Guardz Identity Threat Detection & Response (ITDR)
Detect identity-tier attacks on Entra ID and Google Workspace before they pivot.
Attackers are not breaking in any more. They are logging in. The Salesloft and Drift OAuth compromise chains of 2024-2025 proved the point — credentials and tokens are the new perimeter, and most endpoint-focused tools simply miss the identity-tier signal entirely.
Guardz ITDR is the purpose-built module for detecting these attacks on Microsoft Entra ID, Microsoft 365 and Google Workspace identity. Detection content covers misconfigured directory posture, anomalous app-registration creation, suspicious admin role grants, over-permissioned service principals, OAuth phishing chains and the kind of token-replay activity that signature-based tools never catch in time. The product engineering team also runs the EntraReaper research project — an autonomous red-teaming programme that maps the Microsoft 365 attack surface and feeds new detections back into the platform.
For Australian MSPs whose SMB tenants live in Microsoft 365 or Google Workspace, this is the module that matters most. Endpoint AV plus EDR does not catch an OAuth grant gone wrong, an attacker creating a persistent app registration in Entra ID, or a service principal slowly acquiring scopes it should never have. Guardz ITDR does, and it correlates the identity signal with the endpoint and email surface so the response runs across all three in one workflow.
Scope
Microsoft Entra ID, Microsoft 365 identity, Google Workspace identity
Detection Content
OAuth phishing, app-registration persistence, anomalous admin grants, over-permissioned service principals
Response
Suspend user, revoke OAuth tokens, isolate endpoint — automated playbook then SOC validation
Research Programme
EntraReaper — autonomous red-teaming for Microsoft 365 attack-surface mapping
Multi-Tenant
Native — one console across the MSP customer base with white-label branding
Correlation
Identity signals stitched with endpoint and email surface for one incident view
Plans
Included in Pro and Ultimate; 24/7 MDR overlay in Ultimate
ITDR as a product category is crowded but uneven. Microsoft Defender for Identity is excellent on Entra ID telemetry but locked to the Microsoft estate. Vectra and Varonis play at enterprise scale with enterprise pricing. Huntress shipped its own ITDR product but the detection content is endpoint-adjacent rather than identity-native. Guardz ITDR was built around the recognition that the identity surface is its own discipline, and the EntraReaper research project keeps the detection content current with how attackers actually pivot through Microsoft 365. For Australian MSPs serving SMB tenants, the structural advantage is multi-tenant by default, integrated with the rest of the Guardz platform, and priced for the SMB segment.
One of the advantages of working with CRS — we can recommend the best combination of vendors for your specific needs.
Keepit
Pair Guardz active threat detection with [Keepit](/vendors/keepit) independent SaaS backup of the same workloads — prevention plus recovery in one CRS bundle.
Cibecs
[Cibecs](/vendors/cibecs) protecting endpoint data and DMARC at the email edge while Guardz handles identity-tier detection on Entra ID and Google Workspace.
NAKIVO
[NAKIVO](/vendors/nakivo) protecting on-premises VMs and physical servers while Guardz watches the cloud identity surface.
Guardz Identity Threat Detection & Response is available through Cloud Ready Solutions and our network of authorised partners across Australia, New Zealand, and the Pacific.
Already a CRS partner?
Log in to configure and quoteGuardz
Endpoint & Cyber Security
MSP-built unified cybersecurity platform with 24/7 managed detection and response — identity, endpoint, email and cloud data in one console.
View all Guardz products