Try Attic MDR free for 14 days
In your own Microsoft 365 tenant, connected in five minutes
You connect your own Microsoft 365 tenant and get the full Attic MDR package for 14 days. Every security incident is investigated and judged, day and night, and we carry out remediation once you have approved it. You do not need payment details to start. The day before the 14 days are up we ask whether you want to continue; without a payment method the trial stops by itself.
- No payment details to start
- Connected in five minutes
- Cancel any time, during the trial too
Start your trial
You pick your number of users first. You then see exactly what Attic MDR costs after the trial, and complete the order without payment details.
Whole numbers, from 1 user. The first 5 are covered by the €30 per month entry rate.
€150per month
Breakdown
| Monthly plan | Annual plan | |
|---|---|---|
| Attic MDR | €150 | €135 |
| Cost per month | €150 | €135* |
| Cost per year | €1,800* | €1,620 |
* Converted for comparison.
Active within 5 minutes. No payment details needed to start. Then €150 per month, cancel monthly.
An annual subscription with a 10% discount, or extra IVON capacity, is available on the pricing page.
MSP or IT provider? Start a partner trial.
What happens in those 14 days
No intake call, no waiting list, nothing to install.
Today, connect
You pick your number of users and complete the order without payment details. You then connect your Microsoft 365 tenant through the Microsoft consent screen. You share no passwords and you install nothing. Done in about 5 minutes.
Right after that, the first check
Attic runs more than a hundred checks against your configuration, inspired by the CIS benchmarks and extended with our own research at Attic Lab. Anything set incorrectly can be fixed with one click in the Attic app. At the same time monitoring is live: incidents arriving from that moment on get picked up.
The rest of the 14 days, the service itself
IVON, the agentic layer of Attic, investigates every incoming incident, delivers a verdict with the evidence behind it and proposes remediation. Attic carries that out once you have approved it. Notifications and escalations go by email, webhook or a push message in the Attic app, around the clock. We do not call you.
Five questions you probably have
- Do I have to install anything?
- No. Attic connects to Microsoft 365 through a Microsoft consent screen. Nothing lands on your endpoints and nothing goes into your network.
- Who gets access to my tenant?
- The Attic application, inside your own tenant, with the permissions listed on that consent screen. So you see them before you approve. Attic uses them to read the security data in your environment, including Microsoft Defender and Microsoft Entra ID. We change nothing without your approval.
- What if I do nothing after 14 days?
- Then it stops by itself. The day before the trial ends you are asked to register a payment method if you want to continue. If you do not, the trial ends after 14 days and you are charged nothing. You do not become a customer by staying silent.
- Can I get out again?
- Yes, at any time, during the trial too. You can also withdraw the consent in Microsoft Entra ID. From that moment Attic no longer has access to your tenant.
- What does it cost after that?
- Attic MDR costs €30 per month for the first 5 users. Above that €6 per user per month, and that rate drops as you add more. Cancel monthly, no annual contract needed. You see the amount for your own user count before you start the trial.
What is in the trial?
Everything in Attic MDR. The same package our paying customers use every day, nothing held back.
24/7 detection and response. Every incident is investigated and judged, with the evidence attached, and remediation follows your approval.
Protection against fake sign-in pages. Cloned Microsoft 365 sign-in screens are recognised before anyone types in their credentials.
Visibility on sign-in activity. You follow who signs in to your tenant, and from where.
More than a hundred security checks. Inspired by the CIS benchmarks, extended with our own research, and fixable with one click in the Attic app.
Notifications without phone calls. By email, webhook or the Attic app, day and night.
What otherwise sits untouched
In July 2026, thirteen connected beta environments received 165 Defender XDR alerts. All 165 were handled by IVON: picked up, assessed and closed with a verdict. Seven in ten of those 165 alerts (July 2026, thirteen connected environments) arrived, in our measurement, at the two lowest levels, Informational or Low.
Those are exactly the alerts that sit untouched at a small IT team. Not out of negligence, but because someone has to look at them and that someone is not there. In 14 days you see what arrives in that category in your own environment, and what happens to it when someone does look.
Ready to have your Microsoft 365 watched?
Start your 14-day trial today. No payment details to start, cancel whenever you want, from €30 per month after that.
Prefer a walkthrough first? Book a call with our security team.
Prefer a single report first?
The IVON incident investigation takes a one-off, free look at the incidents currently open in your Microsoft 365 tenant. One run, one report, no subscription and no trial. If you want continuous monitoring afterwards, the trial above is the next step.