Guardz is a managed detection and response platform for MSPs that unifies identity, endpoint, email and cloud security in one console, embedding SentinelOne EDR. Pricing is per user but not published; Guardz shares exact figures directly with each MSP (checked September 2026).
Listing updated . Checked by MSP Software .
Guardz is a managed detection and response platform from Guardz for MSPs and MSSPs, built to unify identity, endpoint, email and cloud security in a single multi-tenant console rather than requiring separate point tools. It covers identity threat detection across Microsoft 365, with Google Workspace support described by the vendor as coming; endpoint protection through an embedded SentinelOne Singularity EDR agent, which the vendor's own site confirms runs on Windows, macOS and Linux; email security with API-based scanning of Microsoft 365 and Google Workspace mailboxes, so no MX record changes are needed; external footprint and dark web monitoring; and adaptive security awareness training with AI-generated phishing simulations. A 24/7 human-staffed SOC with AI-assisted alert triage sits behind the higher tiers, adding managed response actions such as process isolation and account suspension, plus forensic investigation on the top tier.
Guardz sells three tiers, Pro, Ultimate and Elite, each adding more of the SentinelOne EDR depth, Check Point email protection and MDR response, but it does not publish per-user prices. The vendor states it shares pricing directly with each MSP rather than publishing it, so that a public number does not shape how a partner prices the service to its own clients. There is a 14-day free trial with no credit card required (checked September 2026), and no free tier once the trial ends. Guardz integrates with PSA tools including ConnectWise, Autotask, SuperOps, HaloPSA, Syncro and ServiceNow for ticketing and case sync, on top of its native Microsoft 365 and Google Workspace connections.
Guardz was founded in 2022 and lists offices in Miami, Florida and Tel Aviv, Israel, and has raised a Series B round in 2025 on top of earlier seed and Series A funding. MSPs should check which tier actually includes the SentinelOne EDR depth, the 24/7 MDR response and the email DLP and encryption they need, since these move between the Pro, Ultimate and Elite plans rather than sitting in every tier, and should confirm Google Workspace identity coverage before assuming full parity with Microsoft 365.
Guardz's pitch is consolidation: identity, endpoint, email, external exposure and awareness training under one multi-tenant console instead of five separate vendors, which suits a smaller MSP standardising a security stack for the first time rather than one stitching a stack together tool by tool. It sits alongside Huntress, Blackpoint Cyber and Coro as a unified, MSP-only play, and the embedded SentinelOne EDR gives it a recognised detection engine rather than a homegrown agent. Because pricing is quote-only and tiered by feature depth, get the exact per-user figure and confirm which tier includes the SentinelOne EDR, 24/7 MDR response and email DLP and encryption before comparing it against a rival's published number. Check Google Workspace coverage for identity threat detection too, since Microsoft 365 support is further along.
| Feature | Supported | Note |
|---|---|---|
| 24-hour human-staffed SOC | yes | 24/7 AI-assisted alert triage backed by human researchers and threat hunters, included from the Ultimate tier up. |
| Managed threat response and isolation | yes | Automated playbooks with isolation and account suspension; forensic deep-dive investigation added at the Elite tier. |
| Own endpoint telemetry agent | no | Endpoint detection runs on an embedded SentinelOne Singularity agent rather than a Guardz-built endpoint agent. |
| Identity threat detection | yes | Cloud ITDR monitors Microsoft 365 (Google Workspace support described as coming) for account takeover, token theft and business email compromise patterns. |
| Network monitoring | no | No traditional network monitoring described; identity monitoring is behavioural analysis of cloud logs, not network traffic. |
| Microsoft 365 monitoring | yes | Ingests Microsoft 365 Graph API logs for identity and email threat detection. |
| Monthly threat reporting | unknown | Vendor describes client security reports and incident playbooks; a monthly cadence is not stated on the site. |
| PSA integration for ticketing | yes | Documented PSA integrations for ConnectWise, Autotask, SuperOps, HaloPSA, Syncro and ServiceNow. |
| Multi-tenant console | yes | Single console built for MSPs and MSSPs managing multiple client environments. |
| Works with third-party EDR | yes | Platform page describes correlating Microsoft Defender signals alongside the embedded SentinelOne EDR. |
| Dedicated incident response | yes | Incident analysis and forensic deep-dive investigation are included at the Elite tier. |
| Feature | Supported | Note |
|---|---|---|
| Phishing and malware filtering | yes | Fine-tuned LLM analysis of email metadata and authentication signals. |
| Spoofing and impersonation protection | yes | Detects alias mismatches and impersonation from sender behaviour patterns. |
| Email continuity | unknown | Not described on the vendor's site. |
| Archiving | unknown | Not described on the vendor's site. |
| Security awareness training bundle | yes | Security awareness training and phishing simulation are bundled into the same unified platform. |
| API-based post-delivery scanning | yes | Deploys via Microsoft and Google APIs with no agent or MX record changes needed. |
| DMARC monitoring | unknown | Not described on the vendor's site. |
| Attachment sandboxing | yes | Deep inspection and file scanning of embedded links and attachments to detect hidden malware. |
| Data loss prevention | yes | Outbound data loss prevention is included at the Elite tier's Check Point Complete Email. |
| Email encryption | yes | Email encryption is included at the Elite tier. |
| Microsoft 365 integration | yes | Native Microsoft 365 API integration. |
| Self-service quarantine | unknown | Vendor describes quarantine and warning banners as response actions; self-service release by end users is not confirmed. |
| Feature | Supported | Note |
|---|---|---|
| Phishing simulation campaigns | yes | AI-generated phishing emails plus a library of pre-built templates, with randomised scheduling. |
| Training content library | yes | Library of short training videos kept updated by Guardz. |
| Automated remediation training | yes | Failed simulations can trigger assigned training automatically. |
| Phish-reporting button | unknown | Not described on the vendor's site. |
| Multi-language content | yes | Simulations and training portal support English, French, German, Hebrew, Spanish, Portuguese, Dutch and Italian. |
| Compliance training modules | unknown | Not described on the vendor's site. |
| Client-facing reporting | yes | Awareness dashboard tracks engagement and completion, feeding into client security reports. |
| Microsoft 365 and Google user sync | yes | Syncs with Microsoft 365 and Google Workspace so new users are added to campaigns automatically. |
| Smishing and vishing simulation | no | Simulation content covers email phishing; smishing or vishing is not described. |
| Gamification | no | Not described on the vendor's site. |
| Campaign scheduling automation | yes | Campaigns can be scheduled monthly, bi-monthly or quarterly and auto-run once set. |
| PSA integration for billing | unknown | PSA integrations are documented for ticketing and sync; billing-specific integration is not described. |
Guardz is sold per user across three tiers, Pro, Ultimate and Elite, but the vendor does not publish specific figures. Guardz says it shares exact pricing directly with each MSP rather than publishing it, so that a public user price does not shape how a partner values the service to its own clients. An MSP has to book a demo or contact sales to get a quote.
Guardz embeds SentinelOne's Singularity EDR agent for endpoint detection, deployed and managed through the Guardz console rather than SentinelOne's own console. An MSP already running SentinelOne separately should check with Guardz whether an existing SentinelOne tenant and licences can be reused, since Guardz's own site describes the EDR as centrally managed through its platform rather than as a bring-your-own-licence option.
Guardz documents PSA integrations for ConnectWise, Autotask, SuperOps, HaloPSA and Syncro, plus a case integration for ServiceNow, according to its own support documentation. These integrations sync tickets and cases rather than billing, so an MSP should confirm billing-specific requirements separately before assuming full PSA parity.
Yes, Guardz offers a 14-day free trial with no credit card required, according to its pricing page. There is no separate free version once the trial period ends, so ongoing use requires moving to a paid Pro, Ultimate or Elite plan.
Pro covers identity, endpoint, email, adaptive security awareness and external exposure monitoring. Ultimate adds SentinelOne's Control EDR, Check Point's Advanced Email protection and 24/7 AI-plus-human MDR response. Elite adds SentinelOne's Complete EDR with deeper telemetry and threat hunting, Check Point's Complete Email with outbound DLP and encryption, and forensic deep-dive investigations, according to Guardz's own pricing page.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review