Whether you’re a one-person operation or a growing business with a full team, we’re here to help. Get in touch and let’s talk about what we can do for you.

ThreatLocker Choice (Cloud Detect + Cloud Control)

Anomaly detection and posture controls for your M365 environment

Microsoft protects the M365 platform — but protecting what happens in your tenant is your responsibility. ThreatLocker Choice extends ThreatLocker's zero-trust approach into Microsoft 365, watching for suspicious activity and applying conditional-access-style controls that go beyond what Microsoft provides by default.

Key Features Of This Package

Cloud Detect

Monitors Microsoft 365 audit logs for anomalies — impossible-travel sign-ins, mass downloads, unusual mailbox rule changes — and alerts your IT team when something doesn’t look right.

Cloud Control

Applies conditional-access-style posture controls to your M365 tenant, restricting what users and apps can do based on context and policy.

One vendor, end to end

ThreatLocker covers both your devices and your cloud — one agent, one policy engine, one console. No separate cloud security tool to manage.

Your Microsoft 365 tenant, monitored and protected.

Adam Gillett, Head Of Business Partnerships - We Do Your IT Support

What Is Our ThreatLocker Choice (Cloud Detect + Cloud Control)

ThreatLocker Choice is ThreatLocker's M365-focused security tier, combining Cloud Detect (anomaly monitoring across M365 audit logs) and Cloud Control (policy-driven posture controls for the tenant). It's the cloud layer of your Cloud Security Pack.

Why Choose Our ThreatLocker Choice (Cloud Detect + Cloud Control)

Any business running Microsoft 365. M365 is the most targeted enterprise platform in the world, and Microsoft's built-in controls leave gaps that ThreatLocker Choice is specifically designed to fill.

What's Included In Our ThreatLocker Choice (Cloud Detect + Cloud Control)

M365 audit log monitoring, anomaly detection and alerting, conditional-access controls, policy management via ThreatLocker console, and integration with the broader ThreatLocker estate.

Benefits Of Our ThreatLocker Choice (Cloud Detect + Cloud Control)

Closes the Microsoft shared-responsibility gap for M365, provides visibility of suspicious cloud activity, adds control that goes beyond what Microsoft 365 includes by default, and keeps cloud and endpoint security in one place.

How to become a customer

Step 1

Initial Enqiry

Step 2

Advice

Step 3

Setup

Step 4

Call For Support

Step 5

Billed In Arrears
Frequently Asked Questions About ThreatLocker Choice (Cloud Detect + Cloud Control)
We have complied a list of questions that are often asked about ThreatLocker Choice (Cloud Detect + Cloud Control) and how it can help your business. If you can’t see the answer to a question you have, please contact us today!

Yes — Microsoft 365 Business Premium includes Defender for Business and Entra ID P1. ThreatLocker Choice adds anomaly detection and posture controls on top, catching things Microsoft’s native tooling misses.

Impossible-travel sign-ins, mass file downloads, unusual inbox rules being created, unexpected MFA bypass events, and similar patterns that indicate account compromise or insider threat.

It enforces policy-based controls on your M365 tenant — for example, restricting access from unmanaged devices, preventing risky app permissions, or controlling what third-party apps can access in your tenant.

Cloud Detect and Cloud Control connect to M365 via API — no agent required on the device for this component. Your existing ThreatLocker device agent handles endpoint controls.

Yes. Account compromise often shows up as anomalous behaviour — unexpected logins, unusual activity patterns — which Cloud Detect is designed to surface.

No. Defender for Business and ThreatLocker Choice operate at different layers. We recommend running both together — they’re complementary.

Your WDYG IT team receives an alert and investigates. For critical anomalies, we’ll contact you directly.

Yes. ThreatLocker Choice monitors activity across the M365 suite — Exchange, SharePoint, OneDrive, and Teams.

Yes. ThreatLocker Choice (Cloud Detect + Cloud Control) is included in both Core and Complete Cloud Security Packs.

Yes. The audit logging and anomaly detection provide evidence of security monitoring that supports compliance frameworks including Cyber Essentials, ISO 27001, and GDPR.

Reassuring Availability

There is nothing more annoying than an IT glitch that stops you working efficiently. However, knowing you have access to immediate attention to the glitch and a solution to it, is very reassuring and that is provided by We Do Your IT. We have so appreciated the availability and response given by the team at We Do Your IT, enabling us to remain a productive firm.

Richard Sharp – Sharp Family Law