Managed identity security

Identity Monitoring

Microsoft 365 and Google Workspace identities are monitored 24/7 for account takeover, stolen sessions and suspicious access.

Managed by JCPIT For Australian small business
Accounting business owners reviewing account security with an IT adviser

JCPIT’s identity monitoring is for businesses that rely on Microsoft 365 or Google Workspace but do not have someone watching account activity around the clock. Security analysts investigate suspicious identity activity 24/7, while JCPIT manages the service and the practical follow-up.

Source: Huntress Managed ITDR documentation and Microsoft security guidance.

A valid login can still belong to an attacker

MFA is essential, but attackers also steal browser sessions, trick users into approving malicious apps and create inbox rules that hide their activity. Once they are signed in, the activity can look normal unless someone checks the surrounding evidence.

What the service watches for

  • Suspicious logins — access from unusual locations, risky networks or infrastructure commonly used during attacks
  • Session hijacking — stolen browser tokens that let an attacker appear already authenticated
  • Malicious inbox rules — rules that hide replies, payment messages or security warnings during business email compromise
  • Rogue applications — risky OAuth apps that can keep access after a password is changed
  • Credential theft — signals that an account or authentication method may have been compromised
  • Unexpected account changes — activity that needs investigation before it becomes a wider incident

How the response works

  1. JCPIT connects the Microsoft 365 setup — the monitoring service integrates with Microsoft 365 or Google Workspace using approved access.
  2. The service monitors identity signals — detections focus on suspicious behaviour rather than sending every raw log event to your team.
  3. An analyst investigates — the 24/7 security operations centre checks the surrounding account, inbox and application activity.
  4. Supported access can be revoked or isolated — the response depends on the platform, integration and incident. Microsoft 365 and Google Workspace capabilities are not identical.
  5. JCPIT handles the business response — we explain what happened, reset or harden access where required and help staff return to work safely.

Technology behind the service

Huntress provides the identity detections, threat investigation and 24/7 analyst coverage. JCPIT manages onboarding, Microsoft 365 or Google Workspace settings and the customer response around each incident.

What you get

  • 24/7 Microsoft 365 and Google Workspace identity monitoring
  • Human investigation of credible threats
  • Account takeover and business email compromise detection
  • Suspicious login and malicious inbox-rule detection
  • Rogue app and session-theft visibility where supported
  • Clear incident context and remediation guidance
  • JCPIT-managed response and account hardening

Frequently asked questions

Suspicious sign-ins, risky locations, stolen sessions, malicious inbox rules, rogue apps and unusual account changes across Microsoft 365 or Google Workspace.

It helps detect and contain account takeover sooner, but no service can guarantee prevention. The response depends on the platform and incident, and may include revoking sessions, isolating an identity or carrying out guided remediation.

MFA is important, but it is not the whole answer. Attackers also target tokens, consent abuse, and session theft, so monitoring adds another layer.

No. Huntress supports Microsoft 365 and Google Workspace, although some response capabilities differ between the platforms. JCPIT confirms what is available during onboarding.

Other Services

Ready to get protected?
Find out where your business is vulnerable with our free, no-obligation security check.