Your Customers Already Have IAM. Turn Identity Signals Into Your Next Managed Service.

Why MSSPs Are Betting on AI—But Still Missing the Power of NDR

How MSSPs can use Stellar Cyber to package identity insight into a timely, scalable
managed service that creates new recurring revenue and deeper customer value.

The opportunity: turn identity telemetry customers already generate into a managed service
that detects abnormal behavior, correlates it with the broader attack, guides response, and
proves value with tenant-specific reporting.

MSSPs are always looking for the next service customers will actually pay for.

Identity security may be one of the clearest opportunities right now.

Most customers already have IAM. They have Active Directory, Microsoft Entra ID, Okta, MFA and access policies. Those tools help answer an essential question:

Who should have access?

But attackers increasingly work through identities that already have access.

A password is stolen. A session is hijacked. A service account is abused. A legitimate user suddenly logs in from an unexpected location, accesses a system they have never touched before or starts behaving unlike themselves.

That creates an opportunity for MSSPs to answer a much more valuable question:

What are your identities doing right now – and which ones should you worry about?

With Stellar Cyber, MSSPs can turn those signals into a recurring managed service.

Not another identity tool. Identity insight.

Start with the identity data customers already have

The first advantage is simple: MSSPs do not need to create a new identity stack.
Stellar Cyber can ingest identity-related data and use it alongside the rest of the customer’s security
telemetry.
For Microsoft Entra ID, Stellar Cyber can collect sign-in logs, audit events, risk detections, risky-user
information, user profiles and service-principal sign-ins. User information from Entra enriches Stellar
Cyber’s Interflow records and provides profile context for User Behavior Analytics. Stellar Cyber KB: Microsoft Entra ID connector
That matters because the MSSP can move beyond:

“An identity event occurred.”
to:

“This user behaved differently, and here is what happened around that identity.”

That is a much more valuable service conversation.

Detect behavior IAM was not designed to explain

Stellar Cyber already includes multiple behavioral signals that MSSPs can turn into identity-focused insights.
Signal What it tells the MSSP
Impossible Travel A user appears to authenticate from locations that are not realistically reachable in the time observed.
User Login Location
Anomaly
A user authenticates from a location that is unusual relative to prior behavior.
Login Attempt Location
Count
An identity appears from an abnormal number of locations.
Login Time Anomaly A user logs in at a time that is unusual for that identity.
User Asset Access
Anomaly
An identity accesses an asset that differs from its established behavior.

Many of these detections are explicitly tagged in the platform as User Behavior Analytics and Identity
Detection. Stellar Cyber KB: ML detections using traffic data

Stellar Cyber 6.6 improves the fidelity of this layer. The release adds customizable suppression for
Impossible Travel and User Login Location anomalies, prioritizes records that contain usernames for
Impossible Travel, and adds ASN enrichment to those alerts. Stellar Cyber KB: 6.6 release notes

You are not trying to monetize more alerts. You are trying to monetize better answers.

Make identity part of the attack story

This is where the service becomes differentiated.
An identity-only alert can tell an analyst that a login looks suspicious. It cannot necessarily explain
what happened next.
Stellar Cyber’s Case Analysis view connects users with hosts, processes, files, services, URLs and
other entities in a graphical attack view. Since 6.3, Stellar Cyber can connect users to related hosts
even when the underlying event is not itself classified as UBA. Stellar Cyber KB: Case Analysis

That is much more compelling than forwarding an Impossible Travel alert to the customer and asking
them to investigate.

The service becomes: We detected suspicious identity behavior. We correlated it with the rest
of your environment. We determined whether it represented an attack.

Use automation to make the economics work

A new managed service only works if the MSSP can deliver it without adding analysts at the same rate it adds customers.

Stellar Cyber’s Alert Auto Triage can automatically investigate alerts and assign verdicts such as True
Positive, Benign True Positive, False Positive or Inconclusive. In 6.6, analysts can filter on those verdicts directly in the Alert Table and Threat Hunting views and access response actions from the triage page. Stellar Cyber KB: 6.6 release notes

The investigation can also incorporate real-time identity lookups from integrations such as Okta and Microsoft Entra ID, alongside endpoint telemetry, threat intelligence and other evidence. Stellar Cyber KB: Alert Auto Triage performance

Machine does the repetitive enrichment and first-pass investigation. Analyst focuses on the identity activity that deserves attention.

That is what makes the service easier to scale across tenants.

Do not stop at detection

Customers ultimately care about what happens after something suspicious is found.

For Microsoft Entra ID, Stellar Cyber supports response actions including disabling a user, confirming a user as compromised, revoking existing sign-in sessions, dismissing user risk, removing a user from a group, and adding a user to a group. Those actions depend on the appropriate Microsoft licensing and permissions. Stellar Cyber KB: Microsoft Entra ID connector and response actions

This gives MSSPs a natural path to service tiers:

Potential service tier Customer value
Identity Monitoring &
Insights
Detect and report on meaningful identity anomalies.
Managed Identity
Investigation
Add analyst validation, correlation and case context.
Managed Identity Response Add customer-approved response playbooks such as session revocation or account disabling.

Package the value so customers see it

This may be the most important part of the business model.

Customers need to see what the MSSP did.

Stellar Cyber can create recurring tenant-specific reports and exported-dashboard reports. An MSSP can generate discrete reports for each tenant, schedule them daily, weekly or monthly and ensure
each tenant receives only its own information. Tenant-group branding can also replace Stellar Cyber branding on supported reports. Stellar Cyber KB: Reports

That makes it possible to build a repeatable Identity Security Insights Report showing:

Here are the identities that changed behavior. Here is what we investigated. Here is what mattered. Here is what we did about it.

That makes invisible security work visible. And visible value helps retention.

Built to deliver across customers, not one customer at a time

The final piece is scale.

Stellar Cyber’s multi-tenant architecture is designed to support MSSPs, including tenant data segregation, machine-learning customization and centralized operational views. Stellar Cyber KB:
Administrator overview and multi-tenancy

Reporting can be generated per tenant automatically. In supported scenarios, a Modular Sensor can also ingest logs for multiple tenants while preserving the correct tenant identity on the records. Stellar Cyber KB: Multi-tenant log ingestion

Licensing administration also exposes tenant allocation and usage so MSSPs can understand
capacity consumption across customers. Stellar Cyber KB: System licensing

Build the service once. Deliver it across the customer base.

From identity signals to recurring revenue

Your customers already have identity infrastructure. What many of them do not have is a team continuously asking: Is this identity behaving normally? Is this suspicious behavior connected to something happening on the endpoint, network or cloud? Does someone need to investigate? Do we need to act? That is where an MSSP can add value. Stellar Cyber provides the identity telemetry, behavioral detection, correlation, investigation, response and multi-tenant reporting needed to turn those questions into a managed offering.

Turn identity signals into insight.

Turn the insight into a service.

Turn that service into new recurring revenue - while giving customers another reason to stay.

Scroll to Top