password reuse, or session hijacking.

Once credentials are compromised, attackers often:

  • Operate quietly inside mailboxes and cloud apps
  • Set hidden inbox rules to intercept or delete emails
  • Impersonate executives or finance staff
  • Launch invoice fraud or payment redirection attacks

Huntress ITDR focuses on what attackers do after login, dramatically reducing the time an attacker can remain undetected.


Cost of Huntress ITDR

Huntress Identity Threat Detection & Response (ITDR) is licensed per Microsoft 365 user.

Pricing:

  • $4.50 AUD per Microsoft 365 licence, per month (ex GST)

This cost covers:

  • 24/7 identity threat monitoring across Microsoft 365
  • Continuous analysis of user, mailbox and tenant activity
  • Human‑led investigation by the Huntress Security Operations Centre (SOC)
  • Incident reporting with clear, actionable remediation guidance

Licensing is aligned directly to your Microsoft 365 user count to ensure:

  • Predictable monthly costs
  • No minimum seat commitments
  • Coverage scales as your business grows or contracts


Included by Default – Opt‑Out Available

Huntress ITDR will be enabled by default for SOLVit‑managed Microsoft 365 environments starting from April 1st 2026. Billing for Huntress ITDR will commence on the 1st of May 2026, based on the number of Microsoft 365 licenses in use.

Clients may choose to opt out, however this decision carries increased risk and commercial implications, outlined below.


Important Risk & Cost Disclosure

If a client chooses to opt out of Huntress ITDR and later experiences an identity‑based security incident, please note: Incident response, investigation, remediation and recovery services may be charged at up to three (3) times the standard hourly rate.

This reflects:

  • Reduced visibility without ITDR telemetry
  • Longer attacker dwell time
  • Broader impact across mailboxes, data and systems
  • Increased effort is required to investigate and contain the incident

Opting out confirms that:

  • SOLVit has recommended ITDR as a preventative security control
  • The client accepts the increased operational and financial risk
  • Any resulting incident will be treated as a high‑effort, non‑covered security response

For most organisations, ITDR represents a low‑cost preventative control compared to the financial and operational impact of a successful breach.


Frequently Asked Questions (Q&A)

Q: Isn’t Microsoft 365 already secure?

Microsoft 365 provides strong security foundations, however it operates under a shared responsibility model.
Microsoft secures the platform — you are responsible for monitoring and responding to account misuse, identity attacks and suspicious behaviour.

ITDR fills this gap.


Q: We already have MFA. Isn’t that enough?

Multi‑Factor Authentication (MFA) is essential, but it is not foolproof.

Attackers increasingly bypass MFA using:

  • Token theft
  • Session hijacking
  • MFA fatigue attacks

ITDR detects abnormal behaviour after authentication, even when MFA is in place.


Q: What happens if we do nothing?

Without ITDR, identity attacks are often detected only after financial loss, data exposure or business disruption.

The longer an attacker remains undetected, the more expensive and damaging the incident becomes.


Q: Why does incident response cost more if we opt out?

When ITDR is not present:

  • There is less forensic data available
  • Investigations take longer
  • The scope of compromise is often wider

This significantly increases the effort required to respond safely and correctly.


Q: Is this a compliance requirement?

While not mandatory on its own, ITDR strongly supports:

  • Essential Eight maturity uplift
  • ISO 27001 control objectives
  • OAIC and notifiable data breach expectations

It demonstrates reasonable steps to protect identities and sensitive information.


Q: Can we opt out later?

Yes. Clients may opt out at any time by providing written confirmation and signing the ITDR Opt‑Out Acknowledgement.
Re‑enablement is also available should your risk posture change.


Need More Information?

SOLVit is happy to:

  • Walk you through real‑world identity attack examples
  • Explain what ITDR monitors (and what it doesn’t)
  • Discuss how ITDR fits into your broader security and compliance posture

Huntress Identity Threat Detections & Response Opt-Out Form

To Opt-Out of Huntress ITDR, this form must be completed and sent back to SOLVit Network Support (helpdesk@solvitns.com.au) before the 1st of May 2026

For more information, please contact SOLVit Network Support to discuss Huntress ITDR or your security risk profile.

Call SOLVit Now

Contact Info

Call us: 

02 6100 6236