---
title: "Identity protection (ITDR) — when the attack logs in instead of breaking in"
description: "What ITDR is and why stolen credentials are today's most common attack path — protection for Microsoft 365 identities with 24/7 monitoring, as a per-account block."
canonical: "https://corevatis-redesign.pages.dev/en/services/identitaetsschutz/"
lang: en
schema_type: WebPage
---
# Identity protection (ITDR) — when the attack logs in instead of breaking in

What ITDR is and why stolen credentials are today's most common attack path — protection for Microsoft 365 identities with 24/7 monitoring, as a per-account block.

## The short version

- **What:** Monitoring of your user accounts: suspicious sign-ins, hidden forwarding rules and account takeovers get detected and stopped.
- **Why:** Most successful attacks do not break in — they log in. With stolen or phished credentials, often despite MFA.
- **For whom:** Every company with Microsoft 365 or other cloud accounts — especially where invoices and payments run via email.
- **Billing:** Per user account per month, as its own position — the natural second block next to endpoint protection.

A good fit if:

- Your invoice approvals and payment instructions run via email
- MFA is on — but nobody checks what happens after the login
- A 'strange mail from ourselves' incident has happened before

## What is ITDR — in one sentence?

ITDR (Identity Threat Detection and Response) watches your **user accounts** the way [EDR](/en/services/endpoint-schutz) watches your devices: suspicious sign-ins, covert mailbox rules and taken-over accounts get detected, stopped and assessed by an analyst team.

## Why this may be the most important block today

The modern attacker does not break in — **they log in**. Credentials from phishing, data leaks or intercepted sessions are the most common way into mid-sized companies. And the most expensive variant is unspectacular: the attacker takes over a mailbox, reads along for weeks, sets an inconspicuous forwarding rule — and strikes exactly when a real invoice is due. Only the bank account is different. This fraud (business email compromise) has caused higher losses than ransomware for years — it is just quieter.

**And MFA?** Essential, but not the end: fatigue attacks, intercepted session tokens and phished codes bypass it regularly. MFA makes the attacker's login harder — ITDR notices when it succeeded anyway.

## Who needs it?

- **Every company that instructs or approves payments via email** — classic BEC hits finance and management.
- **Every company on Microsoft 365** or other cloud accounts: the identity is the master key to mail, files and Teams.
- **Companies with remote access and external providers** — more accounts, more doors.

## What we take on

- Connecting your user accounts to identity monitoring — without touching daily work
- 24/7 assessment of suspicious sign-ins and rule changes by the analyst team
- Immediate action on takeover: end sessions, secure the account, remove malicious rules — then the debrief with you
- Interplay with [access order](/en/use-cases/zero-trust-baseline) and [user administration](/en/services/managed-workplace): clean accounts are half the defence

## Billing

Per user account per month, as its own position — [like every block](/en/services/add-ons). Typically combined with [endpoint protection](/en/services/endpoint-schutz): device and identity are the two ways in, and both deserve a guard.

## FAQ

**We have MFA — is that not enough?**
MFA is mandatory and stays so. But it only checks the moment of login. ITDR watches what happens after: the sign-in from two countries within an hour, the new forwarding rule at midnight, the sudden mass download. One does not replace the other.

**Is someone reading our mail?**
No. What is monitored are sign-in events, configuration changes and permissions — not your content.

**What happens on a detected takeover?**
The account gets secured immediately — sessions ended, access locked, malicious rules removed. Then we clarify together: what was reached, who must be informed, what prevents a repeat.

## Related topics

- [IT security overview — operations plus protection blocks](/en/services/it-sicherheit)
- [Endpoint protection (EDR) — the guard on the device](/en/services/endpoint-schutz)
- [Microsoft 365 — licences and administration](/en/services/microsoft-365)

