Microsoft 365 Insights for MSPs | inforcer Blog

How Microsoft Became the #1 Attack Surface for MSPs

Written by Graham Morrison | Jul 21, 2026 1:31:16 PM

Summary

Microsoft 365 has become the number one attack surface for MSPs because customer identities, email, files, and admin permissions now live in the tenant rather than on servers. Microsoft blocks roughly 7,000 password attacks per second, and identity-based attacks surged 32% in the first half of 2025. Preventative controls like security baselines reduce breach risk but cannot detect compromise inside the tenant, so complete Microsoft 365 security requires prevention, detection, and response working together.


Time to read

  • 9 minutes

What you’ll learn


  • Why the Microsoft 365 tenant replaced the server as the MSP's primary security responsibility
  • The Microsoft threat data behind the surge in identity-based attacks
  • Why prevention-only and detection-only approaches both leave gaps
  • How closing the loop between detection and prevention strengthens every tenant you manage

Next steps

  • Audit which of your managed tenants have adequate detection and response coverage
  • Review your baseline and drift management posture across your customer base
  • Assess how quickly your team could trace an incident back to its root cause
  • Join the inforcer TDR waitlist for early access, exclusive demos, and product updates

How Microsoft 365 Became the #1 Attack Surface for MSPs

For most of the managed services industry's history, the job was defined by hardware. MSPs monitored servers for their SMB customers, patched Windows, updated firmware, maintained firewalls, and ran endpoint protection. The perimeter was physical, and everything worth stealing lived behind it.

That world is gone. For the average SMB today, there is no server room. Whole businesses run in Microsoft 365: identities in Entra ID, email in Exchange, files in SharePoint and OneDrive, collaboration in Teams, and the admin permissions that govern all of it. The tenant is the new server.

That means the responsibility of the MSP is now not only to manage, but also to defend.

Unfortunately, threat actors have adapted to this change faster than much of the industry's tooling did. The result is that Microsoft 365 is now the single richest attack surface an MSP is responsible for, and MSPs need new ways to protect Microsoft tenants on both sides of an incident: before and after it occurs.

Attacks take place where value is concentrated: the tenant

Think about what a Microsoft 365 tenant actually contains:

  • Every user identity in the organization
  • Every email ever sent or received
  • Contracts, financials, and client records in SharePoint
  • Internal conversations in Teams
  • And, most critically, the administrative permissions that control access to all of the above

The implication of this should concern every MSP and every SMB they manage. Compromising an endpoint only allows a threat actor to access a single device, but compromising a tenant can net them an entire business.

Attackers have responded to this new incentive by scaling up their efforts. Microsoft Entra data shows that password-based attacks make up over 99% of the 600 million identity attacks Microsoft's customers face every day, and Microsoft blocked roughly 7,000 password attacks per second over the past year. According to the 2025 Microsoft Digital Defense Report 2025, identity-based attacks surged by 32% in the first half of 2025 alone.

The bottom line is that when threats started focusing on tenants instead of endpoints, identity became the new perimeter. The MSPs that can most effectively secure their customers’ Microsoft environments in our current day and age are the ones that understand a login attempt against that perimeter can come from anyone, anywhere in the world, at any time.

AI has lowered the cost of attacking your customers

The uptick in attack volume that Microsoft users are seeing is made more concerning by the fact that many attacks are also growing increasingly sophisticated.

According to Microsoft, threat actors are turning to AI to scale phishing campaigns and automate threats. This means that the crude, typo-ridden phishing emails most of your customers have learned to recognize are now being replaced by personalized lures that are generated at scale, and which often appear far more credible to recipients.

Techniques that sidestep traditional controls are also accelerating. Microsoft reported a 146% year-over-year increase in adversary-in-the-middle phishing attacks, which steal session tokens and bypass MFA.

And human beings remain the most reliable way in: 28% of the breaches investigated by Microsoft's Detection and Response Team were initiated through phishing or social engineering.

None of this means that preventative security measures have stopped being valuable, and efficient tenant management remains as vital as ever, because hardened tenants are breached far less often than vulnerable ones. But a higher number of attacks are now designed to be invisible to MFA and other preventative security measures, and these can wreak havoc on a tenant when your MSP has no way to respond to them quickly.

 

The breaches you can't see can do the most damage

If you’re an MSP, the old adage of “what you don’t know won’t hurt you” is one of the single most dangerous phrases you can internalize. The hard truth is that when a Microsoft 365 environment is compromised, it rarely trips an alarm.

  • A malicious inbox rule can quietly forward emails from an SMB’s controller for months without anyone noticing.
  • A stolen session token can be used by a threat actor to bypass a business account’s MFA and access it from their own device.
  • Automated tools can allow an attacker to proxy an organization’s login page in ways that appear legitimate to Conditional Access policies and MFA checks.

Individually, these events may not clearly signify an attack in progress. But once the attacker is inside the tenant, they can quietly increase their privileges and map the environment for months before making a move. And the longer this persists, the more data is usually at risk: in 80% of the incidents Microsoft's security teams investigated last year, attackers sought to steal data.

Establishing proper security baselines, managing tenant configurations, and remediating drift can all lower the odds of a breach. But these measures do not address what happens inside the tenant after identity is compromised.

Modern MSPs must protect customers before and after a breach

Most of the security vendors serving MSPs today were built to detect and respond to attacks already in progress. This approach was first applied to endpoints, and is now evolving to focus on identity. But for many of these providers, detection was the only product being offered. Prevention was the customer's problem.

Only recently have many of these vendors started adding preventative capabilities and tenant management features to their platforms. This is because the market has realized that responding to breaches without fixing the conditions that allowed them creates a risky treadmill for SMBs that can lead to customer attrition.

But preventing threats and managing policies for multiple Microsoft tenant environments is complex. It requires deep policy coverage across the entire Microsoft 365 stack, convenient cross-tenant visibility, reliable drift detection, and the tooling to deploy changes across every relevant tenant without breaking anything in the process. These capabilities take years to build well, and most vendors who previously specialized in threat detection products are still at the beginning of that journey.

Every modern MSP should want to offer a productized Microsoft security service to its SMB customers. But for that service to be comprehensive, it needs to combine world-class multi-tenant management with reliable threat detection and response capabilities. One half of that equation isn’t enough anymore.

MSPs that can satisfy both of these requirements with a single system will be at a significant advantage over those attempting to do it with completely separate tools.

Complete tenant security requires both, working as one system. Not two tools with two dashboards and no shared context, but a loop: prevention reduces the attack surface, detection catches what slips through, response contains it, and, crucially, every detection feeds back into better prevention. When an incident can be traced to the specific policy gap or configuration drift that allowed it, and that gap can be closed across every tenant you manage in minutes, each breach makes the entire estate stronger.

Closing the loop: prevention and response on one platform

An ideal security solution for Microsoft MSPs should look something like this:

  • Prevention reduces the attack surface
  • Threat detection catches what slips through
  • Response contains it
  • Data collected from each incident seamlessly feeds back into better prevention

That last point is arguably the most important. When an incident can be traced to the specific policy gap or configuration drift that allowed it, and that gap can be closed across every tenant you manage in minutes, each breach makes the entire estate stronger.

inforcer spent the last three years on the hard problem first: left of boom tenant security at scale. Its 365 Manager product is the multi-tenant control plane that more than 1,200 MSP partners use to enforce security baselines, manage configuration drift, and standardize Microsoft 365 tenants across their entire customer base.

Prevention has always been the foundation. inforcer TDR builds detection and response on top of it.

Detection across the full breadth of Microsoft 365

Most IiTDR tools watch identity alone. inforcer TDR continuously ingests raw events from every layer of Microsoft 365 to ensure important signals are not ignored:

  • Deep Microsoft telemetry correlates data from Entra ID, Exchange, SharePoint, Teams, Defender, and Purview into a single picture
  • This allows related signals (such as a suspicious sign-in, a new inbox rule, and a bulk download) to surface as part of the same attack narrative instead of disconnected alerts
  • inforcer TDR can also ingest up to six months of historical logs at onboarding, enabling it to identify attacks that predate the tool itself within this window
More reliable threat alerts

Alert fatigue often results in monitoring tools being turned off or tuned out. inforcer TDR is built to only interrupt your team when it matters:

  • Signals are analyzed by the platform and by AI, then verified by human SOC experts before a partner is ever alerted
  • Your team spends its time responding to genuine threats, not chasing false positives
Detection that feeds prevention

By introducing threat detection and prevention to a platform that already handles prevention, inforcer TDR complements 365 Manager to create a comprehensive Microsoft security solution for MSPs:

  • inforcer TDR identifies the policy gap or configuration drift that made an attack possible
  • MSPs can then remediate that root cause for every affected tenant via 365 Manager

With this approach, responding doesn't just end an attack. It also helps prevents the next one.

Security value that customers can clearly see

Prevention has always had a commercial problem: when nothing bad happens, customers wonder what they're paying for.

Real-time detection, incident reporting, and a live view of threats caught across your estate make the value of your entire security service visible. That means it makes your preventative work easier to defend and sell.

Defend each tenant as well as you manage it

Microsoft 365 became the number one attack surface for MSPs because it's where the identities, the data, and the admin control now live. Available threat data shows that attack volume is enormous, AI is making attacks cheaper and more convincing, and invisible attacks can still create massive damage.

Defending the tenant means treating it the way MSPs once treated the server: continuously monitored, actively maintained, and defended before and after an incident. Prevention and response are not competing strategies. They're two halves of the same job.

inforcer TDR is coming soon to complement our existing multi-tenant management platform with threat detection and response designed for MSPs managing Microsoft 365 at scale. Join the inforcer TDR waitlist for a sneak peek at product features, exclusive demos and webinars, and the chance to be among the first to experience end-to-end Microsoft 365 security coverage.

Frequently Asked Questions

Why is Microsoft 365 considered the #1 attack surface for MSPs?

Customer identities, email, files, Teams conversations, and admin permissions all live inside the Microsoft 365 tenant now instead of on a physical server. That concentration of value is what makes it the richest target available to a threat actor, and it's why MSPs are responsible for defending it, not just managing it.

What's the difference between preventative tenant management and threat detection and response?

Preventative tenant management, sometimes called “left of boom” security, includes security baselines, configuration management, and drift remediation that lower the odds of a breach happening in the first place. Threat detection and response, or “right of boom” security, is what identifies and contains an attack that's already underway inside the tenant.

Why don't security baselines catch every threat on their own?

Baselines and configuration policies reduce the attack surface, but they can't detect what happens once an attacker is already inside using a compromised identity. Malicious inbox rules, stolen session tokens, and adversary-in-the-middle techniques are all designed to look like legitimate activity to policy-based controls, which means a hardened tenant can still be breached invisibly.

How does inforcer TDR differ from iTDR tools on the market?

Most IiTDR tools monitor identity signals alone. inforcer TDR ingests raw events across Entra ID, Exchange, SharePoint, Teams, Defender, and Purview, correlating them into a single attack narrative instead of disconnected alerts. It also connects directly to 365 Manager, so a detected incident can be traced back to the policy gap or configuration drift that caused it and remediated across every affected tenant.

Is inforcer TDR available now?

inforcer TDR is coming soon. MSPs can join the inforcer TDR waitlist for early access, a preview of product features, and invitations to exclusive demos and webinars ahead of general availability.

Will inforcer TDR replace 365 Manager?

No. These are separate, complementary products. 365 Manager remains inforcer's multi-tenant management platform for prevention, baselines, and drift remediation. inforcer TDR adds detection and response on top of it, so partners get both halves of tenant security in one connected system rather than two disconnected tools.