MDR for Microsoft 365, delivered by you
Your smallest clients are asking for security, and what you know is too expensive and too heavy for a thirty-user tenant. Attic MDR is the layer you put alongside it: multi-tenant, partner pricing, no minimum purchase.
A month of Partner Portal access with an NFR licence for Attic MDR, for you to use. This is not the fourteen-day trial your client gets.
Rather talk first? Book a thirty-minute partner call.
What you earn on it
This is the first question any MSP asks, so it goes first.
You start at a 20% partner discount on list price. It grows with your total volume; you get the tiers in the partner call.
No minimum purchase and no unit minimum. A twelve-user client is fine.
Cancellable monthly. Your client is not locked in and you do not have to defend an annual contract.
Something to give away
A free offer you hand out yourself, without losing the client relationship.
The IVON incident investigation is free and one-off. Your client has one Defender incident from their own environment investigated through a Microsoft consent, with no account and no sales call first, and has the report within minutes.
In the Partner Portal you create your own short link to that investigation in one go. Every request that comes through it carries your name. English-speaking visitors land on the English page automatically.
And what happens next: for a request through your link, your client gets no follow-up email from us. We contact you about the next step, and you set the pace.
What it costs you in work
Close to nothing, and that is the point. Attic is not a service you have to run yourself.
Switch a client on
Self-service onboarding, live within 5 minutes. Per client you choose read-only or write for automatic remediation. Attic asks for those permissions once, during onboarding; there is no second consent prompt at the moment something needs to be fixed.
We take the night shift
Every Defender alert is picked up, assessed and closed with a verdict. Status and conclusion go back into Defender, so you see them where you are already looking. If something escalates, you hear about it by email, webhook or a push notification in the Attic app. Attic does not call you.
Your client gets the reporting
Every client gets a monthly summary of the alerts that were handled. For an escalated incident, the full timeline is in the report.
Connect your CSP account, if you want to
Optional and one-time. With the connection you get a single view across your whole client base in the MFA Posture dashboard: which clients have MFA watched by Attic and which do not yet. Without it, Attic MDR works exactly the same, you just miss that overview.
In July 2026, thirteen connected beta environments received 165 Defender XDR alerts. All 165 were handled by IVON: picked up, assessed and closed with a verdict. On incidents where automatic remediation is enabled, the time from pick-up to verdict is consistently under six minutes.
Identity first, endpoint second
The order we look in, and why it is that order.
The biggest threat in a Microsoft 365 tenant is not malware on a laptop, it is an account quietly changing hands. A hijacked session looks like an ordinary working day in the logs. So every investigation starts at the identity, and that is what identity-first means.
Endpoints are part of it. IVON takes the Defender for Endpoint alerts into the same investigation, alongside the identity signals, and on IVON's advice Attic can act: revoke a session, clear up persistence or isolate a system. One service that looks at both, instead of two dashboards nobody reads.
Where you put Attic alongside
Already have a security vendor? Nothing has to change there. What works for a hundred users rarely fits a client with thirty: too expensive, too heavy, too much work to switch on. That segment is what Attic was built for, and it is probably the part of your portfolio you currently cannot serve.
If you are looking outside Europe for something affordable for that segment, this is the difference: affordable and European is not a trade-off. Attic is Dutch. Our team, our infrastructure and your clients' data stay inside Europe.
Even on a good licence, work is left undone
Attic MDR works from Microsoft 365 Business Premium up. Every step above it adds detection sources: Business Premium to E3 to E5, with Defender for Identity and Entra ID Protection on top. The alert stream grows with it, the capacity to look does not. E5 is not pointless, but that investment only pays off once someone follows up on every alert. Attic delivers that follow-up from Business Premium onward and never asks your client to upgrade. For picking clients, that is the only licensing question that matters: Business Premium or higher.
What you get to sell it with
You do not have to write a security story. It is ready.
Brochure, pitch deck, talk track and a price sheet. Ready to use, under your own name.
Research from Attic Lab: new attack techniques, and what your clients notice of them.
Joint campaigns and events, if that is useful to you.
Frequently asked questions
What does it cost, and what do I keep?
What do I get when I start the trial?
Can I offer the incident investigation to my own clients?
Can I offer it under my own brand?
Do I need a Microsoft CSP?
What does my client notice of all this?
What happens if something goes wrong at night?
Which Microsoft 365 subscriptions are supported?
What is in Attic MDR?
Can I buy individual components?
How does this help my clients with NIS2?
How do I get support?
Take a month to look at it
A month of access to the Partner Portal with an NFR licence for Attic MDR, for you and not to sell on. No credit card, no obligation.
Rather have a thirty-minute call first? We will walk through your portfolio, show you the Partner Portal and work out the margin with you. Book a partner call.