inforcer TDR Brings Automated M365 Security to MSPs

inforcer TDR is now generally available, giving MSPs Microsoft 365 threat detection, automated containment and multi-tenant security visibility.

Written By
Luis Millares
Luis Millares
Sep 4, 2026
3 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

inforcer has announced the general availability of inforcer Threat Detection and Response (TDR), its Microsoft 365 security platform designed to help MSPs detect and contain threats across multiple customer tenants.

inforcer TDR expands Microsoft 365 threat detection

The launch follows an early access period that began in June 2026. According to inforcer, more than 700 MSPs have since used TDR across customer environments, with 500,000 users onboarded in its first four weeks and 20 billion Microsoft 365 logs processed to date.

Matthé Smit, chief product officer at inforcer, said early testing highlighted previously unidentified threats, lower alert noise, and the importance of customer reporting.

“TDR is surfacing threats in customer estates that partners did not know were there, which is sobering to hear and exactly why we built it,” Smit said. “Second, it is quiet, so it earns a technician’s attention instead of draining it.”

Smit added that reporting helps partners show customers “what happened, in what order, and what was done about it.”

Multi-tenant visibility supports MSP security operations

TDR draws telemetry from across Entra ID, Exchange, SharePoint, Teams, Defender, and Purview to provide context beyond identity activity alone. The platform can also analyze up to six months of historical Microsoft 365 logs to investigate incidents and identify potentially overlooked compromises.

MSPs can view incidents, security trends, and prevention activity across customers through a multi-tenant dashboard and export customer-facing incident reports.

Automated containment targets MSP response times

inforcer is positioning AI analysis and automatic containment as a key part of TDR, particularly for MSPs that may not have technicians monitoring customer environments around the clock.

The platform uses a behavioral engine to profile users, Entra applications, tenants, and MSP environments for patterns and anomalies. When it identifies a threat, TDR can automatically revoke active sessions and lock or disable compromised accounts.

Advertisement

According to inforcer, TDR detected thousands of threats during a six-week period and reduced average containment time to less than 60 seconds.

The company said TDR’s automated capabilities are supplemented by a human security operations center (SOC) team that can provide additional threat verification and guidance when needed.

inforcer positions TDR between alerts and 24/7 SOC services

Early customers have highlighted both TDR’s incident visibility and automated response capabilities as potential benefits for MSPs.

Ruben Ven, modern workplace consultant at Yellow Arrow, pointed to the platform’s incident timeline and reporting capabilities.

“The timeline is chronological and the contain, remediate, and advise options are really clear,” Ven said. “I also loved the export report function. It looks great visually. For a lot of MSPs, this would be a perfect product.”

Meanwhile, Tom Lovell, chief technology officer at Infinity Group, emphasized the solution’s automated containment as a potential middle ground for providers that do not offer full 24/7 security operations.

“It is plugging a real gap between unmonitored alerts and our expensive 24/7 service,” Lovell said. “The value-add of after-hours isolation and containment without a full 24/7 service fee is huge.”

For MSPs, this could provide another option for extending Microsoft 365 security coverage after hours without operating or outsourcing a full 24/7 SOC.

UK MSSP Reliance Cyber recently launched its RADAR agentic MDR platform, using AI automation to support alert triage and detection engineering. Read more about the platform and its role in security operations.

Luis Millares

Luis Millares has extensive experience reviewing virtual private networks (VPNs), password managers, and other security software. He has tested and reviewed numerous forms of tech, covering consumer technology like smartphones and laptops, all the way to enterprise software and cybersecurity products. He has authored over 450 online articles on technology and has worked for the leading tech journalism site in the Philippines, YugaTech.com. He currently contributes to the Daily Tech Insider newsletter, providing well-researched insights and coverage of the latest in technology.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.