top of page

inforcer’s $50M Series C Tests Its MSP Security Strategy

Aug 15
13 min read

inforcer raised a $50 million Series C, putting its Microsoft 365 security strategy into Google News while creating a harder test for the company. The London startup must prove managed service providers can govern AI use across many smaller businesses without adding another layer of operational complexity.

Insight Partners led the round, according to funding coverage published July 30. The financing follows a $35 million Series B announced one year earlier. That pace makes the latest raise more than another cybersecurity funding event.

The underlying bet is that managed service providers, or MSPs, will become the practical AI security teams for smaller organizations. Those customers often lack dedicated specialists but still use Microsoft 365, cloud applications, and generative AI tools.

That creates a contest between centralized, repeatable governance and the messy reality inside individual customer tenants. Microsoft already supplies many underlying security controls. inforcer wants to make those controls manageable across an MSP’s entire customer base.

The opportunity is clear, but so is the dependency. inforcer’s platform relies heavily on Microsoft telemetry, licensing, and security architecture. Its value therefore rests on operational execution, not on replacing Microsoft’s defenses.

What the $50M Series C Actually Changes

The financing gives inforcer the resources to move from Microsoft 365 administration into a broader AI governance role.

inforcer provides a multi-tenant management platform for MSPs. A tenant is an organization’s isolated Microsoft cloud environment, containing its users, policies, applications, and data permissions.

An MSP might oversee dozens or hundreds of these environments. Without a central layer, engineers must repeatedly enter separate Microsoft portals, inspect configurations, apply policies, and document results.

inforcer aims to standardize that work. Its platform lets providers compare settings, deploy configurations, monitor policy drift, and manage security controls across multiple customers.

The new financing arrives after an unusually compressed fundraising cycle. inforcer announced its Series B round on July 22, 2025. Dawn Capital led that $35 million investment, with existing investor Meritech Capital participating.

That earlier announcement followed a $19 million Series A completed during autumn 2024. inforcer said it had launched in 2022, although some later reporting describes its operational launch as 2023.

The latest round therefore represents another significant capital injection within roughly one year. That speed signals investor confidence, but it also raises the expected pace of product development and international expansion.

The company has already widened its product narrative. It once focused primarily on policy standardization and Microsoft tenant management. Its newer materials emphasize Copilot readiness, shadow AI visibility, data governance, and recurring AI services.

Shadow AI means employees use generative AI applications without formal approval or oversight. The risk extends beyond whether an application appears on an approved list.

A worker might paste customer records, contract language, source code, or internal financial information into an external model. The organization may then lack an audit trail, retention policy, or reliable account of where that information went.

inforcer says its platform can expose AI application usage through Microsoft security data. It also presents adoption information for Microsoft Copilot, helping MSPs identify active users, unused licenses, and departments requiring support.

Those functions turn the funding story into a product execution story. The company is not simply adding another automated security scanner. It is trying to make AI governance a repeatable service that MSPs can deliver across many customers.

Google News visibility gives the round a broad audience, but financing does not validate that model by itself. The meaningful change is inforcer’s commitment to building an operating layer between Microsoft and the MSP market.

That position can become valuable if providers use it every day. It becomes less defensible if Microsoft makes comparable multi-tenant workflows easier inside its own administration tools.

Why AI Security Is Becoming an MSP Problem

Smaller businesses face enterprise-level AI risks without enterprise-level security teams, making their outside providers the natural control point.

Generative AI has changed how quickly employees can adopt new software. A browser-based assistant requires no infrastructure project, lengthy deployment, or formal procurement process.

That accessibility creates an asymmetric problem. Employees can begin using AI within minutes, while security teams may need weeks to review privacy terms, access controls, and data-handling practices.

Smaller organizations often have no team available for that review. They depend on an MSP to configure identities, endpoints, email protection, backups, and Microsoft 365 policies.

AI governance now sits across those same domains. An assistant can retrieve files through an authorized account, summarize broadly shared documents, or receive sensitive text through a browser prompt.

The problem is not limited to sophisticated AI-driven cybercrime. Many incidents can begin with ordinary configuration errors, weak credentials, excessive permissions, or unsanctioned applications.

Microsoft’s 2025 defense report describes threat actors using AI-assisted phishing and faster attack workflows. It also stresses that attackers continue exploiting familiar security gaps.

That distinction matters for inforcer’s strategy. The company does not need to build a model that predicts every new AI attack. It needs to help MSPs maintain the identities, policies, and data boundaries attackers already target.

An MSP can influence those controls across many customers. It can standardize multifactor authentication, conditional access, device compliance, data-loss rules, and administrator permissions.

However, this concentration creates its own risk. An attacker who compromises an MSP or its management tools can potentially reach several downstream customers.

CISA has warned that threat actors target MSPs because of their trusted access. Its MSP guidance recommends least privilege, stronger authentication, logging, and careful separation between customer environments.

inforcer must therefore solve two problems at once. It needs to make multi-customer administration efficient while preventing centralized access from becoming a broader failure point.

The company’s opportunity comes from this tension. Smaller businesses need centralized help because they cannot reproduce a large security organization internally. Yet the provider delivering that help must demonstrate stronger controls than any single customer could maintain.

This is why Google News coverage should not reduce the event to “AI security attracts capital.” The pressure falls on MSPs that must now answer questions about shadow AI, Copilot readiness, and data governance.

Customers will expect those providers to identify unsanctioned tools, explain the risks, and recommend controls. They may also expect evidence that approved AI systems are configured correctly.

That work goes beyond installing endpoint software. It requires continuously inspecting identity, data, application, and policy signals across changing cloud environments.

The forced response is immediate. MSPs must decide whether to build these workflows themselves, rely entirely on Microsoft’s portals, or adopt a management layer such as inforcer.

Google News Attention Hides a Deeper Microsoft Dependency

inforcer’s central advantage is also its central constraint: Microsoft supplies the controls and telemetry beneath the company’s platform.

inforcer describes its role as an operational layer for the Microsoft cloud. That positioning avoids the enormous task of creating a parallel identity, endpoint, and data-security stack.

Instead, the platform can organize Microsoft signals for an MSP audience. It can present one view across customers, compare configurations, identify drift, and help providers deploy repeatable standards.

This approach can reduce manual portal work. It also matches how many MSPs already serve customers, particularly those standardized on Microsoft 365 Business Premium.

The dependency becomes visible in shadow AI detection. inforcer says the feature integrates with Microsoft Cloud App Discovery, which analyzes network activity and identifies accessed cloud services.

Microsoft’s cloud discovery documentation says its catalog covers more than 31,000 applications. It scores them against more than 90 risk factors and can surface users, devices, transactions, and traffic patterns.

This gives inforcer a substantial data foundation without requiring its own endpoint sensor. It can transform underlying Microsoft information into cross-tenant dashboards and MSP-facing reports.

However, application discovery does not automatically reveal every risky action. Seeing that a user accessed an AI service differs from knowing what information entered a prompt.

Coverage also depends on data sources, endpoint configuration, application catalog entries, and the Microsoft licenses deployed within each customer environment. Incomplete deployment can produce incomplete visibility.

Microsoft’s newer shadow AI guidance draws an important distinction. Application discovery identifies accessed AI services, while deeper inspection can provide event-level information about prompts and related traffic.

That gap shapes what an MSP can safely promise. A dashboard might show that employees visited a generative AI application. It does not necessarily establish that sensitive data left the business.

The reverse is also possible. An apparently approved application might expose information because existing document permissions are too broad.

Microsoft Copilot generally follows a user’s existing access rights. If an employee can open a poorly governed SharePoint folder, AI can make that accessible information easier to find and summarize.

inforcer argues that AI exposes existing data and identity weaknesses. That framing is more credible than claiming AI alone creates an entirely new security category.

Its platform can help providers inspect readiness before deploying Copilot. The company says assessments examine tenant security, technical configuration, data governance, and likely adoption patterns.

Copilot Manager adds a commercial dimension. MSPs can review usage, identify departments with weak adoption, and discuss whether customers are receiving value from their deployment.

This mix of security and adoption data could distinguish inforcer from tools that only detect threats. It gives MSPs material for both technical reviews and customer planning.

Yet Microsoft retains control over the underlying platform. It can change licensing, expand native multi-tenant features, alter APIs, or integrate more reporting into its own partner tools.

That does not eliminate inforcer’s opportunity. Large platforms often leave operational gaps that specialized vendors can address more quickly.

The test is whether inforcer can build workflows that remain valuable after Microsoft improves its native experience. Cross-customer policy orchestration, evidence collection, and MSP-specific reporting offer plausible areas of differentiation.

Google News interest may create brand awareness, but defensibility will come from daily workflow depth. A provider must save enough engineering time, reduce enough configuration drift, or support enough new service revenue to justify another platform.

The Real Contest Is Standardization Versus Tenant Reality

inforcer’s model assumes repeatable security baselines can scale, while customer environments keep producing exceptions that resist standardization.

Central management works best when customers use similar products, licenses, policies, and operating models. MSPs often encourage this consistency because it reduces support complexity.

Security baselines fit that model. A provider can define expected settings for multifactor authentication, device compliance, email protection, sharing, and administrator access.

The platform can compare live settings against those expectations. When a policy changes, the MSP can investigate the drift and restore the approved configuration.

AI governance appears to follow the same pattern. Providers can define approved applications, acceptable-use policies, data controls, and Copilot deployment requirements.

The difficult part begins when business context enters the system. A marketing team, software developer, legal practice, and health provider may use AI differently.

An application that is unacceptable for one customer may support a legitimate workflow for another. Even departments inside the same company can require different access and retention rules.

Blocking every unsanctioned application can drive employees toward personal devices or unmonitored accounts. Allowing every tool creates the opposite problem, with little control over sensitive information.

An effective MSP service needs more than a red warning symbol. It must connect observed usage to data sensitivity, user role, contractual requirements, and approved business purposes.

inforcer’s materials describe a staged approach. The MSP begins with an acceptable-use policy, monitors actual application activity, then introduces remediation where required.

That sequence is sensible because policy without observation offers little assurance. Monitoring without a policy also leaves administrators without a clear standard for judging behavior.

Still, the platform cannot make every governance decision automatically. It can identify patterns and deviations, but the customer must decide which uses are acceptable.

Consider a sales employee using an external assistant to rewrite generic outreach. That may carry little risk if the prompt contains no confidential information.

The same tool becomes more concerning when the employee includes an unpublished contract, customer history, or internal pricing strategy. Application-level discovery may not distinguish those situations.

This is where inforcer’s emphasis on Microsoft configuration becomes important. Identity permissions, sensitivity labels, endpoint controls, and data-loss prevention can constrain what users access or transmit.

The platform’s role is to make those controls deployable and reviewable across tenants. It should not present configuration consistency as proof that no sensitive information escaped.

This distinction separates operational evidence from security certainty. A report can demonstrate that expected controls were configured at a specific time.

It cannot guarantee every employee followed policy or that every attack was prevented. Controls also lose value when exceptions accumulate without review.

The Series C therefore funds an ongoing product challenge. inforcer must support enough flexibility for real customers while preserving the efficiency that attracts MSPs.

Competitors can attack this problem from several directions. Established remote monitoring vendors can add Microsoft cloud and shadow AI features to their existing MSP platforms.

Security vendors can expand application discovery and data controls. Microsoft can improve native partner administration, while governance specialists can offer deeper inspection for larger customers.

inforcer’s narrower Microsoft focus helps it move directly into a familiar MSP workflow. It also limits the platform when customers use mixed productivity, identity, or endpoint environments.

The company does not need to cover every environment to succeed. It does need to prove its chosen segment is large, consistent, and willing to adopt a dedicated operational layer.

What the Funding Does Not Prove

The Series C validates investor interest, but it does not establish detection quality, customer outcomes, or durable product differentiation.

Funding announcements naturally emphasize market size, product momentum, and future expansion. They rarely provide enough evidence to evaluate detection accuracy or operational savings.

inforcer’s recent statements explain what the platform can display. They describe multi-tenant dashboards, Copilot adoption data, shadow AI application visibility, assessments, and policy workflows.

Those capabilities remain company claims unless supported by independent testing. Public materials do not yet provide a standardized comparison against other MSP management or AI governance products.

Several practical questions remain unanswered. Buyers need to know how reliably the platform identifies policy drift across complex tenants.

They also need evidence about false positives, missed applications, API delays, role separation, auditability, and the security of inforcer’s own privileged access.

Shadow AI creates an especially difficult measurement problem. A count of detected applications can look impressive without showing whether the activity exposed sensitive information.

A low count can also mislead. It might indicate strong governance, limited telemetry, employee avoidance, or an application absent from the discovery catalog.

Context matters more than raw totals. Providers should examine which users accessed a tool, what devices they used, and whether relevant data controls were active.

They should also separate visibility from enforcement. inforcer has said Business Premium can provide the discovery information used by its shadow AI dashboard.

More extensive policy and blocking functions can require additional Microsoft capabilities. That licensing boundary affects how easily smaller customers can move from observation to remediation.

Customer readiness also varies. Some organizations lack basic identity hygiene, consistent device management, or accurate data classification.

For those customers, an AI governance dashboard may expose problems without making them easy to fix. Remediation can require policy redesign, user training, licensing changes, and substantial engineering time.

The platform could still make that work more efficient. However, buyers should evaluate complete operational costs instead of assuming automated assessment equals automated resolution.

Another uncertainty concerns market behavior. MSPs must persuade smaller customers to pay for ongoing AI governance rather than treating it as an included support task.

inforcer argues that usage and risk data can support recurring services. Providers can offer assessments, acceptable-use policy reviews, monitoring, remediation, and adoption consulting.

That model depends on customer willingness to act. A report showing unsanctioned AI use has little value if management will not fund controls or change employee behavior.

The funding also does not settle the competitive question. Remote monitoring platforms already hold deep relationships with MSPs and can bundle additional Microsoft management functions.

Large security companies have their own endpoint telemetry, cloud application catalogs, and policy engines. They can introduce AI-focused filters without asking customers to deploy an entirely new data source.

Microsoft remains the most consequential competitor and partner. It supplies the underlying controls, but every native administrative improvement can narrow the gap that inforcer fills.

The company must therefore demonstrate more than feature availability. It needs evidence that MSPs can serve more customers, reduce errors, and create defensible governance services.

This skeptical view does not make the round insignificant. It defines the evidence needed to interpret future Google News coverage responsibly.

Investor confidence has financed the next stage. Customer retention, platform usage, and measurable security operations will determine whether that confidence was justified.

Three Signals That Will Decide the Bet

The next phase should be judged through product depth, MSP adoption, and evidence that centralized governance improves customer outcomes.

The first signal is deeper product integration after the Series C. inforcer should show how funding expands detection, policy orchestration, evidence collection, and remediation across Microsoft environments.

A long list of new dashboard widgets would provide limited proof. More meaningful progress would connect observed AI use to data controls, identity posture, and documented response workflows.

Buyers should watch for clearer distinctions between application discovery and prompt-level inspection. They should also examine how the platform reports gaps caused by licensing or incomplete telemetry.

Transparent coverage information would strengthen inforcer’s case. It would help MSPs explain what they can see, what they cannot see, and which additional controls customers require.

The second signal is adoption by MSPs outside inforcer’s early base. The company needs to show that providers can deploy its approach across customers with different sizes and requirements.

Useful evidence would include renewal rates, tenant growth, active policy management, and the number of customers receiving recurring AI governance services.

Those measures would reveal more than signed partnerships. They would show whether the platform becomes part of routine operations after the initial assessment.

The company must also prove that smaller providers can use it. Large MSPs may have specialists who can interpret security data, redesign policies, and manage exceptions.

A smaller provider needs simpler workflows and clearer recommendations. If the product requires extensive internal expertise, its addressable MSP market becomes narrower.

The third signal is how Microsoft and established vendors respond. Microsoft continues to expand discovery, data governance, identity, and AI security functions across its cloud.

Native improvements can help inforcer by producing richer signals. They can also weaken its differentiation if Microsoft makes multi-tenant administration sufficiently accessible.

Remote monitoring and security vendors present another test. Their existing distribution gives them an efficient route to add shadow AI reporting and Microsoft policy management.

inforcer must stay ahead through workflow design rather than relying on early category language. “AI governance” will not remain a distinctive label as more vendors adopt it.

The company’s Microsoft specialization can still be an advantage. Focused software often organizes a platform’s scattered capabilities more effectively than the platform owner does.

That advantage must appear in measurable operations. Providers should be able to manage more tenants, find configuration drift sooner, produce clearer evidence, and resolve issues faster.

Readers should also watch the company’s security posture. A platform with privileged visibility across customer tenants must maintain strict separation, least privilege, monitoring, and incident response.

Independent security assessments and detailed architecture disclosures would strengthen trust. Silence around these issues would weaken the centralized management argument.

The larger story is not whether criminals use AI. Attackers already combine automation with familiar techniques such as phishing, credential theft, and exploitation of weak configurations.

The strategic question is whether MSPs can turn scattered Microsoft controls into a reliable security service for smaller businesses. inforcer has raised enough capital to pursue that role aggressively.

Its timing is favorable. Employee AI adoption is moving faster than many customers can build governance programs, while Microsoft environments contain the identities and data those tools access.

Yet favorable timing does not remove execution risk. inforcer must translate visibility into decisions, policies into sustained controls, and dashboards into evidence customers value.

That is the standard future Google News reports should apply. Another product release or funding milestone will matter less than signs of repeatable customer outcomes.

For MSPs, the immediate action is practical: inventory AI use, inspect tenant permissions, define acceptable behavior, and document which controls are actually enforced. Then test whether centralized software reduces the work without hiding important exceptions.

For business leaders, ask your provider what it can observe today. Request a clear distinction between discovered applications, sensitive data movement, and enforceable policy.

The $50 million round gives inforcer room to build its answer. The next evidence must come from the MSPs and customers expected to depend on it.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page