Huntress vs ThreatLocker: block everything, or watch everything
ThreatLocker blocks what is not on the list. Huntress watches what gets through. Most businesses comparing them are asking the wrong question.
Read articleSmall Business Security
Defender for Identity installs sensors on domain controllers. If your business has no on-premises Active Directory, there is nothing for it to watch.
These two products share a category name — identity threat detection and response — and almost nothing else. Comparing them on features misses the fact that most small businesses cannot run one of them at all.
Disclosure: Obsidian Ridge is a Huntress MSSP partner and delivers Huntress-powered Managed ITDR. Read the recommendation below with that in mind. The technical facts below come from Microsoft's and Huntress's own documentation, cited throughout.
Microsoft Defender for Identity is sensor-based. Microsoft's deployment guide is specific:
"Install Defender for Identity sensors on all domain controllers, including read-only domain controllers (RODCs). If you have AD FS, AD CS, or Microsoft Entra Connect servers in your environment that aren't domain controllers, install the v2.x sensor on each of those servers as well."
— Microsoft Learn, retrieved 28 August 2026
Every documented sensor target is a Windows Server you run. Each sensor wants two cores, 6 GB of RAM and 6 GB of disk, plus a directory service account with read access. (Microsoft Learn.)
If your business is a dozen laptops and a Microsoft 365 tenant with no domain controller anywhere — which describes an enormous share of small businesses formed in the last decade — there is nothing to install and therefore nothing to monitor.
Microsoft's current overview page has broadened its language to mention Entra ID and other identity providers such as Okta, and that is fair as far as it goes. But the only documented API connector is Okta, and it is marked Preview. Cloud identity risk in the Microsoft stack is delivered by Entra ID Protection, a different product with its own licensing, surfaced alongside Defender for Identity in the unified portal.
That distinction is easy to miss and expensive to miss, because the licence that carries Defender for Identity is not cheap.
Defender for Identity requires an E5-class licence: EMS E5/A5, Microsoft 365 E5/A5/G5, Microsoft 365 E5/A5/G5/F5 Security, Microsoft 365 F5 Security and Compliance, or a standalone Defender for Identity licence.
Microsoft publishes no standalone per-user price for it. What is published on the Defender pricing page, retrieved 28 August 2026: Microsoft 365 E5 at $60.00 per user per month with Teams, $51.45 without, and the Microsoft Defender Suite at $12.00 per user per month. Both include Defender for Identity.
Huntress publishes Managed ITDR at $4.80 per licensed identity per month, and states it "works with all levels of Microsoft and Google licensing." A 50-seat minimum applies to direct purchases; through an MSP there is none.
So for a business on Microsoft 365 Business Premium, adding Defender for Identity means a licence uplift into E5 territory and standing up domain controllers to put sensors on. That is not a product decision, it is an infrastructure project.
Defender for Identity is built around on-premises Active Directory attack techniques — reconnaissance against the directory, lateral movement, domain dominance, certificate services abuse. If you run AD, that is genuinely valuable and there is no substitute for it.
Huntress Managed ITDR is built around the cloud identity attacks that dominate small-business incidents. From their product page: session hijacking — "Attackers grab session tokens, the digital keys that keep users logged in, and import them into their own browsers" — plus credential theft, rogue OAuth applications, location and VPN anomalies, and malicious inbox rules used in business email compromise. Google Workspace coverage went generally available in March 2026 and adds detections for attacker-created Gmail filters and unusual datacenter logins.
Notice these are not competing coverage claims. They are different attack surfaces. The reason it matters is that for most small businesses, the second list is where the actual losses happen — a wire redirected after a mailbox rule quietly filed the real invoice into Deleted Items.
Defender for Identity has no human triage attached. Microsoft sells that as Defender Experts MDR, which does list Defender for Identity among its qualifying prerequisites — so unlike Defender for Business, you would at least be eligible. No price is published; the page carries Contact Sales.
Huntress includes 24/7 SOC coverage in the ITDR subscription. Their current wording describes an "AI-assisted" SOC whose analysts provide investigation context and remediation guidance, and it is worth quoting them accurately rather than implying a purely human operation.
Defender for Identity is right for you if you run on-premises Active Directory, AD FS or AD CS, you already hold or can justify an E5-class licence, and you have someone who will work the alerts. Under those conditions it is a strong product doing something nothing else does as well.
It is wrong for you if you are cloud-only. Not weak — inapplicable. There is no sensor to install.
Huntress Managed ITDR is right for you if your identity risk lives in Microsoft 365 or Google Workspace, you want it monitored rather than merely logged, and you would rather not move your whole tenant to E5 to get identity coverage.
It is wrong for you if your crown jewels sit behind on-premises Active Directory and your real exposure is domain compromise. That is a different problem and it needs the on-prem product.
Do you have a domain controller?
If no, Defender for Identity is not a candidate and the comparison is finished. Your cloud identity options are Entra ID Protection inside the Microsoft stack, or a monitored ITDR service.
If yes, ask the follow-up: is your risk that someone breaks into your domain, or that someone takes over a mailbox? Most small businesses answer the second one, and quite a few of them run both products for exactly that reason.
Our Managed ITDR service covers Microsoft 365 and Google Workspace identities with no minimum seat count, and Ridge Watch pricing is public. If you are unsure which half of the identity problem you have, book a briefing and we will work it out with you.
Identity is now its own line on most carrier questionnaires, separate from endpoint. If that is what brought you here, the cyber insurance readiness view is the faster route: establish which identity question you have to answer, then pick the product that answers it with evidence you can produce.
Last updated
September 2, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
Microsoft's deployment documentation describes installing sensors on domain controllers, and on AD FS, AD CS or Entra Connect servers where those exist. There is no documented cloud-only deployment path. A business with no on-premises Active Directory has nowhere to install a sensor, so in practice there is nothing for the product to monitor.
Microsoft lists EMS E5 or A5, Microsoft 365 E5, A5 or G5, Microsoft 365 E5, A5, G5 or F5 Security, Microsoft 365 F5 Security and Compliance, or a standalone Defender for Identity licence. No standalone per-user price is published. Microsoft 365 E5 is listed at $60.00 per user per month with Teams, and the Microsoft Defender Suite at $12.00 per user per month, both of which include it.
Huntress publishes Managed ITDR at $4.80 per licensed identity per month on its own pricing page, with a 50-seat minimum per product for direct purchases and a 12-month standard term. There is no Huntress-required minimum when buying through an MSP.
Huntress lists session hijacking through stolen session tokens, credential theft, rogue OAuth applications, location and VPN anomalies, and malicious inbox rules used in business email compromise. Google Workspace coverage adds unexpected login activity, attacker-created Gmail filters and malicious datacenter utilisation.
Not within Defender for Identity itself. Microsoft sells that separately as Defender Experts MDR, which lists Defender for Identity among its qualifying prerequisites. No price is published for Defender Experts, which shows Contact Sales.
If you have no domain controller, Defender for Identity has nothing to install. Cloud identity protection in the Microsoft stack comes from Entra ID Protection instead, which is a different product with different licensing. Huntress Managed ITDR is built around Microsoft 365 and Google Workspace identities and works with all levels of Microsoft and Google licensing.
Related reading
ThreatLocker blocks what is not on the list. Huntress watches what gets through. Most businesses comparing them are asking the wrong question.
Read articleTodyl sells a six-module platform including the network layer, channel-only, with no published pricing. Huntress sells a layer and publishes its rates.
Read articleBoth run a 24/7 SOC for small businesses. Huntress publishes its prices and sells direct. Blackpoint publishes none and sells mainly through MSPs.
Read article