Our Product experts, Matthé Smit and George Cochrane, break down what's new and upcoming in the inforcer platform in Q3 2026, and how these updates will help you deliver even more value to your customers.
inforcer Product Roadmap webinar: Q2 2026
Our Product experts down what's new and upcoming in the inforcer platform in Q3 2026, and how these updates will help you deliver even more value to your customers.
Matthé: Hello everyone. We're going to give it 30 more seconds before we officially get started. Nice of you to join. I see all the AI meeting assistants trying to get in as well. You know what? We're going to allow that today. See? Yeah, I think we're going to get started. Hello. Good to see all of you.
Matthé: Welcome to the Q3 roadmap update. I'm looking forward to this one. We have a packed hour for you today. I know you have a busy day generally, so I really appreciate the time that you spent with us today to learn more about what's happening in the world of Inforcer. If you're a normal person and not like me or George here, you might have missed a whole bunch of stuff, because your world doesn't always revolve around Inforcer. You might have taken a summer vacation even. So sit back today, we'll talk about everything that you might have missed and everything that's coming up soon.
Matthé: So if you've been with us before, you might know sort of the program. What we're going to do today is take you through some of the Q2 highlights, some of the things you might have missed, and then we'll talk about what's coming up soon. And there is plenty of time for Q&A. And when I say plenty of time, make sure to put all your questions into the chat or the Q&A panel. We also have Roy here to help answer some of them. And at the end of the session we might also have some time available to answer them live.
Matthé: Today, again, we have a lot of stuff to go over. We have big features. We have four demos. So it's going to be interesting. If I haven't met you before, I'm chief product here at Inforcer, and today I'm with George, who's our principal product manager. We're going to talk about and demo everything that's happening here. So, let's jump in.
Matthé: But before I talk about all the individual features and really cool updates that we're working on, let me sort of paint the picture a bit. Because for some of you who have been with us for a longer period of time, you've seen us develop into much more of an M365 management platform for MSPs, right? And that's been deliberate. That's the strategy. Over the last year you've seen us add so much support for different Microsoft products, but also many different capabilities like the assessments, the user management, Copilot management, REST API, PSA integrations. And today we're going to talk about some really interesting things. We're going to talk about the app management that we're adding. We're also going to talk about the detection and response engine that we're launching in September.
Matthé: So yeah, the strategy for us is to build a platform, also because most of the MSPs that we work with tell us that they prefer fewer point solutions and more solutions that help them with a lot more, so you reduce the number of things that you have to deploy and manage. Now, in the last year or so — hey, what's happening there? I'm suddenly missing a column here. We definitely released things in August of last year. I think the story here is that every single month, for the last year or more, there have been major new additions, new policies that we've added, and the velocity of the product is really, really high.
Matthé: There's a lot of work going into Inforcer. Before we talk about what we're promising for the future, it's always good to look back and see that we've actually delivered a whole lot every single month. So, let's talk about some of the recent highlights. Recently, we've added a lot of great stuff. And when I say recently, let's review the last three months and talk about everything that was changed. And the first one I need to call out is the multi-tenant policy alignment feature.
Matthé: Multi-tenancy — and I hope you've seen this already, we'll do a quick demo in a second — but this is the number one MSP feature, the way I see it. The feature is really the ability to deploy one policy to, and actually check the status of one policy in, all your tenants, or see the alignment for that specific policy across all your customers. It's such a powerful feature. It landed extremely well. Again, I just want to make sure you are aware that we released this and you're not sleeping on it.
Matthé: But there's more. Many of you have been asking for more features around user management, and in the last quarter — and I'm specifically talking about Entra ID user management — in the last quarter we added a lot there. Especially the scheduled user offboarding went down really well. What is it, eight weeks ago? The ability to say, hey, that user is going to need to be offboarded at the end of the month, and scheduling it now. It's been working flawlessly with the new scheduling engine. The ability to reset or set a temporary access password that now also respects the policy has been used quite a bit. So yeah, a lot of enhancements there.
Matthé: And then also in the last week we added the improved onboarding experience, which includes scheduling. So, the ability to create a user on a schedule, but also the copy-from-existing-user functionality. And on top of that, we've also just made the whole experience much more integrated. So, instead of you creating a user and then having to add groups and licences later on, it's now all part of one single flow. And that was only a week ago.
Matthé: And also — it still feels like a long time ago now — we added the back-then number one feature request, the public onboarding link, with the ability to onboard tenants with read-only permissions, especially for prospecting. This is wonderful, right? You can send people a link and say, 'Hey, go onboard your tenants yourself. We don't need your GA permissions. We'll only ask for read-only.' And then through that link people can do the whole onboarding themselves. There are many other use cases for it, but this is an incredibly powerful feature and you should absolutely be using it. So you know what, let's do a couple of quick demos in case you have missed anything here, and then we'll go back and talk a bit more about this. George.
George: Absolutely. So, let me jump in. And for those that have seen these new features, I'm going to try and add in a few power-user top tips and tricks as well. We're going to kick off actually while I'm in user management. We're going to kick off with the new align by policy. And I have actually bookmarked a page that I want to use as an example for this. So, it's a nice little mini feature of command launcher that you can bookmark pages you like to come back to. And you'll see it's just underneath align by tenant.
George: And if you're used to align by tenant, you'll see that essentially the axes have been flipped on this graph. You've got your policies down the left, and you've got the customers and how they align to it in the middle. We do combine — if the exact same policy is in multiple baselines, it'll only show up once — and we'll show you from which baseline this particular tenant requires that policy or setting.
George: And from there, you're basically in home territory again. Once you've found the deviations, whether you like it by table view or by grid view, this is now saved to your local cache, by the way, so it will remember next time you get to this page. You can actually also use left and right arrows to have a look through all the tenants and see what properties are different. I like to do that so that by the time I've reviewed everything, if they're all just good to ship, then I can select all and align.
George: And even a small thing here: we removed any unnecessary steps in deployment. This is a setting. There's no variables, there's no assignments. So we took out about three or four clicks in the deployment process there. So that is align by policy.
George: I'm going to show you one more cool thing. And for that, I'm going to just clear the type-based filtering and find a policy that I named a while ago. And I kind of wish I'd given it a different name. For those that have been around for a while, I'm sure you might have felt this. You came up with a great naming convention and now you need to adjust it somehow. Well, if I was to go and rename this baseline policy, all of my aligned tenants — which admittedly I only have two of in this test database, but you can imagine tens and hundreds of tenants that already have this policy — you'd actually lose the connection and have to click rename to baseline 100 times to get them back connected to this baseline policy.
George: So, we made a little tool. It's hidden away in a three-dot menu because I don't want people using this accidentally. But this is a tool that will rename your baseline policy and all customers that also have this policy. So I don't know, maybe I just rename this to compliance and off it goes, renaming those particular policies. Okay. Could take a little while if there are loads of tenants, but still way, way faster than renaming to baseline times 100.
George: So then I'm going to lazily refresh the page so I don't have to wait for that. I do not care about my customer tenants. And next we are going to have a quick look at some of the new user management features. So once again, I'm going to Control-K, use command launcher to jump to a certain tenant and then to a certain list of users. And I'm going to pick out someone called Jack West here.
George: So this user — you'll notice we now have granular auth methods, so that you can remove or reset passwords and temporary access passes from here. Temporary access passes, as Matthé said earlier, respect the policy configuration that you've got on this tenant. It's a really handy one. And when you come to offboard a user, there is now the option to schedule as well. And that will ensure that you don't have to sit up until 6 p.m. on a Friday. I'd say sit up — hopefully, you're down to the pub or something by 6 p.m. on Friday.
George: One last thing to show on user management is that you can now, as you create a user, fill in their group membership and their licence assignments. If I copy — let's copy Jack. Actually, he had some stuff configured. Okay. Didn't actually have much configured. Manager is a new field that we missed off, for some reason, in the first version of user management. So you can now configure and copy manager. And yeah, just obviously a very common request from your end customers saying, oh, there's a new employee that's starting on the same team as Jack, could you copy that user and their group assignments and things.
George: And then last but not least, I just wanted to touch on that onboarding link that Matthé mentioned. This is essentially a new way to add tenants to Inforcer. You've got global admin, which is passable but not the most scalable. You've got partner center GDAP onboarding — that's still the best option for working at scale, managing loads of tenants. But on the odd occasion that you don't have access to the global admin credentials for a tenant — for example because they are a prospect, and you want to onboard a tenant with perhaps read-only permissions, with an expiration on the enterprise app — you can now create this onboarding link. It's a static link, but you can rotate it if it gets into the wrong hands.
George: And we're seeing a lot of people successfully using this to just run some assessments and really identify the Microsoft 365 gap that end customers have. Let me cancel out of this and just show you a quick example. You'll get a page here where you can put in your admin@lego.com global admin credentials, and my friend at Lego would have to authenticate their tenants, but we don't need to ask them awkwardly for their global admin credentials. So, just a nice optimisation there to help you get prospects onboarded, or for those scenarios where maybe you've got a co-managed setup and the customer doesn't actually want to give you a global admin on an ongoing basis. That was a lot, but that's just what we've done recently, and we wanted to save time for all the cool stuff to come.
Matthé: Very cool. Just a reminder for everyone, put in your thoughts or questions in chat or Q&A. We have a high pace today, so you might not even have time to type. So please try. Anyway, thanks — great demo. But wait, there is more, because there's more to talk about.
Matthé: For those of you who are using a PSA like Autotask, Halo or ConnectWise, you had the integration already, of course, for alerts to tickets. We also see an increasing amount of ServiceNow customers, especially on the higher end of the market. Apparently there are two versions of ServiceNow, ITSM and CSM. That is now also supported. We launched that last week. So make sure to enable that. It's much better getting your tickets right where you are managing your tickets, rather than email. So, good news for you.
Matthé: And there's more. We are, of course, still very much focused on adding more policies and settings to the product. You've probably seen us increase the velocity there quite a bit throughout the year. I'm still surprised how much there is that we can still add. We are still working through a long list of things that we'd look to add, and we're always looking for your feedback around that to help us prioritise. Microsoft 365 is incredibly deep.
Matthé: Anyway, recent additions that you should probably take advantage of are the following. The local admin settings, where you can now, for Entra ID, control who gets admin rights when you onboard a new device. The system-preferred authentication helps you nudge people into a more secure way of authenticating. So it pushes people into the most secure way possible. We've added more around Purview. The foundations for insider risk management are the settings — you can now configure that.
Matthé: I think the big one, from — what is it, six weeks ago — was the Exchange org config that we now support. There are probably over 100 settings in there. Some of them are really, really important. And, as you might have seen with Exchange, a lot of that can't even be done in a UI. You have to do it through PowerShell. And now, of course, you can do that through an Inforcer policy or setting. We've grouped them nicely together. It's really, really useful.
Matthé: Some of the largest MSPs that we work with heavily rely on scope tags and Intune roles, especially to work together with their larger enterprise customers, to delineate who can do what. That's now also fully supported. So when you deploy an Intune policy, we will deploy the scope tags with that, and you can configure the Intune roles. We've added support for app configuration policies, which is really useful if you do MDM, mobile device management, for iOS and Android and — what is it — watchOS and iPadOS devices. And then last but not least, the app control for business support, where you can now enforce that only applications deployed within Intune are allowed to install and run. Especially when we're going to talk about app management in a sec, that's really, really useful.
Matthé: So I think the point I'm trying to make here is that, even though today we'll talk about other things that we're building, we haven't forgotten about the core — the multi-tenant policy alignment, the new policies, the new settings. We're deeply investing into all of that. One thing that I wanted to highlight is the change around Defender custom indicators. You might have seen the update last week. I do want to flag this. Custom indicators are extremely powerful, of course, and some of you go crazy with this.
Matthé: So I think you're allowed to support 15,000 different indicators in Microsoft. Some of you, I think, are approaching that number, especially if you do multi-tenant policy alignments. You can hit crazy numbers, and every time we've seen some kind of latency or timeout, it was definitely around custom indicators. So we've changed this. Now, instead of being handled as 15,000 unique policies, they're now grouped into four major categories: IP addresses, file hashes, domains, and certificates. And they are aligned in those four buckets.
Matthé: Much easier to manage, much less impact on your alignment score. However, it's a new policy type. So, you need to update your baseline and add the new type and remove the old custom indicators. And then we will keep the deviations that you've set. It's not going to impact you in any other way. And over the next couple of weeks — I think in four weeks — we're going to remove the old custom indicators. So, I just want you to be aware.
Matthé: All right, there's more. So much more. Quick, ugly slide here, but a couple of things to highlight. The work around our blueprints and baselines is ever ongoing. So recently we added new projects for macOS — the core and advanced enhanced projects — which should help you deploy Intune to Mac if you're not doing that already. We've added new assessments, and we've updated existing assessments, especially for the EU folks here on the call. NIS2 hardening is a new assessment that I think you should check out.
Matthé: George already showed you that wonderful new command launcher. That is just really, really cool. The configurable SSO force authentication still doesn't really roll off the tongue, but it was actually a very highly rated feature request, which allows you — especially if you use the IDP integration, right, so you log in through Entra — it allows you to persist that, and you don't have to log in every single time when you log into Inforcer.
Matthé: We've added more capabilities to our REST API. All the reports and assessments are now available. We've added more buttons, also on the request of some of our customers, to the tenant dashboard, to jump straight into Azure or the Power Platform. And yeah, a whole lot of UX improvements: collapsible navigation, the new themes. There was just so much in the last period. It's hard to stay on top of that for you. But I know this is not why you're here today. You're here to also hear about what we're working on and what's coming soon. So, let's spend the rest of the session talking about that. And I'm going to actually hand it off to George to talk a little bit more about some of the exciting things that we're working on.
George: Absolutely. So, we're going to kick off with two big ones. The first of which is RBAC. Now, I would say that the permissions behind a system are typically not the sexiest feature, but we're all techies. We know how important it is to give the right level of access to the right people. Our job, day in, day out, is security, and giving the least privilege to the right user is a fundamental pillar of that.
George: So, it will behave very similarly to existing RBAC roles. You can essentially think of it like this: the existing engineer role we have will now be split out, and there will be all of the individual components for you to choose between. And we will, of course, migrate your existing RBAC groups into the new system as well. So it should be a very straightforward migration, and it will just allow you to take care of all of those little niggles. We've had lots of people saying, ah, I do like the engineer role, it's mostly there, I just wish that they could also manage a baseline, something like that. So, do you know what? I think I'll just jump in and show you. It won't take very long. It's pretty straightforward.
George: There is also a lovely bit of detail that the engineers have put in regarding the dependencies. So let's say we're creating a brand new role and we want to start with a read-only level, but when it comes to users I think this will be maybe a level-one engineer that can do some of the basics of managing a user. And, for example, if I say manage, that is going to be all of the facets of user management. But if I just want them to edit groups and to be able to revoke sessions for some reason, then of course I've got that granular control. And there's quite a few places here where there was previously the ability to do all of this stuff or none of this stuff.
George: And of course — excuse me, I'm losing my voice — it's all just nicely broken out now. There's also a lovely detail about — let's pretend we were an engineer — you can use the search as well, which is a great way to say, oh, I'd like this engineer to also be able to edit licences on Inforcer tenants. That was not previously possible, but just a small tweak from the existing role template and you're there already. So that's the deal. Otherwise the tenant scoping is the same, and you can still layer up RBAC roles to give everyone a minimum access level, and then add extra privileges that will accumulate for a specific user.
Matthé: Yeah. I mean, this is probably the least sexy demo that we're doing today, but it's so incredibly important. And in the session this morning, people also said it's so easy to forget about RBAC as a vendor, right? Because it doesn't always demo all that well, but it's so important, and especially if you see us do more. Already we're doing user management. Well, if the platform goes into device management or other areas down the line — the more powerful the platform gets, the more important this functionality is. So, great job to the team that worked on that.
Matthé: So — oh, let me move this out of the way. So, that was a nice demo, George. But you're not done yet. Can you talk a little bit about app management?
George: Absolutely. So, Intune app management: the ability to deploy apps to many Microsoft tenants. Why do people consider this as a method? Look at all the applause coming in. I don't know if that's a few people spamming the applause button, but why do people care so much? Why are people clapping so much for Intune app management?
George: Well, the most obvious thing is that keeping apps up to date is just a part of our responsibility as IT providers. There is a new CVE every week. Even things like Notepad++ are having vulnerabilities found. I think AI is doing some real damage into the vulnerabilities of apps that we previously thought were safe. Now, we need to get those updates out to all tenants all at once, and have the confidence that it's done right.
George: We need to deploy apps through company portal because we really don't want users to be local admins. That is far too much privilege. That's far too much risk, just to avoid the ticket coming in and the user waiting around for a team share for you to install an app on their behalf. We have some real magic by using the Microsoft native tools. Things like Autopilot enrolment is just a lovely quality-of-life feature. It really impresses a user when they log into their laptop for the first time and all their apps start installing.
George: But also there are things like your RMM agents and your antiviruses and your VPNs and things that can be useful to use in Intune, as just a rock-solid way to get your other management agents out there. Especially if you're using Autopilot, that first login just gets all of your standard agents out. No more shipping a laptop to yourself, plugging in a thumb drive, uploading all your agents, etc. So that's why we cared enough to get solving on this problem.
George: But as we move to the next slide, I want to emphasise that we have a mindset, as Inforcer, driven by the engineering team, which I love. And it is: we should focus on what we're best at. And in our world, that is reading and writing to Microsoft APIs, that is understanding the Microsoft 365 challenges that you as IT providers have — with our lovely, now up to three, Microsoft MVPs, which I will always celebrate. But honestly, one thing that we're maybe not specialists at — well, we have some people that will be good at it, but they have day jobs — is packaging up apps to always be up to date and always be available, especially with this sheer volume of apps that are out there.
George: So we have partnered with a wonderful company called Devicey. They are a fantastic toolkit for Intune device management, and they specialise a little bit more into the enterprise space, but we have been working with them for a long time. Fantastic experience on their side. We're licensing their app catalogue to be available inside Inforcer, so that you can take over a thousand common apps — which I think that list is growing to a few thousand very shortly — and just have a really easy mode of adding apps to tenants and knowing that they're going to always auto-update.
George: So we have a handful of other features: the ability to manage custom apps, the ability to template out the assignments of those apps, and the ability to pass custom install strings so that you can put in your custom IDs. But I think it's going to be better for me to just show this. So, I'm going to jump straight in. Let's share the screen again.
George: Very well, into your Age of Empires deployment. I think we all want to deploy Age of Empires. I would also love to do that. I fear that there might be claims of piracy — although Age of Empires was originally published by Microsoft. It was their first kind of AAA game. So maybe we're friends enough with Microsoft that they'd be cool with that. I don't know. So here we are in the Intune app catalogue. This is your MSP-level view.
George: So from here you've got all of the apps that are deployed out from Inforcer to customers, whether they are sourced from our catalogue or made custom, like my Age of Empires here. To add new apps, you're either going to just search for it in the catalogue, such as, I don't know, Tailscale or something. There we go. And simply subscribe to it.
George: Or if it's not in the catalogue — and of course there will be really bespoke line-of-business apps, or things that are typically maybe behind a paywall where you're not able to just download an RMM agent off the internet, you do have to have an account and go and get your own agent — for those we have 'add custom apps'. At first release it is going to be IntuneWin uploads, but we're working with the Devicey team; they have this awesome packager technology where you can just upload executables or MSIs. It will even use PSADT, for the nerds out there that know what that means — just an extra wrapper for a good customer experience.
George: But for now, I'm going to upload a quick example. My demo folder — I thought I set up a hotkey to quickly get to my demo folder. And now I fear I might have to... Okay, I should probably not open my files on the fly. Excuse me one second while I stop the screen share and find—
Matthé: Yeah, look, it gives me time to answer two questions already. There's one feature that George will demo a little bit more. We're primarily focused on managing Intune apps in the tenant, right? We're not looking at the device level yet. We're not scanning vulnerabilities. We're not looking at what else is installed on each endpoint. We're very much focused on the Intune app library, as you see it when you log into Intune. But that packaging experience is extremely painful, as you probably know, and many people use additional tools for that. So that's what we're solving for here.
Matthé: The second one — and before George starts his demo again — already I see a bunch of questions around licensing. I just want to tell you this one. The feature itself, the ability to deploy a custom app, all the tenant views that George will demo in a second, that's part of the core product; you're going to get that as part of Inforcer. The library is an add-on. It's per MSP, it's not per endpoint, it's not per tenant, it's pretty low. You need to license it. It gives you access to the device library, because we have cost for that as well, but that's an optional add-on that you can decide to buy.
George: Absolutely. So I've just dragged in an IntuneWin here. I'm going to upload the icon as well, for prosperity, because this was an MSI that we packaged up. All of the details about the install command are prepopulated. The detection rules will also be prepopulated, but I'll just mention here that this is where you can put in — perhaps it's a customer ID equals — and then either use one that you already have or create a new variable for a licence ID. I'm running out of synonyms for this.
George: And once you've done this, it will now appear as an install string in the left sidebar, where you can go and fill in the correct value for each tenant. Okay. Matthé and I both came from the RMM world before Inforcer, and we know how valuable it is to make sure your agents install and map to the right customer, especially for RMM and antivirus tools and backup tools.
George: So, simple as that. It's going to take a second to process, which, if I'm lazy, I might not bother waiting for. But from there, you simply take the apps that you want to push out. I will take — let's take Audacity — deploy selected. Pick out whichever tenants. We will automatically grey out tenants that don't have Intune, of course. Let's pick another random one.
George: And here's where you decide: will this app forever be linked to the catalogue? So every new version in the catalogue — which you can still do with custom apps as well — will auto-update to the tenant. Or just a simple no version control; it should be pinned as it is.
George: Now, here is where I didn't create group templates on the demo, but you'll see I have a list of groups here that I've templated out. The idea is you can't predict which groups every single tenant will have, but we can create our best naming convention of security groups, and then, once the app is finished deploying, you just need to go and put the right people in the finance team apps group. And of course you can still use all users and all devices too.
George: So really straightforward, that will push out. We can watch the progress and see them firing off to Intune. And that leads us to the last point, which is that now, at an individual tenant level, we can go and check out Intune apps per tenant. So from here you've got both the apps that we've deployed, and also a whole bunch of apps that I added manually while I was playing around and testing.
George: So, if for example we've got the Inforcer-managed version now, we don't need to have this old version. To be honest, none of them are actually assigned to anyone anyway, but I could clear out the test versions of Adobe Reader that I was playing with, and instead just use the managed version. From there, of course, you can still come in and assign all users available, put it in the company portal, that sort of thing. So just a simple toolkit.
George: If you're doing anything too advanced, then we've just made a shortcut to see this in Intune. It is a partner center GDAP-compatible link, so you just log in with your partner center user and it will take you straight to this app. So that is Intune app management. And, again, great to see how many people are excited about that one in the chat. I will probably start prodding around in the questions. I think I'm handing back over to you, Matthé.
Matthé: I think so. I mean, you did mention that you can manage the assignments and everything from there, right? I think for some of you, you might be new to Intune app management. Definitely drill into that. But yeah, you can definitely control whether or not an app is actually forced on an endpoint, or if it's only available through customer portal. You can even uninstall it. It's just an extremely versatile and powerful feature. I love how the team integrated that into the product.
Matthé: So that was Intune management, but there's more. Oh, that's the demo slide. There are a couple more things to talk about. You know what? I'll talk about this one, George. The auto-remediation of policies has been a top feature request, and a top thing that we want to do, for quite some time now. Of course, when a policy changes right now in your tenant, you will see a deviation. You will get an email saying, hey, someone changed — or a policy was changed, right? You have the daily snapshot emails.
Matthé: But of course, people want more, right? What if that policy that was changed was a critical security policy? You kind of want to flip it back to the previous state. Whoever made the change — it shouldn't happen, and it needs to be flipped back. So that's what we're building here with this feature. So what you can do is you can go into either a tenant, or look at a specific policy, depending on which view you pick, and you say, this policy, or this set of policies, is now locked and you can't change it anymore.
Matthé: And well, you can still go into the Microsoft portal and change it, but the moment we detect that — and that will be very quickly, it's not going to rely on the 24-hour backup schedule that we have today, it's going to detect that within minutes; I'm going to set the expectation of 15 minutes, hopefully we can do better — as soon as we detect that, we're going to revert it back to the previously aligned state. So if you had a deviation for that specific customer, it will still revert it to that state, not the baseline state. And of course we'll also send an alert and a notification saying someone changed this policy, but now we've reverted it to the previous state.
Matthé: And yeah, you can pretty much lock a ton of policies, all policies, in place, if that's what you want to do. There might still be good reasons why people change a policy, but it's a very powerful enforcement engine. This is in progress and we're looking to ship this in September.
Matthé: I think, by the way, I saw a couple of questions come in around app management earlier. App management, what George demoed, is looking to go out in August. Same thing with RBAC that George demoed before — also still this month. So big things coming this month.
Matthé: Also for September, another really, really cool feature called scheduled CA exclusions, also known as vacation mode. Here's the thing. You might have a great conditional access policy and you say, well, customers can only log in from these specific countries, but then someone needs to travel, and making an exception for that specific user is a pain, right? It's just not great to manage that in either one of the Microsoft portals, but especially because many people forget to revert the exception that you've made. So you end up with either users or groups being excluded from critical conditional access policies forever, without you noticing it.
Matthé: So what we're going to do here is you select a group of users, or a user, and say, from this moment to this moment that user needs to be excluded from these policies. And we're going to create a schedule for you. We're going to create the exclusion group if it doesn't exist already. We're going to put a user in that group, and that group is going to be excluded from that policy for that specific period, and at the end the user will automatically be removed. You don't have to think about it. It's a great feature. It's a big time-saver for people in technical support.
Matthé: Again, for September. And then also for September — and this is the big one — Inforcer threat detection and response. Some of you might already be in early access. We launched early access roughly six, seven weeks ago. We're getting a great response on this. It's a wonderful new product addition to the Inforcer stack. If you don't know what I'm talking about, let me give you a bit of an introduction in like five minutes, and we'll do a quick demo.
Matthé: But Inforcer threat detection and response — we've built this for a number of reasons. One: even with all the policies in place, like MFA etc., we still see that breaches are common and, like, invisible. So what that means is that users are still the weakest link. There's a lot of business email compromise. There's a lot of man-in-the-middle session hijacking. There are many things that we see happening even with policies in place, and they're just very hard to prevent. And they're only getting better with AI — it's becoming much easier to convince people to click on links.
Matthé: But what we also see is that when an attacker is in, they leave all these footholds behind in your tenant — forwarding, enterprise apps, etc. — and they might be in there for months. If you don't monitor for this, they might be in forever. But what we also see is that monitoring for this is really difficult to do well. We've had an alerting engine, and people asked us to add specific alerts for this for like a year, but what we've noticed quickly is that if you just start to detect something like an IP address change or an email forwarding rule, you end up with an extremely noisy engine. And the problem with noisy security tools is, well, you don't need more of them, because the end result is you start ignoring all those alerts.
Matthé: So, and the last thing is that what we see with many MSPs is that prevention and detection are two separate worlds. So you might detect a breach, you might fix whatever happened there, but it rarely leads to better policies or prevention at scale. And on the flip side of that, prevention — stopping things — is very hard to show the value of to your customers, right? It's something where you have to present the absence of an attack. But by combining the two worlds, you now have a much stronger story around prevention, and detection will lead to prevention. So that's why we built Inforcer TDR.
Matthé: What is Inforcer TDR? It is an engine that we've built on top of the Inforcer platform. So it relies on the enterprise app that we have today, and it sits within the Inforcer UI, and RBAC and everything. But it is also available as a standalone. It is a real-time detection platform for things that happen in your tenant, specifically around users.
Matthé: And we do a lot of different things. We have very sophisticated rules, including behavioural profiling. So we know when, like, George logs in, what his normal location is, what his apps are, what his behaviour is. And we know when it's different. But there are many sophisticated signals that determine if you are compromised, and we are able to remediate. What we're seeing today is that a lot of the damage gets done in the first 10 to 15 minutes after a user is breached. Our job is to stop that breach within a minute or less, right? And we have a very sophisticated engine to help you automatically respond: revoke the user sessions, lock the user, remove apps, remove forwarding rules, and do all of that automatically.
Matthé: But we've built this with MSPs in mind. So, it's all multi-tenant. You have multi-tenant threat management, log management, visibility, and also great reporting. There are a lot of options here to show value to your customers, either through these wonderful maps but also great reports that we've built. The way we work: we capture a lot of log files, a lot of things from across the tenants. It goes way beyond the general activity logs. It's also Purview and SharePoint and other areas. And we look at this all the time across all your tenants, and we detect if there are indicators of compromise, through both our SOC and our AI engines.
Matthé: We focus a lot on noise reduction. And then when we have multiple indicators, or things that together make up something that we're absolutely sure of — that is a threat — because we built this incredible threat timeline, we're going to contain, either automatically or, if that's what you want, you click a button and contain it yourself. We're going to do that from within the product, and we're going to create tickets in your PSA if you use a PSA. And then from there, we're going to also help have dashboards and ways for you to deploy better baselines, better policies, and help prevent things at scale moving forward.
Matthé: So, let's do a quick demo. I know some of you might have seen this, or are even using it already. George, would you mind sharing your screen again?
George: Cool. So if this is coming, I'll give you control as well, just so that you've got freedom to click around.
Matthé: Awesome. Yeah, there we are. Love it. So, okay, well, we landed at this wonderful homepage that shows me the multi-tenant view. This is all my customers and all the login sessions and all the failed logins that are happening. Sometimes that's an eye-opener for people already. Like, holy — are we... I shouldn't curse here — but are we seeing people log in from Argentina? We don't have people working in Argentina. How's that possible?
Matthé: But you can drill into your open threats, right? Open threats are the things that you really don't want. So let's see if — let's just open the first one, right? What's going on with the first one? So, what we're seeing with this threat: it's not a single alert that made this threat. It's a whole lot of things. Sometimes you'll see things like brute force attempts, or people logging in from Tor nodes, or — well, someone added a mailbox forwarding rule here. That's not good — to mary@techthreats.co. Well, that's definitely something of an indicator of compromise.
Matthé: Sometimes there's, like, impossible travel. There are all these different things that we're seeing, and together we're building this great story. If the timeline is a bit long for you, and you can add notes, you can contain things from here. We do have an AI analysis, and depending on what we're seeing here, we're going to show you what emails were accessed, what files were accessed, and that is all available also for you to export, which is great for security audits, etc.
Matthé: So there's an AI analysis there. There are ways for us, or for you, to contain. You can run that from here, or, depending on your setup for the tenant, it will happen automatically. And then this is what the system will do for you. And your job then is to remediate, bring the user back up and running. That's not something Inforcer will do for you. You're going to have to re-enable the user to login and reset their passwords, etc. And then there's advice that we give you, either improve policies or review this, etc.
Matthé: This is a very brief demo of what you can expect from this technology. I'm not going to do it justice today because we have so much to talk about. But this is an amazing, amazing feature, and we're launching this in, well, a few weeks. We're pretty close. So I'm going to — oh, move this out of the way. Two more things, actually.
Matthé: One: it comes with great reports, right? So you are able to then go in and say to your customer — because we also fetch information from, like, the last six months, if the logging was enabled — you can say, in the last period you've been breached and people have been in your tenant. You have active attacks going on. Attackers are reading emails. They have back doors. There's a whole story here.
Matthé: And you can — let's see if I can find some good examples here. So, in this case, like Leonardo de Crypto — I mean, with a name like that, you're kind of falling for it. But anyway, Leonardo de Crypto, he was compromised. You can see what the attackers did. And there's a whole story that you can share with your customers. And yeah, there's a lot that you can get from Inforcer TDR that way.
Matthé: Quickly to wrap this up: Inforcer TDR is an add-on, or a standalone product. It's licensed per user. And this is not, like, all the users in the tenant — only the ones that have a Microsoft licence and a mailbox, right? So, not your admin accounts or service accounts. You don't need an Inforcer tenant licence. You could even use no licence, or the tenant assessments licence, if that's what you want. And it works well with all M365 tenants, right? So if you have business basic or above, it will work.
Matthé: We are primarily focused on identity and the tenant, not yet on the endpoint. I do want to make that clear. We're not using Defender for Endpoint telemetry with the current product. And it's going to be available in September, early September. So, if you haven't signed up for early access, visit the website, or let your PSM know, your account manager, that you're interested in this, if you are.
Matthé: All right. So, God, time flies. I do want to mention a few more things, because you're going to ask in chat, like, hey, in the last webinar you spoke about this, you didn't cover it this webinar — did it drop from the roadmap or something? No, but we also had to prioritise what we're going to talk about today. So, what are the things that either are in development, or in design, or in planning for the remainder of the year? A couple of highlights.
Matthé: Again, there's more. SharePoint management is something that is getting a lot of validation from our customers and customer advisory boards. It's almost the extension of what we've done with Copilot management. And this is something that you can expect from us later this year. Intune device management is almost an extension of Intune app management. We're going to look at devices and do a lot more there.
Matthé: For the larger American customers that we have, they have a lot of tenants with GCC — that's the governmental cloud, the secure enclave in Microsoft. We're going to support that in Q4. For people that do a lot with our user management today, one of the common asks is: do more with hybrid. Well, the first thing that we're going to do is at least show, and change the behaviour a little bit, when a user is actually managed on the local Active Directory.
Matthé: So, it's hybrid, but then local AD is in the lead. If that's the case, you're not really going to be able to make any changes in our user management, because it's not going to stick. So we're doing work there. We're also doing a lot of work around reporting, making it easier for you to show value. We've done a lot of work around even instant reports in the last week, but we think we need to improve our existing reports quite a bit.
Matthé: And then last but not least, we're making it easier for people to deploy recommendations with a single click. So instead of us giving you an assessment and saying, hey, you need to deploy this policy or turn on this setting, that's going to be a one-click thing, if that's what you want. I think that's going to reduce the barrier to entry for some of you to Inforcer. So there's a lot going on. And I think we have a few more minutes to do Q&A. If you have to drop off, I know you're busy.
Matthé: Make sure that, if you have feedback, you let us know. From within the product there is a feedback and roadmap button. You click on your icon and click on feedback and roadmap. We do read this, and we look at the votes all the time. If you look at what's on top of the list, it generally gets delivered, right? So, make sure to vote, leave comments. It really helps us prioritise the roadmap. But, George, are there any outstanding questions in the chat that we should talk about?
George: Roy has been doing a brilliant job of answering many of them. But there's been a few questions on what the cost is for Intune app management. And while the precise cost hasn't been firmed up for every region yet, it is going to be, (a), very affordable, and (b), a nice, simple, flat cost for you as an MSP. We're not wanting to add complexity to your billing process with yet another per-device cost or something like that.
George: So, we're really just looking to cover the Devicey licensing cost and the cost of our storage. And actually, egress is probably more than storage. If you're deploying a few gigabytes of apps to many tenants, then the data coming in and out of Azure tends to be a bit more expensive. But yes, compared to what you might see of other products, I think we are going to be incredibly cost-effective. And I'd like to think we are a little bit more MSP-focused in how we've solved the problem here.
George: Other questions — there's quite a few people asking around SharePoint, storage alerts, and tools to manage permissions and things like that. What are your thoughts on our SharePoint manager tool?
Matthé: I'd say stay tuned, right? There's just more coming. We're seeing a lot of interest in the work we've done around AI and the readiness reporting, etc., and that leads to a lot of work around SharePoint and Purview. I think last year people thought they were boring topics. Now everybody's all over data management. So definitely expect more from us a little bit later this year, including reports and management and alerting.
Matthé: I see a question from Jamie here: will Inforcer have a managed SOC? TDR has a SOC component built into it, so we have humans in the loop to continuously improve the engine and to answer your questions if you have them. The system itself is a fully automated engine. So, even though we have humans in the loop, it's all designed for speed, because we know a lot of attacks happen and then you can't wait for 15 or 30 minutes for a human to take an action. But yeah, we definitely have our own SOC team nowadays.
Matthé: All right. I think — there's a long scroll here. Gentlemen and ladies also on the call, thank you so much for spending your precious time with us. Let us know how we can make a better product for you. Hopefully we'll see you at the next one. We'll probably do another one three months from now. Stay tuned. There's a lot of good stuff coming. And again, thank you for being here. See you at the next one. Bye-bye.