See why the future of Microsoft 365 security isn't another security tool. It's a platform that connects prevention, detection, and response, helping you stop threats faster, strengthen every tenant, and prove the value of the security services you deliver.
Chief Community Officer, Will Connor, and Director of Product Innovation, Dan Harris, demonstrate how inforcer TDR can detect and contain a threat in as little as 30 seconds.
Will Connor
Good afternoon, everybody. Thanks a lot for joining so promptly.
My name is Will. I am one of the founders of inforcer.
and going to be one of your presenters today. So we'll just let a couple more people join. We had quite a lot of people registered for this one. So we'll maybe give it a couple of minutes before we get started and we'll kick off with some introductions to everybody who's going to be part of the presenting panel.
today and then we'll get rolling.
And in the meantime, I'm not going to risk live presentation mode like earlier, Dan. So Dan and I did this session for our Australian region this morning. And I tried to use the live PowerPoint mode in Teams and it was not very happy.
So I'm just going to share my screen.
That looking all good, Dan.
Dan Harris
That's good.
Ready?
Will Connor
Perfect. Let's get rolling. And I'm sure everybody can catch up if they miss the intros. So first of all, great to have you all on today. Super exciting times for us as a business and very much looking forward to talking you through a little bit around
why we decided to build inforcer TDR and why you might consider working with inforcer on this. As a quick introduction, my name is Will Connor. I'm one of the co-founders of inforcer. I've been working with MSPs for over a decade and decided with a group of other people from the MSP space to build inforcer back in 2022
really because of the conversations we'd had with so many MSPs who were looking to scale their Microsoft practice, specifically wanting to deliver more of the Microsoft security stack, but just really struggling to put that into action because of the lack of multi-tenancy. So from 2022
Up until a few days ago, everything that we'd been helping MSPs with was sort of on the left of Boom, protecting and configuring their tenants more effectively. Of course, now we're going to talk to you today about all the things we're doing on the right of Boom with our new TDR product. We've also got Dan. Dan, do you want to do a quick intro?
Dan Harris
Yeah, hi guys. Nice to meet you all. I'm Dan. So I head up the TDR product at inforcer, but I've actually been here for about a couple of a couple and a half years roughly. But I actually originated in the MSP space. So I started out at a pretty young age, kind of fixing printers and stuff, and kind of ended my career in modern workplace solution architecture.
you know, focused on fixing up, you know, enterprise and, you know, small business infrastructure, especially around the Microsoft stack. And there'll be a team of architects there, which is pretty sweet. But actually, we've been creating, you know, TDR in somewhat secret for quite a while now. And actually, I was just looking for the attendees and I'll just say hello to Chris and Clinton, who are in a meeting at the minute.
They're two of the developers that were actually quite foundational and monumental to the actual TD development. So say hello to them. I've popped a hello in the chat for you guys to say hi. Awesome chaps. And we're launching today. You know, we've been in early access for a while and it's been really good to get the feedback and get everything from the team.
as well. So I guess today is going to be a chance to really see it for everyone. So nice to meet you all.
Will Connor
Yeah, love it. And we've actually got one of our partners, Start Tech, on the call today who's going to cover, after the demo portion of the agenda, we're going to do a bit of a Q&A with both Ian and Josh. They have been long-term sort of partners of our core product and also
were one of our earliest early access partners for TDR. So they can give you some insight into their experience. Ian, Josh, you guys want to do a quick intro as well and then we'll get rolling.
Ian Groves
Yeah, I'm Ian, Ian Groves, Managing Director of Start Tech, and pretty much as Will said, we've worked with the inforcer guys for a while now and had the privilege of seeing this very early on and looks forward to seeing everyone else's reactions to the product.
Josh Upton
Okay.
But yeah, TD has been really good to have a look at early and get used to. So yeah, excited to go through some of the Q&A on that.
Will Connor
Love it. Perfect. Cool. Well, we'll get rolling. And I'm going to start with a bit of an introduction just into inforcer and also why we decided to go down this route. Conscious, there's quite a lot of partners on the call, but there's also quite a lot of people who don't work with us currently. So I want to start with just a little bit of numbers.
So as I mentioned, we founded the business in 2022. We launched the very, very first version of inforcer, which didn't have a UI in 2023, right at the beginning of the year. And it took us until probably October time 2023 to launch the very first version.
of what we would call inforcer today. And in that time, since then, we've been fortunate to bring on over 1,500 partners. So I feel like we must be getting something right. And through those partners, we are helping to secure over 70,000 Microsoft tenants. And across those tenants, that's helping to protect.
over 8 million users within 365, which is pretty cool. And it's really allowed us to have a huge amount of insight into what partners are doing well, what's missing, and where we can also add more value to their 365 service delivery.
As I mentioned, up until this week, we've been very much focused on this left of boom side of things. So helping MSPs to manage their tenants, to configure them and harden them proactively, really treating ourselves as that, almost like that RMM for 365 in terms of making sure you've got everything proactively managed and maintained.
And over the last couple of years, we've done an insane amount of releases that's just evolved that side of our platform so significantly to the point at which we're really known as one of the main vendors in this space, one of the leaders, which have also been recognized by Microsoft in their In Tune for MSPs program.
as, you know, one of the leaders in this side of multi-tenant management for 365. And for us, it made so much sense to bring left of boom and right of boom together, which is why we built TDR. And there's quite a few things both in the market as a whole in terms of cybersecurity, but also in our space in the MSP world,
which kind of drove us to this decision.
One thing we talk about a lot is this idea that the tenant is a new server. And we really, really do believe that in this cloud-based world that we live in, the tenant is business critical infrastructure. And it should be treated in that way. You need to be monitoring it, proactively managing it. Sometimes I describe it as patching, but the patches are essentially those updates from Microsoft that we have to make changes on.
And that's where our core product has really sat, focused on helping MSPs deliver that scale. But in that same world, the identity is a huge, huge security threat. It is your perimeter. And ultimately, one of the biggest challenges is that identities mostly are people. I know there's a lot of
different perspectives on what identities can be in the future with agents, etc. But these are people who click on things, unfortunately, and even the most protected, hardened tenant can be breached, unfortunately. And that's where we wanted to bring those two sides together to help an MSP, not only
deliver higher levels of protection, but also be able to tell that story better to their customers as well.
And when I started looking into this, as we were building out our platform, what's clear is that identities really now are one of the most important things you need to be looking at. Because as you can see here, two in three breaches start with a stolen identity. And that could be from compromised credentials
all the way through to, you know, adversary in the middle kind of attacks. And one thing I thought was quite interesting from this Sophos most recent adversary report is that across all the breaches they looked at, 59% of them MFA wasn't there. So that's a challenge. And that's why we need
the detections that we pick up in the right boom platform to drive our protections, our configuration, to be able to show the value of having those kind of protections in place with things like MFA, but also the wider protections across 365 that are available in the security stack. But then probably most concerning is that even when MFA was there, people were still getting through.
And that's when you need to have your extra line of defense, essentially. Just configuring the tenant isn't actually always going to be enough.
And on top of that...
The speed in which an attacker can now infiltrate a tenant, for example, is massively reduced because of AI. And even in 2021, I feel like 98 minutes doesn't even feel that long. But now the average time is 29 minutes.
and the fastest being 27 seconds, being the fastest breakout on record today, according to CrowdStrike, which is insane. And that's also why some of the tools out there today that were not built in the era of AI are struggling to keep up, because in order to react that quickly,
the tool and the rate in which your log ingestion has to happen, it has to be working at the same speed. And that's why we also took a very much AI first approach with the way that our tool works, which Dan will get into in a little bit more detail as well.
And AI is not just making the process of getting an understanding of what needs to be taken or, you know, where the important things are in an attack. But it's also just helping with the very, very beginning, which is phishing. And as you can see, 82% of the phishing emails are now
containing AI generated content. So AI is causing a lot of problems when it comes to the cybersecurity space. You've got everything from fraud GPT, which allows people a pretty cheap rate to be able to start going and building out these threats.
Now, as well as the whole process around AI and also lack of MFA causing issues, but in our space, we're seeing that a lot of the tools out there are quite noisy, especially native Microsoft tools, but also tools that sit on top can be noisy, and of course, noise gets ignored. But probably the biggest thing for me was
having prevention and detection in two different platforms means that you can't tie the data together. You can't tell the story to your customers. And in an ideal world, in what we're trying to build in our platform here is that all the things that do happen, unfortunately, the breaches that may well happen across your customers,
They Dr. prevention to stop it from happening, not only on that tenant, but on all of your tenants. You can use that data to prove the value and also to argue against some customers maybe who don't want to take your configuration across the security stack. You can use the data to show them
why it's really, really necessary.
I think one of the biggest misconceptions in SMB IT security is we're too small to be a target. And of course, being able to present the facts here is going to be really important to the reporting Dan's going to show you. But also, if you take Fort Knox and you take your local
coffee shop. I think I know which one I'd probably prefer to have a go at. And the biggest difference with AI today is that now the adversaries, the attackers are able to push out many, many, many, many attacks automatically at once. So instead of going for one big opportunity, which is very difficult to get into,
What we're seeing is SMBs are the huge, biggest target here because using AI, you can automate attacks across hundreds or thousands of different businesses at once.
There's a lot of work to do for MSPs to stay on top of this in the 365 world. And that's why we decided to bring these two worlds together where you've got our best in class protections within 365 across the whole of the stack. And we're combining it with the real time detection across all of 365.
And that's why we decided not to call this an ITDR, because we're not just looking at the identity layer. And again, when we get into the demo, Dan will go into the different areas of the logs that we can, well, that we are analyzing as part of this, and then all the different methods that we're taking to reduce noise.
and to make our tool as quick as possible when it comes to containment, because ultimately, that's why you're going to be able to differentiate. And just a final piece from me before I hand over to Dan. We have followed a similar track to what we did when we first released inforcer. We brought MSPs on the journey.
We took feedback and over the last six weeks we've actually ended up with over 600 MSPs who joined our early access program.
And during that time, they onboarded over 600,000 users, and then we've enabled them to protect them more effectively with our platform. And we actually analyzed over 25 billion logs from 365, which is just insane. And from each of those MSPs, we've taken loads of amazing feedback and we've iterated the platform.
We'll continue to do that. And that's something that I'm definitely going to chat a little bit more about with Ian and Josh once we get to our Q&A there. So Dan, I'm going to stop sharing and let you share.
Dan Harris
Awesome. Thank you, Will. I do actually have some slides, but do you know what? I think let's just dive right into a demo. There's nothing better than just kind of seeing it on the screen. So yeah, this is inforcer TDR, guys. Now, for those of you who are an inforcer partner and maybe seen this for the first time, probably recognize that we haven't just built something completely separate and in its own world, in its own portal.
Will Connor
Yeah.
Dan Harris
In fact, this is actually just completely baked into inforcer, right? We're a platform. It's just kind of 1 easy view to be able to kind of link everything together. Now, you're probably going to see some war games going on on my screen at the minute. These aren't missiles. It's not World War 3 big enough. What this is is a nice representation of impossible travel occurring across
A few tenants that I've got on boarded in here, very aptly named one, two, three, and four. Not the most great names in the world, but these tenants themselves are ones that we test with. We're able to kind of like, you know, add attacks to and then breach and do all the rest. And we can see here, there's some sketchy things going on, you know, logins from Japan and Moscow and wherever.
just happening a bit too quickly. So it's triggered off the good old arc to say, well, that's not quite possible. But you might ask, really, why does a map matter? I love maps, so that's good enough for me. But personally, I think really with the maps, it's a good way to represent easily for some partners like why identity is.
so wide. It's quite easy for like a dentist shop to think that they almost are a little bit like Fort Knox because no one knows where they are. No one would dare like attack them because they're barely on the internet, right? They're too busy fixing teeth and ripping money as well. So on this one, you know, when you've got like logins happening all over the world, you know, it could be from anywhere.
This is a good representation. Just help them understand that even when it's failing, you know, you might see red dots over here and here, then it's quite important.
But how do we get here, right? I think this is a key thing. It's pretty simple, right? You're all eligible to a 14-day trial with TDR. And through here, you're able to actually just go and license tenants pretty easily. You know, you can go to this, add your trial as this is needed, and do some checks just to make sure everything's all up and running, and then you're going to sign.
In this case, I'm going to do some things to my tenant because I think this is one of our dev ones. But effectively from this, it allows you to just quickly deploy out. Now, what happens is, is that during the onboarding, there's a few things that occur, right? The big thing is you'd see that the tenant goes into a new status. He might see a little hourglass.
And what it's doing is processing the last six months worth of logs. It's a bit of technology that allows us to do that for the unified audit log with Microsoft. And we do this intentionally for two major purposes. One is to build profiles around users, and we'll talk about that in a bit of detail later. And the second is to build a kind of
uncover threats of the past. It's kind of a big like pre-sales tool as well for you guys, you know, whether you're trying to win business or expand your existing business to show that there are active threats or even just previous threats that have been remediated is a good way to kind of represent like over the last six months why it's so important to go for
good tenant hardening practices, and everything else in between that. So one thing I'll zoom in on, I won't spend too much time on the logs here, as cool as they are. I wish Dave was on the call, he could take some credit for this, well, all the credit for this. But yeah, one of our devs. This is a pretty sweet view that allows you to do a multi-tenant like search.
of everything from your like entry sign in, audit logs, auth methods, apps, exchange, SharePoint, teams, devices for in tune and enrollment. There's a lot of really cool things here. And I won't dwell on too much here, but you know, you can zoom in on old Brute Willis that we have and just see what he's been up to. God knows what, really.
And why I zoom in on this is because, like Will mentioned, we're processing billions of logs, right? So when you add in all of these tenants, there's a lot of logs that happen. Now you can spot check and look for people logging in from all over the place, but I don't think that's very necessary. That's where indicators come in, right? This is a page that
It's kind of the inside of TDR's brain, right? You get to see what it's thinking, like what it's reacting to. There's nothing really to action here apart from observing that there's so much behind this. You know, you can see people using VPNs, potentially matching a block list, going into an account via brute force successfully.
maybe consenting to some new applications or enrolling a device or getting in through a device code flow and phishing someone. Impossible travel, mailbox rules getting added, malicious ones too, and also seeing that phishing emails are being delivered and also those links are being clicked on. You can see there's just so much stuff.
that we're looking at. And you can just see TD are thinking all the time. Now, the reason I say it's thinking is because there's a lot of indicators in there and things happen, right? Impossible travel is often possible travel, where people are just using VPNs and, you know, whatever. Maybe it's Will, he's on the plane all the time.
So, you know, the Wi-Fi is always kind of going from A to B and hopping them all over the world. But we know that. TDR knows that. And that's what kind of gets built out over the last six months, is knowing what is normal for someone and building normal behaviors based on individuals, on the tenant, on the applications. And actually also you as an MSP, if you have a bit of time, I'll dig into that.
a bit later. But what matters is TD is smart.
And it's able to kind of review something like if I look at old cipher over here, we can see what's happened in a timeline, which is, it looked like a phishing e-mail was clicked on, right, the link within it. And not long after, just a couple of minutes, we saw a device go phishing. Now luckily what this was, was one of those good old attacks to say, hey, enter this 8 digit code.
you've had a breach, would you want to verify your account or whatever. AI will mention is it's doing quite well to trick people to do these logins. And it goes to an official Microsoft site, nothing sketchy about that, and allows them to log in. You can see there's a few tags here that are saying impossible travel. Ah, they've moved from London to Russia.
a little bit too quickly. And we're seeing no new device, its device is not compliant, it's a risky IP address, and there's all kinds of things that is really quite concerning here. And again, a minute after that, they added a mail forwarding rule, they downloaded a bunch of files, and the threat was open just within those 3 minutes we saw.
and some stuff was being shared outside the organization. Now, this threat hasn't been contained yet. This happened for me last night or the early hours in the morning. And we need to probably contain this. So the first thing I do is block that user, right? This is an absolute step to make sure that
whilst we're doing all of this work, the attacker, whilst they're present in this environment, they've got leaked credentials potentially, maybe a way to bypass MFA and other ways to kind of get in. We've blocked the user because the next most important step is to revoke the sessions, right? This is to say, right, remove all the logins for that user and make sure that that's all killed.
Now we know the account's blocked, so they can't log back in. Again, this is handy. And we should probably remove that mail forwarding rule that we saw added to that tenant going to some sketchy domain. And then finally, ah, looks like they were sharing some files. Let's just execute this and ensure that those files are removed. You know, you can feel free to export these and take those over to your customer to say what was potentially exfiltrated.
but we've been able to kind of remove all of those files. So happy days. The threat has been contained. Now, the next step for you to do is really get the user back online, right? And all this needs to do is allow you to go call up the user and say, look, we need to just set you a new password just to be extra safe. And you know, well, actually, I won't show because I'm sure someone will try to log in. We got the password over here. And
Good. The password is reset. They can't log in because we need to enable their account. So let's enable the account. And we can also do stuff like, you know, resetting their MFA. Now, this is a brand new one. And I'm sure the devs are like giving me daggers whilst I press this button in our development environment. So let's see if this works. This is actually due to me today. Awesome.
It does. And this allows us to make sure that everything is all reset. So the next time they log in, they'll just be asked to set up MFA again, they've got the new password, and everything's all nice and reset. So pretty useful, pretty handy stuff. Finally, I think this is the most important step. We fixed the user, that's cool, but why did it even happen in the 1st place? Sure, it's because a phishing e-mail got in, but in reality, we should have had some really strong configuration.
either using something from the Exchange Online stack to make sure that safe links was enabled if they got the business premium and a strong anti-phishing policies in place, or even better than that, that were at least blocking device code flow from that organization. Now, all of those things would come together to help just secure, not just for that user, but the entire tenant.
So this is just a massive stitch back to left a boom to allow us to ensure that this entire threat is being handled as needed. Now,
Just before I close off this threat, I kind of want to run through something, which is, you're probably thinking, well, this threat has been open for, what, 15 hours, 16 hours? How comes we couldn't have just, you know, responded to this quicker? Now, this is part of that 24 service that, 24-7 service that you'll be able to offer.
because TD are not only alerts on threats occurring, but you have the choice to be able to enable a feature called auto containment. Now, when you enable it, just sticking up there, you will see that it's able to execute on some of those actions. Now, we always recommend that you have to just do all of them. TD will just kind of rotate and just make sure all of those actions are occurring.
sufficiently. But if you do feel uncomfortable about blocking the user sign-in, but you do want to do everything else, that's okay, right? We understand that that in fact is pretty significant. And you can manage this on a per tenant basis, right? So you can control the experience. Again, highly advised you do this just to make sure attackers can't get back in. And again, for the severity,
you can make sure that it only triggers out critical, right? And that basically says that TD is absolutely certain this is a problem. Or it could be high and above, you know, just lowering that threshold a little bit and you just want to be a bit more cautious kind of thing. You can exclude people as needed to. So if you want to exclude the CEO at SMB.com,
You can, again, don't recommend it. Let's block them. If there's a high value target, you don't want them trying to get into that environment. And what would have happened in that one scenario is that when TDR detected that threat for cipher, at minute 3, this would have been handled, right? So not only would the threat have been, you know, no further damage done,
All of those extra things would have been, you know, handled in terms of the malfolding rule, getting removed, user getting blocked, and all the rest. So, been a nice, safe state, the attacker can't do any more damage. You know, you can wake up in the morning and get a user back online, or this could be integrated to your PSA as that if you fire off one of these P1 tickets, maybe it fires off a workflow to wake you up.
as you need to. So a good service is helpful and kind of brings everything together kind of into one major view.
So I kind of want to dig into just one more thing before I kind of hand over to a bit of a customer panel. And that is reporting, right? So when we look at Cypher over here, let's close this off as remediated. We can get some pretty cool reports out of TDR. Now, there's three. I'm going to start in reverse order.
of value, I think, to you as an MSP. Now, number one is the root cause analysis. Now, what this does is it spits out a pretty report. Dave also was very influential on this one, to show he's not on the call. He effectively built this together to pick all of the data that we've collated on this side.
and just make it useful. Make it something that you can understand and something that you can potentially give to an insurance organization who actually make a claim back on cybersecurity insurance. And you get a nice summary of what happened in one short sentence or a couple there. And you get the threat time, like, you know, what happened, where and how. You give the initial access, what is a phishing link to some sketchy website that caused this.
why it worked and what was flagged.
And here we can see that all of those things were contained. And that back door was removed, the mail forwarding rule, and we was able to kind of clear out the MFA. Now, the impact was fairly significant, actually, just because we left it open for quite a few hours. We've got emails being read, we've got files being exfiltrated, and you'd be able to see if stuff has been downloaded, deleted, read, shared, etc.
And finally, you get your nice little appendix at the bottom, once we get through these files, around what our recommendations are and what we saw, you know, IP addresses, domains, and all the rest. Pretty cool report, right? We have some partners already starting to mobilize on setting this, right? Typically, for an organization to run these reports, it can take
days to even get that data together. And it's always a work in progress. If you guys find something that you will have in there, that's why we have such a fantastic engineering and product team that we're able to mobilize quickly to actually get some extra details as needed, within reason, of course. And here we've got two more reports we can run.
So we go into this tenant, we'll be able to run something like the reports, go to TDR, and you'll see a couple more in here. So you'll see prospecting, customer facing, and the way these look, I'll just bring them out of here just so you can see both of them side by side. We have probably a really cool report to me. Now,
For those of you who are new to inforcer, we have quite a few ways to onboard a tenant. And one thing that we're always very encouraging of is prospecting, right? Being able to add a prospect tenant using what we call the onboarding link, was the magic link once upon a time, that you can send to a partner and they can self onboard into inforcer. You can license them, kick off the TDR process to do the last six months worth of logs.
And it spits something like this out, right? Again, processing all those logs and going into the past, we can find those threats and we can see that, well, look, one person is under attack right now. Three more were breached in the last six months and Sarah, your CCO, was breached for the last 72 days. We know it because of those millions of logs that we've been processing.
and identifying those down into indicators and threats. And your biggest risk was the fact that you're missing a lot of that key configuration that we saw in that threat. Again, rolling it up into one page, stuff like they don't have MFA, you know, you don't have device code flow enabled. And when we look at Sarah, the reason she got breached is because of that phishing e-mail.
you know, logging from Nigeria, some back doors being added, emails and files being read and sent around as well. And just surfacing some of that really scary stuff, like sent emails, like wire change approval needed. And it looks like they figured that out because they read a wire authorization pack that was in SharePoint.
in the Treasury there. And a lot of this can happen so quickly now because of AI. Will mention that broad GPT, which does allow you to just kind of pop the session of a user in and just say, hack the living daylights out of them. And it will, it's got no rail guards. So it'll just be like, yeah, sure, no worries, buddy. I'll do what I can. And it'll be looking for stuff like this and being able to send it.
So pretty cool, pretty scary, right? But if you're actually providing TDR as a service, you don't want to kind of scare off your partners and say like, hey, you're not secure. Instead, what you'd be able to do is actually show a customer-facing success report.
And this says like, look, we've been running TDR or the service that you have behind this that you offer for maybe a month now, a couple of months. And in this case, in this little one month period, we was actually able to detect two attacks and remove the five back doors that they planted. And the average time to contain that was just a few minutes, right? And again, we know that because of the logs.
And we've actually been proactively hardening that tenant. There's a lot of things that we've been adding in there to make it more secure. But, you know, attackers still get through the cracks. This is why we have an alarm system in place like TDR. And it's a case of phishing emails. Someone got logged in, but it's just in a few minutes that they was able to contain that particular threat.
So again, it has a lot of value to kind of demonstrate that the service you're offering or selling through to them has immense value back as well. So again, some pretty cool reports, right, to be able to kind of demonstrate all of this. And yeah, I think for me, that's really like the main crux of TDR. If we add some more target, we get to Q&A a little bit later, then
We'll be in a position to do to do that, but I think I'm really excited to hear some more from Josh and Ian that we have on the call today, because they've been using TDR, right? You know, me showing a demo and doctored environments and funny things is useful, but I think actually hearing it from the horse's mouth is far, far better. So, Will, I'll hand over to you.
To run that.
Will Connor
Yeah, perfect. Well, I guess...
For my first question, probably directed to Ian to begin with, would be, you know, you've obviously worked with us now for a number of years. You've seen the product evolve. What was it from your perspective that made you give the green light to the team to jump into early accesses?
as quickly as you did as a business owner.
Ian Groves
Yeah, I think we have worked with you guys for a few years and it's well documented elsewhere on a podcast that you and I did well on the sketchy start we had to that where I was really unsure, but from the time we have started working with you, we've made the right decision. I think it's your understanding and your, for us, you're the conduit to Microsoft.
We build our ecosystem around Microsoft products, but we've always needed some middle layer that levels that up and helps us do it at scale. We've done that through the tangent management stuff now for a couple of years. What I've loved with that is the speed of the development of it. It's new feature after new feature. You make keeping our slots of processes up to date really difficult because you're constantly improving features all the time, so we're constantly having to update them.
Will Connor
This is.
Ian Groves
So when you told me that you guys were going down the route of this, A, I was shocked. I didn't see it coming. I was quite surprised. It was a very, very, very sensible strategic move, but I didn't see it coming. And knowing as we see this today, and I've seen quite a bit of the platform, but just seeing your demo there, Dan, I mean, I'm impressed just watching your demo and I've got access to it.
re-impressed along with some of the guys in the chat I can see. So for us it was a no-brainer to take that early access and I'm glad we've had the privilege really to give the feedback and work with you guys in these early days.
Will Connor
Perfect. Love it. And yeah, we've been iterating quite, I'd say, quickly, aggressively during early access based on feedback from all of the partners we had in. And we'll continue now we've gone into general availability to just add more value to
all of the platform. The goal for us is to be the tool that an MSP needs to manage Microsoft 365. And that's why we're adding so many different layers to both our core product 365 manager and also, of course, now TDR and starting to then stitch them together with the protection side that Dan talked about.
where we can really start to prove that value of why your customers need the policies in place. And I guess, Josh, you've been more hands on with the tool. What is it from your perspective that you've sort of enjoyed about getting hands into the TDR?
Josh Upton
I mean, a lot of it comes down to sort of like the single pane of glass, really, where, right, you've got millions and millions of these logs, but you can easily identify, right, well, I need to look at this, or I'm curious about that, going for and searching. So it's kind of where you previously have to go through multiple portals and run whatever PowerShell you want to pull things out.
It's just all there for you. You can find what you need to see. And the sort of categorization and the way they actually ingest is impressive.
Will Connor
Love it. And are you guys sort of already delivering a service around sort of right of boom threat protection for 365 specifically to your customers today?
Ian Groves
Yeah, we have a current SOC offering, which has been very good. There's never been an issue with it. And this has really thrown us quite a curveball to us because the stuff that you guys are doing, start on the report list, we ignore the engineering and the different approach you've taken for an AI here for just one minute and look at the report and I suppose we don't get that level of reporting.
Nor do I think, if I'm truly honest, do we get the level of speed that you demonstrated with the auto remediation stuff. And you'd said it at the beginning of the call, identity isn't just people anymore. It's we're going into agents. You know, I know we've been saying that now for a while, but the agents are coming and they are going to be everywhere. And we do need platforms that are built for an AI era. So as much as our current platform hasn't faulted us,
Will Connor
Yeah.
Ian Groves
We probably haven't seen the development or the progression on that platform that I think we're going to need going into 2027 with the world the way it is with the speed of AI. And how many seconds did you say that that X build, the speed of that X build was 23 seconds or something like that?
Will Connor
Yeah, the fastest one on record is, I think, 27 seconds.
Ian Groves
It's terrifying. We've got to be using platforms that are built with the same intelligence, speed, and systems to combat that. And we all knew this was coming with AI, right? All the good stuff about AI is always going to be the negative, but we've got to kind of got to fight fire with fire.
Will Connor
Yeah, makes sense. And I think, Josh, you got most of your customers into early access in the end, didn't you?
Josh Upton
Yes, yeah.
Will Connor
Okay, perfect. And do you think having like that visibility over all of those logs from 365 has just given you sort of some additional value on what you had with your previous, with the other tool that you guys have been using for this?
Josh Upton
Absolutely, yeah. Sort of the previous tool, well current tool, you'd sort of, you'd only really hear about things when something had triggered a certain rule or a certain set of flows, whereas you go into TDR and you've got full visibility of anything you want to look at. You know, if you're hunting for a particular type of thing, it's in there. So you don't have to wait for something to have gone wrong and go through that whole process. You can
look what you want to see. It might not be flagged as malicious, but you know what you're trying to find.
Will Connor
Perfect. Makes sense. And I suppose in terms of the tie-in with you guys already using inforcer today, is that sort of, you know, where does that sit in your priorities for bringing these two areas together? I suppose that's the both of you.
Ian Groves
I'll jump in on that one as the guy who has to decide the products we buy and where you buy them from. I hate products, Paul, and I love the fact that A, these things do belong together. If you ask me, it makes total sense. The left and boom and right boom, I think you used the phrase stitched earlier down. I think they belong together and working with somebody where we already have a strong relationship with first class account management that we have a
system that we can train on and learn around that for that consolidation is streamlined. You know, we're constantly looking for efficiencies in our lives. We can't scale without efficiency. So bringing this closer together is a game changer for ourselves. It's an extra 1 less product that we need, but it isn't just the consolidation. We're levelling up at the same time as we consolidate our stack.
Josh Upton
Yeah, on top of that, I mean, the way that it sort of brings detection and prevention together, it does just make sense. It's A no-brainer. You've already got inforcer where you are aligning to your baseline. You've got everything you want in there, but then you've got the clear reasons why you don't. Yeah, where else are you going to see that?
Will Connor
Love it. Good to hear. Yeah, we're going to be stitching those areas together even more over the next couple of months. There's something I mentioned on the ANZ session this morning, so I'll share it with you guys as well, to be fair. We've got sort of some new features coming in our
365 manager tool within the assessment engine, where you're going to be able to fix things from assessments. And of course, you may recognize in the prevention section of TDR, we're tying into those assessments. So once we've got that out, we're also going to be building that into the TDR console. So when you're in TDR, if you see those
you know, you would have fixed this if you had these policies, you'll actually be able to one click fix those from TDR from that same screen as well. So really bringing the two areas together where you can make
Ian Groves
Nice.
Will Connor
just data-driven decisions, which is this threat happened because we didn't have these gaps filled. You'll be able to run the report that shows that to the customer, prove to them that, you know, those policies that you said you didn't need, you actually did, and you probably should have listened to us. And if you'd like, we can fix them for you today.
as part of the service. So that's the direction we're heading, where we can just give you guys the tangible evidence that I think a lot of tools don't provide, especially not in something which is nice looking instead of just CSVs and things like that.
Ian Groves
I think that's a key thing for MSPs. Very few MSPs will tell you that they're great at letting their customers know what they do, a good job, what they're providing for you. We feel we get no gratitude in our industry for the work again, but we're also guilty of not telling the businesses we're looking after what we do. So to have good looking reporting evidence of what we've done,
whether it's to prove that you're right to be buying this service office or you, yes, it's good that you're buying this service office, but look at the near misses what happened to catch if you came along and bought more of a higher stack product office or a bigger security wrap up, this would have been prevented in the 1st place. You know, how many times do you want us to tell you how this was a near miss as opposed to perhaps those holes with a different offering? So
Being able to give us stuff that translates the value of what we do to customers through the products we buy is really important to MSPs. It isn't just the how cool the tech is behind it. And on that point, the impossible travel stuff, we've got another product that did some impossible travel stuff and it just didn't work because of VPNs exactly as you said that.
we would end up having alerts that we'd have to waste time. It didn't do any auto remediation or anything like that anyway, but it would trigger us having to go and do research to find out, well, is there a problem here? And it was just somebody landing in the States, popping up their laptop, connecting on a hotel IP, and then all of a sudden switching to their UK IP. We get in possible trouble. We've burned tech time on that.
We know it's not a thing. So the fact that you said that the system is thinking and it does analysis and it accounts for that stuff, this is the this is the bill for the AI year and the more modern stuff that we need rather than just, you know, this rule triggered this thing and there's no intelligent trap around.
Will Connor
Yeah, yeah. To be honest, we heard a lot of that same thoughts around impossible travel during early access from a lot of our partners, to be honest, where, yeah, it's a lot of time wasted. So that's why we decided to go down this sort of heuristic behavioural approach, where also we have to ingest as much of the logs as we can with day one.
is very difficult to make those engines work. So we do, as Dan mentioned, we're loading in, if possible, six months worth of logs, if the audit logs have been turned on, et cetera, for that amount of time. And then we can actually start to do that from day one, rather than with a lot of tools that do also have this functionality, they don't all
Ian Groves
Yeah.
Will Connor
do the log ingestion at the beginning, which means that they start with no idea about a user, and then it takes them that amount of time to then build up the profiles. Whereas once we've done the ingestion, the AI saw in the back end will essentially be analyzing all of the users immediately once we have all that data in.
Ian Groves
I'm halfway home from an event down in London, but a lot of that talk there was getting efficiency gains on your desk and using different AI platforms to help triage tickets and do things of it. It's all well and good as buying that time back, but as the threat landscape gets worse, we will lose that time if we don't have smart tools and systems helping to combat that. So what we take from one hand will lose it the next. So I think
seeing the intensity at which the logs have watched and the reactiveness stops my guys having to get involved to do something most of the time unless we need to go and actually have an extra pair of eyes on it. So it's one thing looking for games on the best to give support, but we're going to lose that to security stuff with all these AI threats.
Will Connor
Yeah.
Perfect. So I actually had benchmarked like 10 minutes of Q&A from the chat, but Dan's been answering all of the questions in the chat while I asked you guys questions. So unless anybody from the chat also has any questions for Ian and Josh or any further questions,
then I'm actually just going to quickly share and if they do come in, then please do answer or ask them. Dan, I'm just going to pull up the QR code as well, which will allow you guys to register for a trial. So we are opening up
Dan Harris
Yeah.
Will Connor
to all partners and also to partners, to MSPs who don't use any of the inforcer platform today. You can sign up and start a 14-day trial where you can onboard as many tenants as you need into TDR to get a good
insight into how this could work for you today. Another side note is you don't have to take our 365 manager tool either. So TDR does work standalone. If you want to start there and then have a look at the wider platform as well or in a future evaluation, that's totally fine too.
Ian Groves
give what is going to look like an obvious plug if you give the answer, I think you're going to give. So if people set that up and connect their tenants up to it, and let's say the audit logs are on for those tenants that are set to the period they need, you're effectively saying that's a sweep of all the customers' tenants to give them some security info for 14 days for free as a starting point.
Will Connor
Tess.
Yeah, exactly. You can run all of the reports, all of the assessments, looking back in time, essentially. So that prospecting report that Dan showed, where it does the 180 day look back, that's available for all as part of the trial period, yeah.
Dan Harris
Yeah. I think I also want to take a bit of time, just because there's a bit of a common theme between some of the questions that I raised. So I just want to sort of dig in to behavior profiles a little bit. Like why is TDR smart? It's a little bit confusing. We actually encourage you to go ahead and add as many tenants as possible into TDR. Again,
all free, there's no auto conversion, you know, it's all going to be to your own liking. If you don't like it, it's not going to charge you or anything. But actually adding a lot of tenants in there helps us with our behavioral system. So it's able to learn very uniquely like you as an MSP, right? And I think that's one thing. So I'm going to start top down with all of our different profiles here.
I watch you guys are scanning and then signing up. When you've added in, let's say like 10 or 20 tenants or hopefully a lot more, then what it's doing is it's able to kind of observe like what administrative workloads are occurring on this tenant and what commonality is there between them? And between you as an MSP, can we start to pinpoint your staff, right? You know, if they're working from home, from offices, from VPNs and stuff,
that we can start to have a bit more of like a trusted network of like, right, this seems to be the collection of individuals who perform administrative activities within the MSP. So when you are adding sketchy things like global admins or blocking users and creating like, you know, new workloads and sites and whatever, it looks scary to a platform like an ITDR, but for inforcer TDR, it's actually just like, yeah, this is cool. This is normal. We've seen this before.
This is routine, this is expected. And I raise it because TDR first and foremost is focused on denoising, right? Like where are we, you know, competitively standing out in the market is that we're focusing on trying to alert you only when there is a real threat. And going down another layer, we have a tenant profile, right? The tenant profile says,
Right, what commonality is that between the users within one business? Right? This is like, you know, someone working from one of our offices, like for us, it could be from the Tampa office, it could be from, you know, UK office, it could be from the Netherlands or Denmark or wherever else we are now. And it sees a lot of users
on the one same IP address, doing typical workloads, and they say, okay, this is probably an office and it can piece it all together. Next is the applications within the tenant. Let's say cloud backup software as an example, I think this is a good one, is able to profile what's normal for it. We're not in the book of business of exclusions. We'll always refuse to say, yes, you can exclude stuff.
from the brain of TDR. Because TDR just watches, just like, yeah, okay, this is a known backup solution. You're using it across other tenants, we're okay here. But if that backup solution was going off and actually able to, you know, run some malicious workloads, like creating users and stuff, that was a big change in behavior, right? So we will actually call that out and say, well, we're going to throw it. And then finally, we've got the user, right? For the user, we're profiling.
When do they typically log in? And what devices do they use? What do they typically do? How do they log in? What operating systems? You know, stuff like their IP address, ASN, VPN usage. You know, do they use NordVPN a lot? That kind of stuff. And there's a lot more to it than that. But there's just so much that we profile on the individuals that we use.
all of that telemetry across TDR to work out, right, is that possible travel? Is it not? Is there someone doing something they should be or shouldn't? And it's always thinking and it's always evolving. Those behaviour profiles are always refreshing, right? It's a constant stream of knowing what's normal today. And the intention there, like I mentioned, is to make sure it's a denoise platform. So when you receive an alert from TDR, you know, it's something worth reacting to.
something worth jumping on and making sure that you're resolving as soon as possible.
Will Connor
Love it. Well, thanks a lot, everybody, for all of your time for joining us today. Thanks a lot to Ian and Josh, of course, for joining us as well and giving some great insight into partnership and also your experience, Josh, in actually getting hands on in early access. I appreciate you guys' time.
And if anybody needs a recording of the session, I've had a couple of people message me directly asking if that'll be available, we can make that available. So if you, either if you're a partner, you want to just ping your account manager, they'll be able to send it to you, your PSM. And yeah, hopefully.
we can get you guys set up on a trial and testing it hands-on over the next few weeks.
Ian Groves
Thanks for the result, Will.
Josh Upton
Thank you.
Will Connor
Cheers, guys.
Dan Harris
Cheers, everyone.
stopped transcription