Microsoft 365 Insights for MSPs | inforcer Blog

Measuring the cost of alert fatigue for multi-tenant MSPs

Written by Graham Morrison | Aug 27, 2026, 8:00:01 AM

Summary

MSPs managing multiple Microsoft 365 tenants often face hundreds of alerts weekly. At even 15-30 minutes to investigate each, that adds up to hundreds of thousands of dollars in annual engineering time. Large MSPs sometimes address this by building an internal SOC—but this is too expensive for most others. Since locking tenants down too tightly can impact customer relationships, the only practical solution for most MSPs is to find a threat detection and response solution that scales across their estate.

Measuring the cost of alert fatigue for multi-tenant MSPs

A managed service provider providing security for multiple customers does not manage one environment. It manages a separate tenant for each customer, and every one of those tenants generates its own alerts.

Most of these alerts turn out to be false positives, meaning the system accidentally flagged normal behaviour as suspicious. In conversations with various MSPs using a range of detection tools, our team has seen similar figures come up again and again: between 90 and 95% of alerts often turn out to be false positives.

When that volume exceeds an MSP's capacity to review it, the reviewer stops reviewing carefully. This is called alert fatigue, and it creates the risk of causing genuine threats to go unnoticed.

But this is more than a potential security problem for MSPs. It is also a budget problem.

Related: How Microsoft Became the #1 Attack Surface for MSPs

Why alert fatigue is a big problem (even for small MSPs)

Manually sorting through alerts for a single tenant is already a lot of work. An engineer has to answer one question for each one: real or false? That means checking the sign-in location against the user's known patterns, confirming with the customer whether the activity was expected, reviewing adjacent logs, then either escalating or dismissing.

An optimistic estimate of the scope for this kind of work is 15 to 30 minutes per alert. Assume a more-or-less standard engineering rate of $125 to $175 an hour—then multiply that by 22 tenants.

At 150 alerts a week across all of them, at 22.5 minutes each, that is 56.25 hours. At $150 an hour, that is $8,437 a week, or roughly $439,000 a year. Across the full range of 100 to 200 alerts, 15 to 30 minutes each, and $125 to $175 an hour, the annual figure runs from $162,500 to $910,000.

That is real money spent entirely on tedious manual work. And because it’s tedious, it also leaves room for error.

But that’s not all. For context, our market research found a small MSP managing small customer tenants receiving over 600 alerts in a single week. At 22.5 minutes each, that is 225 hours a week. In other words, it is equivalent to more than five full-time engineers doing nothing else.

A four-person MSP cannot possibly pay that bill. So for many smaller providers, this work simply does not happen, and the alerts go unread.

How large MSPs often solve this problem (and why most others can't)

You might assume that larger MSPs would generate even more alerts, but that’s not always true. Some of the substantially larger MSPs we talked to saw only five or so alerts in a given week, and nearly all of them turned out to be important.

But how are these larger organizations dealing with fewer alerts? It’s not that they’re less vulnerable. Rather, it’s that they’re able to invest more money in the solutions they use to separate meaningful alerts from false positives.

Out of the box, Microsoft security tooling flags broadly, because it does not yet know what normal looks like in a given tenant. Establishing that baseline means learning each customer's working hours, travel behaviour, sanctioned applications and device patterns, then adjusting thresholds accordingly. Do that work across every tenant and the noise falls away.

But that work is expensive, and it’s not a one-time project. It is ongoing, because every new customer resets it.

So larger MSPs often solve this by building an internal security operations centre, or SOC: dedicated senior security staff whose job is managing detection rules, tuning thresholds, and maintaining baselines across the estate. The MSPs we spoke to had invested tens to hundreds of thousands of dollars reaching that position, and most of those are recurring costs.

But the vast majority of MSPs cannot make that investment. In a Canalys survey of 135 MSPs and MSSPs, talent acquisition and retention ranked as the biggest external threats to business operations, ahead of both evolving cyber threats and market competition. Even MSPs with the budget struggle to fill these roles. For a four-person MSP, neither the capacity nor the budget exists.

Creating a cost-effective TDR solution without building your own SOC

An MSP that cannot afford to build their own SOC or manually manage alerts for multiple tenants needs a cost-effective threat detection and response solution that scales across their estate. This is what the inforcer team set out to develop with inforcer TDR.

inforcer TDR enables MSPs to continuously monitor all of their managed tenants from the same single-pane dashboard. It also correlates signals across all Microsoft 365 products within each tenant environment to provide context for each alert and separate likely attacks from normal operational events.

This addresses the cost problem outlined above in three specific ways:

  • One view across every tenant. Detections from identity, endpoint, email and cloud arrive in a single console covering the whole estate. This cuts down significantly on required engineering hours by eliminating the need to manually sign into each tenant or review logs by hand.
  • Behavioral analytics instead of per-event alerting. TDR uses deep Microsoft telemetry to understand normal behaviour for each tenant and correlate alert signals against it, reducing false positives and alert fatigue.
  • Fewer alerts, higher confidence. Cutting false positives makes it easier for engineers to focus on the alerts that represent genuine concerns, improving response times and outcomes while guarding against customer attrition.

This approach allows small-to-midsize MSPs to even the playing field against larger competitors without requiring the budget to build their own SOCs. You get the same quiet tenant view, at a fraction of the cost.

Tenant hardening only goes so far

There is one option MSPs often reach for that sounds responsible at first: lock the tenant down and prevent more alerts in the first place.

Enforce Conditional Access on every application, require MFA challenges on every session, block unmanaged devices, restrict external sharing, disable OAuth consent entirely. Tighten far enough and the alert volume genuinely falls, because the risky behaviour that generates alerts becomes impossible.

But this also makes the tenant essentially unusable. The customer's staff find themselves hitting MFA prompts repeatedly throughout the day, switching apps or devices to approve each one, losing access to tools they were using, and waiting on approval tickets for things that used to take seconds. Small businesses often push back on this quickly and firmly.

So the MSP negotiates. A Conditional Access policy gets an exception for the sales team. A legacy application keeps its access because the finance system depends on it. Personal devices stay permitted because replacing them is not in budget. Each exception is a security decision made for a legitimate business reason, and each one is a gap the customer has explicitly asked to leave open.

Those gaps do not close. They have to be watched. This is why threat detection and response is essential even for well-managed tenants.

Related: Prevention vs. Protection: Why Both Are Vital to Modern MSPs

The risks of missing even one alert linked to a genuine threat

The main reason this matters is the potential cost of getting it wrong.

IBM's 2026 Cost of a Data Breach Report puts the global average cost of a breach at $4.99 million, a 12% rise year on year and the highest figure the report has recorded, based on 602 breached organisations between March 2025 and February 2026. IBM also frames the same figure in a second way: roughly $1,100 for every hour the breach runs. That is an average spanning organisations of every size, but it is still significant.

And MSPs can’t protect every potential gap with sound tenant management. Microsoft’s 2025 Digital Defense Report attributed 28% of breaches to phishing or social engineering, with only 18% to unpatched web assets and 12% to exposed remote services. Microsoft also found that 40% of ransomware attacks now involve hybrid components, up from under 5% in 2023.

So while hardening can guard against many breaches, some attacks can succeed based on nothing more than human error on the target organization’s end. That makes a threat detection and response solution essential.

So where does that leave a small MSP?

If you’re managing security for dozens of business customers and getting hundreds of alerts per week, that’s not a security problem you can solve by simply working harder or hiring better. Locking tenants down more tightly will impede operations and potentially risk relationships. You can try hiring a security analyst, but even if you find one, a single person is not an internal SOC. And sorting through the alerts manually requires time and money that you almost certainly don’t have.

Every path built into the business model of a small MSP leads somewhere you cannot afford to go.

The alternative is not to ignore the gaps. It’s to monitor them efficiently and remediate incidents quickly. The right threat detection and response solution is what gets you there.

Request early access to inforcer TDR today.

FAQs

If I can use inforcer to lock the tenant down, why do I still need to monitor it?

Because a fully locked-down tenant is not often practical. In practice, every MSP negotiates exceptions: a legacy application that keeps its access, a team that keeps working on personal devices, a policy carve-out for a workflow the business depends on. Those exceptions are deliberate business decisions intended to support daily operations, and each one leaves certain gaps that hardening cannot fully close. Threat detection and response covers the gaps that tenant management is not able to.

Do larger tenant environments generate more alerts for MSPs?

Not necessarily. Alert volume tracks how well an environment has been tuned rather than how many users it contains. Our market research found a small MSP managing small tenants receiving over 600 alerts in a week, while some considerably larger MSPs were seeing around five. The difference was that the larger providers had invested in dedicated staff to establish baselines and adjust thresholds across their estate.

What is a false positive alert, and how can MSPs reduce them?

A false positive is an alert triggered by normal activity that the detection system read as suspicious. Microsoft security tooling is deliberately sensitive, because failing to flag a real attack is worse than flagging a legitimate login. Until a tenant is tuned, the system has no baseline for that customer's travel patterns, working hours or sanctioned applications, so ordinary behaviour keeps looking anomalous. MSPs that use cost-effective tooling to analyze alerts from across their Microsoft 365 environments can reduce unnecessary alerts caused by regular business activities.

What does manual alert triage actually cost an MSP per year?

At the midpoint of our research assumptions, 150 alerts a week at 22.5 minutes each is 56.25 engineering hours. At a blended rate of $150 an hour, that comes to roughly $8,437 a week, or $439,000 a year. Across the full range of 100 to 200 alerts, 15 to 30 minutes each, and $125 to $175 an hour, the annual figure runs from $162,500 to $910,000.

Can’t MSPs just hire more security analysts instead?

This approach is both prohibitively costly and difficult to execute. Canalys found talent acquisition and retention to be the top external challenge facing MSPs and MSSPs, ranking above evolving cyber threats. A single analyst also does not replicate an internal SOC, because tuning across a multi-tenant estate is continuous work that resets with each new customer.

How is inforcer TDR different from inforcer’s multi-tenant management platform?

inforcer’s flagship tenant management platform is rebranding to 365 Manager, but it functions the same way it always has: it operates left of boom, hardening configuration and enforcing policy before an incident takes place. inforcer TDR operates right of boom, monitoring managed tenants continuously and correlating signals across identity, endpoint, email and cloud to separate likely attacks from isolated events. They address different halves of the same problem, and both are important for a complete security solution.