Managed IDR
MICROSOFT DEFENDER FOR IDENTITY · ENTRA ID PROTECTION
Managed IDR is our identity scope: cloud and on-prem, human and non-human. Examples are Microsoft Defender for Identity and Entra ID Protection.
What sets this service apart: identity is the attack surface that needs no malware. A stolen token, one approved consent, one MFA push too many. Response here means session revoke and account control, not host isolation.
Typical detections
- Token theft and session hijacking
- Consent phishing and abuse of OAuth apps
- Impossible travel and implausible device combinations
- MFA fatigue and push bombing
- Kerberoasting and DCSync on on-prem AD
- Changes to tier-0 groups and privileged roles
Response actions within mandate
- Session revoke across all active tokens
- Forced password and MFA reset
- Account disable and temporary lockout
- Revoking risky app consents and service principal permissions
- Example mandate: auto revoke for standard accounts, approval required for privileged and tier-0 accounts
Limits of this service
- No host forensics and no process visibility, that is Managed EDR
- No network visibility at segment level, that is Managed NDR
- On-prem coverage depends on domain controller logging and sensor deployment
SLAs
Included
- Identity detection tuning against legitimate business patterns such as travel, contractors and automation
- Monitoring of conditional access, privileged roles and tier-0 groups
- Coverage for non-human identities: service principals, managed identities, OAuth apps
Not included
- Platform and licence cost of the IdP (yours, or passed through at cost)
- Anti-ransomware (e.g. Halcyon) as a separate add-on module
- Implementation of IAM governance, role models and recertification
- Use case/playbook development and log source integration, those come with a Managed SIEM or Managed NDR scope
Process
- Assess
Identity inventory, privileged and tier-0 accounts, existing conditional access policies, non-human identities.
- Integrate
Identity detections rolled out, baseline over the first weeks, tuning against legitimate business patterns.
- Automate
Session revoke and MFA reset pre-authorised by account class, playbook per detection, SOAR enrichment.
Deliverables
- Identity attack surface report including non-human identities
- Conditional access baseline with deviations and recommendations
- Overview of privileged and tier-0 accounts with change history
FAQ
Does this cover non-human identities?
Yes. Service principals, managed identities, OAuth apps and workload identities are in scope, that is exactly where consent grants and app impersonation happen.
Do you also disable executive accounts automatically?
Only if you mandate it that way. As a rule, privileged and tier-0 accounts require approval: we revoke the session, document the finding and escalate along your defined path.
Included in every ANOMAL managed service
- 24/7 threat monitoring: every alert is picked up, enriched with context and documented in the ticket system
- Incident triage on every severity from low to critical, classified as false positive, benign true positive or true positive
- Further analysis on every suspected true positive, including log, telemetry and asset context
- Incident response along NIST: containment and first response within your mandate. A full IR engagement for a major incident is billed separately.
- SOC platform operations: backend, updates and health monitoring of the SOC stack
- Automated incident response: SOAR enrichment, automated queries, pre-authorised response actions per mandate
- Threat hunting and threat intelligence (e.g. MISP plus external feeds) feeding back into detections
- Effectiveness testing once a year, e.g. together with an external purple team
- Service management: monthly service efficiency report, quarterly optimisation meeting, live view in ANOVIEW
- Ongoing operations: continuous tuning, detection maintenance and quarterly service optimisation
Scope, service level (e.g. business hours for low to high, 24/7 for critical) and volumes differ per environment. That is why there is no list price: every customer gets a dedicated quote with defined scope, service level and response mandate. With Managed SIEM and Managed NDR the scope additionally covers use case and playbook development as well as log source integration and management.
Let's talk about Managed IDR.
30 minutes with our SOC team. You describe your situation, we tell you clearly whether and how we can help.
More managed services
We run your SIEM and keep it sharp: we connect new log sources, build detection rules and maintain them.
We monitor your endpoints around the clock and step in immediately during an attack. It works with all leading EDR platforms.
We monitor traffic inside your network and detect lateral movement and connections to attacker infrastructure. The signals flow straight into our cases.
We correlate signals from endpoint, identity, cloud, email and network. Everything lands in one case with one response path.