Whether you’re a one-person operation or a growing business with a full team, we’re here to help. Get in touch and let’s talk about what we can do for you.
Microsoft protects the M365 platform — but protecting what happens in your tenant is your responsibility. ThreatLocker Choice extends ThreatLocker's zero-trust approach into Microsoft 365, watching for suspicious activity and applying conditional-access-style controls that go beyond what Microsoft provides by default.
ThreatLocker Choice is ThreatLocker's M365-focused security tier, combining Cloud Detect (anomaly monitoring across M365 audit logs) and Cloud Control (policy-driven posture controls for the tenant). It's the cloud layer of your Cloud Security Pack.
Any business running Microsoft 365. M365 is the most targeted enterprise platform in the world, and Microsoft's built-in controls leave gaps that ThreatLocker Choice is specifically designed to fill.
M365 audit log monitoring, anomaly detection and alerting, conditional-access controls, policy management via ThreatLocker console, and integration with the broader ThreatLocker estate.
Closes the Microsoft shared-responsibility gap for M365, provides visibility of suspicious cloud activity, adds control that goes beyond what Microsoft 365 includes by default, and keeps cloud and endpoint security in one place.
Step 1
Step 2
Step 3
Step 4
Step 5
Yes — Microsoft 365 Business Premium includes Defender for Business and Entra ID P1. ThreatLocker Choice adds anomaly detection and posture controls on top, catching things Microsoft’s native tooling misses.
Impossible-travel sign-ins, mass file downloads, unusual inbox rules being created, unexpected MFA bypass events, and similar patterns that indicate account compromise or insider threat.
It enforces policy-based controls on your M365 tenant — for example, restricting access from unmanaged devices, preventing risky app permissions, or controlling what third-party apps can access in your tenant.
Cloud Detect and Cloud Control connect to M365 via API — no agent required on the device for this component. Your existing ThreatLocker device agent handles endpoint controls.
Yes. Account compromise often shows up as anomalous behaviour — unexpected logins, unusual activity patterns — which Cloud Detect is designed to surface.
No. Defender for Business and ThreatLocker Choice operate at different layers. We recommend running both together — they’re complementary.
Your WDYG IT team receives an alert and investigates. For critical anomalies, we’ll contact you directly.
Yes. ThreatLocker Choice monitors activity across the M365 suite — Exchange, SharePoint, OneDrive, and Teams.
Yes. ThreatLocker Choice (Cloud Detect + Cloud Control) is included in both Core and Complete Cloud Security Packs.
Yes. The audit logging and anomaly detection provide evidence of security monitoring that supports compliance frameworks including Cyber Essentials, ISO 27001, and GDPR.
There is nothing more annoying than an IT glitch that stops you working efficiently. However, knowing you have access to immediate attention to the glitch and a solution to it, is very reassuring and that is provided by We Do Your IT. We have so appreciated the availability and response given by the team at We Do Your IT, enabling us to remain a productive firm.
Richard Sharp – Sharp Family Law
This website uses cookies to improve your experience. Choose what you're happy with.
Required for the site to function and can't be switched off.
Help us improve the website. Turn on if you agree.
Used for ads and personalisation. Turn on if you agree.