Huntress ITDR vs Defender for Identity: same name, different problem
Defender for Identity installs sensors on domain controllers. If your business has no on-premises Active Directory, there is nothing for it to watch.
Read articleIdentity Security
Compare five identity-security options for Microsoft 365 and Google Workspace by coverage, who responds, pricing model, contract term and minimum.
Obsidian Ridge's Ridge Core costs $25 per person per month, month-to-month, with no minimum; managed endpoint detection and response and Microsoft 365 or Google Workspace identity monitoring are included. Business onboarding is separate. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. 9
For identity security, the first buying question is whether the service actually covers your email and identity platform. The second is who can investigate and act. A tool that produces risk scores and a managed SOC service place different responsibilities on your team.
We publish this comparison as Obsidian Ridge, which appears in it and uses Huntress. This is a sourced comparison of buying models, not an independent performance ranking. Commercial details and product documentation were checked on October 1, 2026.
“Not published” means the cited page does not disclose that fact. Do not read it as no minimum, no contract, or no capability. The Microsoft and Push rows are self-run contrasts to the managed services. Scroll the table sideways to see each column when it is wider than the page, or focus it and use the arrow keys.
| Provider | Microsoft 365 coverage | Google Workspace coverage | Who responds | Pricing model | Contract term | Minimum |
|---|---|---|---|---|---|---|
| Huntress ITDR (direct) 1 2 | Microsoft 365 identity monitoring and response 2 | Google Workspace identity and email monitoring and response 2 | Huntress's 24/7 SOC; the direct buyer owns deployment, portal management and follow-through on incident reports 1 2 | Published: $4.80 per licensed identity per month at 50 licensed identities; $240.00/month at that floor 1 | 12 months standard 1 | 50 per product 1 |
| Blackpoint (Cloud MDR / identity) | Microsoft 365 supported 3 | Google Workspace supported 3 | Blackpoint human-led SOC with active response 3 | Quote-only; public rate not published 4 | Cloud MDR Essentials offers month-to-month; confirm partner terms 3 | Base minimum not published; do not mistake the endpoint volume-discount threshold for an identity minimum 3 |
| Microsoft Entra ID Protection (self-run) | Entra identity and sign-in risk detection; risk-based access controls 5 | No native Workspace tenant or mailbox monitoring documented; this is Entra identity coverage 5 | Your administrator plus configured automated risk policies 5 | Published: Entra ID P2 $10/user/month paid yearly; included in some bundles 6 | Annual commitment for the cited P2 offer 6 | Seat floor not published on the reviewed pricing page 6 |
| Push Security (self-run platform) | Microsoft 365 integration, including mail-forwarding monitoring and browser detections 7 | Google Workspace integration, including mail-forwarding monitoring and browser detections 7 | Your team receives alerts; platform can monitor, warn or block; staffed SOC not stated 7 | Published: $6/employee/month monthly or $5 on an annual contract; enterprise quote above 500 7 | Monthly or annual, billed in advance 7 | Not published on the reviewed pricing page 7 |
| Obsidian Ridge managed ITDR (Ridge Core) 8 9 | Microsoft 365 monitoring included 8 9 | Google Workspace monitoring included 8 9 | Huntress SOC 24/7; CISSP-led follow-through within one business day 8 9 | Published: $25/person/month, bundled with endpoint MDR; onboarding separate 9 | Month-to-month 9 | No minimum; start with one person 9 |
The coverage descriptions are deliberately narrower than a “yes” checkbox. Entra ID Protection covers Entra risk signals; the reviewed documentation does not describe native Google Workspace mail-rule monitoring. Our conclusion about that limitation follows from the documented scope, not from a test of every possible Microsoft integration. 5
Ask for the detection and response matrix for the tenant you use. A Microsoft 365 screenshot does not prove the same mail, OAuth or session controls exist for Google Workspace. Likewise, a browser extension observes browser activity; that is a different collection point from a service monitoring tenant events.
Huntress's expansion announcement describes Microsoft 365 and Google Workspace coverage, but it is not a promise that every detection is identical. Blackpoint's Essentials datasheet lists both services. Push lists both integrations and browser controls. Those are useful shortlist criteria, followed by a technical scope check. 2 3 7
The managed ITDR service page separates the platform-specific features in our service. The endpoint MDR overview covers computers; neither should be used as evidence that every identity or application is automatically covered.
Ask who investigates, who can revoke a session or disable an account, and who approves restoring access. Get the normal follow-through hours and the after-hours process in writing. A risk-based access policy is valuable, but it does not remove the need for an administrator to investigate an exception or recover an account.
Microsoft documents automated risk remediation and administrator-led investigation. Push describes configurable blocking and alert integrations. Huntress and Blackpoint describe managed SOC response. Our service adds deployment and CISSP-led follow-through to the managed platform, with the division of responsibilities published on pricing. 1 3 5 7 9
The Obsidian Ridge figure includes endpoint MDR as well as identity monitoring. Huntress's direct ITDR line is a separate product. An Entra P2 licence is a self-run software purchase. Comparing those prices as if each bought an identical response service would hide the work you still own.
For a renewal, ask what records you can export and who turns them into accurate questionnaire answers. The cyber-insurance questionnaire is a starting checklist, and the Readiness Sprint is a separately scoped evidence engagement. A detection feature is not a guarantee that an insurer accepts a control answer.
1. Huntress pricing: commercial values and direct-buyer responsibilities from the canonical Huntress facts module, last checked September 30, 2026.
2. Huntress Google Workspace ITDR announcement: platform coverage and managed response.
3. Blackpoint MDR Essentials datasheet: cloud coverage, active response, monthly terms and endpoint volume-pricing conditions. Confirm current partner scope in a quote.
4. Blackpoint pricing: rates are not publicly disclosed.
5. Microsoft: what is Entra ID Protection?: risk signals, automated policies and administrator investigation. Native Google Workspace tenant monitoring is not described in this scope.
6. Microsoft Entra plans and pricing: the live US page checked October 1 lists P2 at $10/user/month paid yearly. Older indexed snippets showed $9; the table uses the fetched pricing page. Confirm the licence and region in your quote.
7. Push Security pricing and FAQ: integrations, browser controls, response modes, monthly and annual rates. No minimum or staffed SOC service stated on the reviewed page.
8. Obsidian Ridge managed ITDR: supported tenants and the service scope.
9. Obsidian Ridge pricing: Ridge Core, included ITDR, onboarding, term, minimum and operating responsibilities.
Bring your platform, licences, headcount and the name of the person who owns account recovery to the first conversation. For Google Workspace, ask to see Google-specific detections and response actions. For Microsoft 365, separate the capabilities already in your licence from the service that will operate them. That is a clearer starting point than buying a broad “identity protection” label.
Last updated
October 2, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
Huntress Managed ITDR and Blackpoint Cloud MDR publicly describe both platforms. Obsidian Ridge operates Huntress ITDR for either platform within Ridge Core. Confirm the detections, permissions and response actions for your exact tenant; support for both platforms does not imply identical features.
No native Google Workspace mailbox-monitoring coverage is documented for Entra ID Protection in the sources reviewed here. It detects risk in Entra identities and sign-ins. A Google application using Entra for sign-in does not make every Google tenant event visible to Entra ID Protection.
The reviewed Push offering is a browser-security platform with Microsoft 365 and Google Workspace integrations, automated controls and alerts for your security team. A staffed SOC response service is not described on that pricing page.
Assign an operator or ask a partner to include managed response explicitly.
Obsidian Ridge's Ridge Core costs $25 per person per month, month-to-month, with no minimum; managed endpoint detection and response and Microsoft 365 or Google Workspace identity monitoring are included. Business onboarding is separate.
Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States.
Business onboarding is separate: $500 for up to 25 machines, $1,000 for 26 to 100. This is a bundle price, not a standalone ITDR licence price.
Related reading
Defender for Identity installs sensors on domain controllers. If your business has no on-premises Active Directory, there is nothing for it to watch.
Read articleA scenario walkthrough of what Identity Threat Detection & Response should catch when an attacker tries to redirect payroll wires over a long weekend.
Read articlePlain-English 2026 buyer guide to the three email-security architectures small businesses actually pick between: built-in Defender or Google Workspace.
Read article