Multi-tenant Threat Detection for MSPs in action
Summary
inforcer TDR’s multi-tenant visibility gives MSPs a single-pane view of alert signals across every Microsoft 365 tenant they manage. These signals are correlated across identity, devices, mail, files, and data movement within each tenant, providing vital context that differentiates genuine threats from false positives produced during normal business activities and helps recognize signs of a coordinated attack that might appear to be noise when considered in isolation.
One Threat Actor, Many Tenants: Multi-Tenant Threat Detection in Action
Multi-tenant threat detection gives your MSP the ability to contextualize alert signals from every Microsoft 365 tenant you manage inside a single view.
MSPs need threat detection and response tooling with this capability because a threat actor working through a list of small businesses may attack more than one managed tenant. However, most threat detection and response products are not designed specifically for MSPs and are usually intended for use in enterprise environments. These tools may lack features that are important for identifying signs of a coordinated attack across separate managed tenants.
Below, you’ll learn about the benefits of having dedicated multi-tenant capabilities when you use a threat detection and response solution designed for MSPs. Learn how this can help your MSP deliver peace of mind for customers and defend the value of your security service.
Why attacks across multiple tenants often go unnoticed
Consider a fairly ordinary week for a typical MSP:
- On Monday, a tenant in your estate records a handful of failed sign-ins against three accounts, followed by a success.
- On Wednesday, a different tenant shows an unusual OAuth consent grant, where a user has approved an application's request for access to their mailbox.
- On Thursday, a third tenant produces a mailbox rule that quietly moves anything mentioning invoices into a folder nobody reads.
When viewed in isolation, it can be difficult to tell whether each of these incidents represents a normal business activity or potential threat in progress. Failed logins, application approvals, and new mailbox rules are all regular occurrences at most businesses. An analyst working through them separately would very likely close all three and move on.
But considered together, these might well represent different stages of the same operation being run against three of your customers.
Related: Anatomy of an Invisible Microsoft 365 Breach
The information needed to connect them is in your estate the entire time, but it is only useful if you have a practical way to see it. Without that, each signal can surface in a different tenant, on a different day, quite possibly in front of a different engineer.
Imagine trying to solve a jigsaw puzzle. Now imagine that you’re only allowed to look at the piece you’re currently holding in your hands instead of being able to see the pieces around it.
That’s what most MSPs are up against.
How legacy threat detection and response tools leave your customers vulnerable
Not every threat detection and response product is intended for MSPs. Companies producing these solutions have historically focused on enterprise-level organizations.
Selling to these companies is far more lucrative on a per-transaction basis than selling to smaller organizations, so many of these vendors have never bothered to create an alternative for them.
But smaller organizations still require cost-effective security tooling. And when MSPs managing tenants for dozens or hundreds of small businesses use threat detection and response products that weren’t designed for the job, it creates risks that can put key customer relationships in jeopardy.
Here’s how:
Some enterprise tools are single tenant only
Not every threat detection and response tool offers multi-tenant capabilities, and many are cumbersome to manually configure and maintain. MSPs using these tools must invest considerable time and effort to ensure that they are not leaving security gaps in the tenant environments they are responsible for protecting.
A large company can often afford to spend these resources. But an MSP primarily serving SMBs often can’t, especially if it needs to be done separately for dozens or hundreds of tenant environments.
ITDR products are limited in scope
Many enterprise threat detection and response products are ITDR solutions, which means they only evaluate identity signals.
A product like this watches sign-ins, compares them against a baseline, flags what looks anomalous, and raises alerts. Because it cannot see the devices, applications, and data those sign-ins connect to, it has no way to check its own conclusions before it interrupts somebody.
Products with these limitations often produce high volumes of false-positive alerts, even within a single tenant environment. When MSPs managing multiple tenants rely on them, it can create a dangerous phenomenon known as alert fatigue.
Alert fatigue distracts from genuine threats
Imagine that an employee flies to Florida for a few days of customer meetings. In the hotel that evening, they connect to a VPN so they can watch Netflix on their laptop, which places their apparent location somewhere else entirely.
Reading sign-in data alone, this appears to be a sign of impossible travel: two sign-ins from locations too far apart for the time between them. Identity-only security tooling interprets this as a sign of an attack in progress and sends an alert. Then an engineer spends twenty minutes establishing that an employee watched a film.
When this kind of thing happens infrequently within a single tenant, it’s a minor irritation. Across ninety tenants, it buries engineers under mountains of meaningless alert signals.
Engineers overwhelmed this way may fail to notice the signs of a genuine attack in progress, or even turn off alerts to stop the noise and lose the ability to identify threats at all.
Related: Measuring the cost of alert fatigue for multi-tenant MSPs
MSPs need purpose-built threat detection and response tooling
An MSP facing the challenges described above will likely struggle to respond to threats in a timely and effective manner.
Connecting the signs of a coordinated multi-tenant attack would mean logging into each tenant in turn, cross-referencing sign-in data against device records, checking mail activity and file access, and then repeating the entire exercise across the rest of the estate to find out whether the same indicators appeared anywhere else.
By the time that work is finished, there is no telling what data may already have been compromised. This approach does not allow MSPs to offer a reliable security service to customers.
What MSPs need instead is tooling that automatically correlates threat signals across Microsoft 365 environments for each managed tenant in the estate and presents all the results in one place.
Multi-tenant correlation via inforcer TDR
inforcer TDR is built on the same Microsoft integrations that power 365 Manager, our multi-tenant management platform for Microsoft 365. 365 Manager is a “left of boom” solution that helps MSPs harden their estates by pushing policies and configurations across managed tenants from a single dashboard.
inforcer TDR brings the same capabilities to a “right of boom” solution that enables MSPs to efficiently identify and remediate incidents across multiple tenants. It reads telemetry from across the products under each customer’s Microsoft 365 licence rather than from identity alone:
- Entra ID for sign-ins and identity events
- Intune for device state, compliance and network context
- Exchange Online for mail activity and mailbox rules
- SharePoint and OneDrive for file access and sharing
- Purview for data movement
The added context from these signals allows inforcer TDR to meaningfully distinguish genuine threat signals from routine business activities. It also arms MSPs with more actionable data when a real threat occurs, and enables them to use that data to improve security for every tenant in their estate.
Fewer false positives
Let’s go back to the previous example of the employee in Florida. Instead of sending a false-positive alert for impossible travel, inforcer TDR would be able to check their sign-in against Intune. From there, it would be able to identify the managed device and the VPN connection that explain the location and avoid sending an alert for a non-event.
Related: The Six Layers of TDR for Microsoft 365 (& Why ITDR Alone Isn’t Enough)
Tracking attack trails
Cross-product telemetry does more than suppress noise. When an attack succeeds, inforcer TDR gives you the trail.
An identity-only tool can tell you that a brute force attempt worked and someone is now inside the tenant, which is the point at which its usefulness ends. Because inforcer TDR can see across the estate, it can follow what happened next:
- Whether the account has started sending mail (internally or externally)
- Which SharePoint and OneDrive files were opened, downloaded, or shared
- What data actually moved through Purview
- How the compromise began: a clicked link, a consent grant, a stolen token, etc.
Preventing future incidents for every tenant you manage
Once you’ve dealt with a threat, the Prevention tab in inforcer TDR also shows the controls that would most likely have stopped the incident in the first place. From there, you can push the required changes through 365 Manager—not just to the affected tenant, but to every other tenant carrying the same gap.
Your inforcer dashboard shows every tenant you manage in the same place. That means:
- Patterns become visible. This means the signs of a coordinated multi-tenant attack appear next to each other rather than in three unrelated queues, and are far less likely to be missed or misinterpreted.
- Responses can be coordinated. When something is confirmed in one environment, you can act across every environment exposed to it, in the same working session.
- Service becomes consistent. You get consistent visibility for every tenant instead of checking them at random or at long intervals. This improves the quality of service that every customer receives.
Related: How MSPs Can Turn Every Breach Into Stronger Long-Term Prevention
Proving the value of your security service to customers
Threat detection and response tooling designed for MSPs does more than improve your accuracy and response times. It also allows you to show customers the gaps in their tenants, the risks that followed, the fixes you implemented, and the money you saved them.
Taken together, that is the difference between a security service your customers question and a security service they trust. None of it requires you to be a larger business with a dedicated security operations centre. It simply requires tooling designed to help you protect multiple tenant environments at once instead of one at a time.
Ready to deploy effective threat detection and response across your entire estate?
Book a demo of inforcer TDR to see multi-tenant correlation running against the environments you manage.
FAQs
What is multi-tenant threat detection and response?
Multi-tenant threat detection and response is the ability to contextualize alert signals from every Microsoft 365 tenant an MSP manages inside a single view. Signals are correlated across identity, devices, mail, files, and data movement within each tenant, and those correlated results are then displayed for the whole estate in one place.
Why aren't most threat detection and response tools suitable for MSPs?
Most threat detection and response products were not built to serve MSPs. They are instead aimed at large enterprise-level organizations. As such, they often require complicated manual configuration and considerable billable hours per environment, which does not scale to dozens or hundreds of tenants. They may also lack capabilities that help identify the signs of a coordinated attack running across separate managed tenants in an MSP’s estate.
Is inforcer TDR an ITDR product?
No. ITDR stands for identity threat detection and response, which evaluates sign-in and identity signals alone. inforcer TDR correlates alert signals across multiple layers of the Microsoft 365 ecosystem, including devices, mail, files, and data movement, so it can check identity-based conclusions against what is happening elsewhere in the tenant.
Which Microsoft 365 services does inforcer TDR read telemetry from?
inforcer TDR reads telemetry from across the products under each customer's Microsoft 365 licence: Entra ID for sign-ins and identity events, Intune for device state, compliance, and network context, Exchange Online for mail activity and mailbox rules, SharePoint and OneDrive for file access and sharing, and Purview for data movement.
Why do identity-only security tools produce so many false positives?
An identity-only tool watches sign-ins and flags what looks anomalous, but it cannot see the devices, applications, and data those sign-ins connect to, so it has no way to check its own conclusions. A VPN connection that explains an apparent impossible travel alert stays invisible to it.
Do MSPs need a security operations centre to detect threats across multiple tenants?
No. A dedicated SOC is one route to reliable detection across an estate, but it takes significant investment in staff and environment tuning. Tooling purpose-built for multi-tenant estates delivers correlated detection and a single-pane view of every managed tenant without the MSP having to become a larger business.
Share this
Live demo with Co-founder,
Will Connor
Want to see inforcer in action? Join a live platform demo with inforcer Co-founder and Chief Community Officer, Will Connor to explore how inforcer could benefit you.
You may also like
These related stories

ITDR, XDR, SIEM, MDR: A Plain-English Guide to the Microsoft 365 Security Alphabet for MSPs
