inforcer has announced the general availability of inforcer Threat Detection and Response (TDR), its Microsoft 365 security platform designed to help MSPs detect and contain threats across multiple customer tenants.
inforcer TDR expands Microsoft 365 threat detection
The launch follows an early access period that began in June 2026. According to inforcer, more than 700 MSPs have since used TDR across customer environments, with 500,000 users onboarded in its first four weeks and 20 billion Microsoft 365 logs processed to date.
Matthé Smit, chief product officer at inforcer, said early testing highlighted previously unidentified threats, lower alert noise, and the importance of customer reporting.
“TDR is surfacing threats in customer estates that partners did not know were there, which is sobering to hear and exactly why we built it,” Smit said. “Second, it is quiet, so it earns a technician’s attention instead of draining it.”
Smit added that reporting helps partners show customers “what happened, in what order, and what was done about it.”
Multi-tenant visibility supports MSP security operations
TDR draws telemetry from across Entra ID, Exchange, SharePoint, Teams, Defender, and Purview to provide context beyond identity activity alone. The platform can also analyze up to six months of historical Microsoft 365 logs to investigate incidents and identify potentially overlooked compromises.
MSPs can view incidents, security trends, and prevention activity across customers through a multi-tenant dashboard and export customer-facing incident reports.
Automated containment targets MSP response times
inforcer is positioning AI analysis and automatic containment as a key part of TDR, particularly for MSPs that may not have technicians monitoring customer environments around the clock.
The platform uses a behavioral engine to profile users, Entra applications, tenants, and MSP environments for patterns and anomalies. When it identifies a threat, TDR can automatically revoke active sessions and lock or disable compromised accounts.
According to inforcer, TDR detected thousands of threats during a six-week period and reduced average containment time to less than 60 seconds.
The company said TDR’s automated capabilities are supplemented by a human security operations center (SOC) team that can provide additional threat verification and guidance when needed.
inforcer positions TDR between alerts and 24/7 SOC services
Early customers have highlighted both TDR’s incident visibility and automated response capabilities as potential benefits for MSPs.
Ruben Ven, modern workplace consultant at Yellow Arrow, pointed to the platform’s incident timeline and reporting capabilities.
“The timeline is chronological and the contain, remediate, and advise options are really clear,” Ven said. “I also loved the export report function. It looks great visually. For a lot of MSPs, this would be a perfect product.”
Meanwhile, Tom Lovell, chief technology officer at Infinity Group, emphasized the solution’s automated containment as a potential middle ground for providers that do not offer full 24/7 security operations.
“It is plugging a real gap between unmonitored alerts and our expensive 24/7 service,” Lovell said. “The value-add of after-hours isolation and containment without a full 24/7 service fee is huge.”
For MSPs, this could provide another option for extending Microsoft 365 security coverage after hours without operating or outsourcing a full 24/7 SOC.
UK MSSP Reliance Cyber recently launched its RADAR agentic MDR platform, using AI automation to support alert triage and detection engineering. Read more about the platform and its role in security operations.





