Huntress launches Managed ISPM for Microsoft 365 identity hardening
Huntress has announced general availability of Managed Identity Security Posture Management (ISPM), adding proactive identity controls to its Agentic Security Platform. The product, which targets account takeover, business email compromise, unauthorised logins and privilege misuse, extends coverage beyond Entra ID to include Microsoft Exchange, SharePoint and Teams.
The Columbia, Maryland-based cybersecurity vendor says Managed ISPM was developed in part from its acquisition of Inside Agent less than a year ago, and draws on findings from an early-access programme spanning more than 12,000 Microsoft 365 tenants. That data revealed significant configuration gaps: more than 60% of organisations lacked at least half of Huntress's recommended ISPM controls, 66% had incomplete MFA configurations, 59% were missing key admin-account restrictions, and 55% had standard users who could perform administrative functions.
What the GA release adds
General availability introduces three capability expansions beyond the early-access baseline. First, coverage now extends to Exchange, SharePoint and Teams, closing attack paths commonly exploited for business email compromise and data exfiltration. Second, a Learning Mode allows security teams to model the blast radius of a Conditional Access policy before it is enforced, addressing a common barrier to rollout. Third, a Managed Deployments feature provides continuously updated policy baselines informed by attacker behaviour, Microsoft guidance and industry standards, removing the burden of maintaining static configurations in-house.
Huntress reports a policy rollback rate of less than 0.04% across tens of thousands of policies deployed during early access, a figure it uses to argue the product can harden environments safely at scale. Based on Managed ITDR data from the past six months, the company says fully deploying the available posture controls could have prevented 35% of identity-based incidents, with that figure projected to reach 80% by the end of Q3 2026 as additional controls are added. Both numbers are vendor-reported and have not been independently verified.
Prakash Ramamurthy, Chief Product Officer at Huntress, said: "Managed ISPM was built to solve that challenge. In Early Access, it proved it can harden environments safely at scale, and General Availability builds on that with new capabilities that deliver broader coverage, easier onboarding, and smoother policy rollouts."
Market context and competitive landscape
Identity security posture management has emerged as a discrete product category over the past two years, spun out of the broader identity threat detection and response (ITDR) market. Vendors including CrowdStrike, Microsoft itself (via Secure Score and Entra ID Protection), Semperis and Silverfort compete across overlapping segments of identity hardening, active-directory security and posture assessment. Huntress differentiates partly on its managed-service model and its focus on the SMB and MSP channel, a segment often underserved by enterprise-oriented platforms whose complexity demands in-house identity expertise.
The timing matters: identity-based attacks accounted for 79% of critical and high-severity incidents Huntress responded to in 2025 by the company's own count, a figure consistent with broader industry reporting that credential compromise has overtaken vulnerability exploitation as the primary initial-access method. The EU's NIS2 Directive and DORA, both now in force, impose tighter identity governance and access-control requirements on organisations operating in the EU, increasing commercial pressure on ISPM adoption beyond North America.
Huntress currently reports protecting more than 5 million endpoints and 13 million identities. The company has not disclosed revenue, funding stage, or a roadmap for extending Managed ISPM beyond the Microsoft 365 ecosystem to Google Workspace or other identity providers. Both would be logical expansion vectors, and their absence from the release suggests the Microsoft-first strategy will hold for at least the near term.