But the launch arrives in a market where Microsoft already provides substantial protection across those workloads. The issue Trustifi is trying to solve is less the absence of Microsoft 365 controls than the operational burden of deploying, licensing, tuning and investigating them consistently across many small and midsize tenants. Whether Collaboration Shield is a meaningful security layer or primarily a simpler management wrapper will depend on technical details Trustifi has not yet published.
CRN first reported the launch on August 5, citing Trustifi vice president of strategic partnerships Zack Schwartz. He said the platform is intended to detect sensitive data, enforce policies, monitor activity and investigate incidents across Microsoft 365 collaboration services from a multi-tenant interface. Trustifi says it includes more than 70 built-in sensitivity types, covering personally identifiable information, financial and health data, passwords, API keys and credentials.
Trustifi Is Moving Beyond the Mail Flow
Trustifi has historically sold cloud email security: filtering inbound phishing and malware, outbound encryption, email data loss prevention, archiving and account-takeover protection. Its public MSP materials still describe the company chiefly as an AI-powered email security provider built around centralized management for service providers.
Collaboration Shield changes that product boundary. Rather than treating email as the beginning and end of the threat path, Trustifi is positioning Teams messages, SharePoint document libraries and OneDrive shares as places where an attacker can continue after a successful credential theft or phishing campaign.
That is a credible operational concern. An attacker who gains a Microsoft 365 account does not need to send more suspicious email to cause harm. They may search SharePoint, inspect OneDrive folders, create sharing links, use Teams chats to reach coworkers, distribute malicious files internally or identify executives and high-value systems. The practical incident response problem is that email, identity, Teams and files often generate evidence in different Microsoft portals and log streams.
Trustifi’s claim is that an MSP can follow that chain from an initial email incident into collaboration activity and take action from one interface. CRN reports that the product can trace where an attack spread and identify affected users. That is the central promise worth testing, because correlation across workloads is more useful to an understaffed MSP than simply adding another dashboard that produces alerts.
Trustifi has not yet described the data sources, Microsoft Graph permissions, audit-log dependencies, retention requirements or response actions behind that claim. Those omissions matter. A tool that can alert on public sharing is very different from one that can revoke a link, quarantine content, disable a compromised account, remove a Teams message and preserve a defensible incident timeline.
Microsoft Already Covers Much of the Stated Territory
The product’s marketing should not be read to mean that Teams, SharePoint and OneDrive lack Microsoft-native data protection. Microsoft Purview DLP can apply policies to SharePoint, OneDrive and Exchange under Microsoft 365 E3 licensing, while protection for Teams chat and channel messages carries more restrictive E5-level licensing requirements. Teams file sharing also relies heavily on SharePoint and OneDrive, so file controls can protect a substantial portion of content shared through Teams.
Microsoft Defender for Cloud Apps also provides cloud visibility, file inspection, policy enforcement and investigation features, while Defender for Office 365 can protect Teams, SharePoint and OneDrive against malicious files and links. Microsoft’s security stack is broad; it is also fragmented by licensing tier, portal, role and product family. That fragmentation is the commercial opening Trustifi is targeting.
For MSPs, the question is therefore not “does Microsoft 365 have DLP?” It is whether an existing customer has the necessary licenses, whether policies cover the correct workloads, whether alert handling is viable across dozens or hundreds of tenants, and whether the provider can prove that controls are operating as intended.
Trustifi’s templates for health care, financial services and legal clients could reduce the time needed to establish a baseline. They do not remove the need to tune policy matches, set exception paths, establish owner responsibility for shared data and test what happens when a legitimate business workflow is blocked. A sensitivity template can accelerate deployment; it cannot determine which external recipients, document libraries or staff roles are appropriate for a particular customer.
The vendor is also using “email-grade” protection as shorthand for a unified experience. That phrase should not be confused with a published technical equivalence between Trustifi’s mail scanning and its new Microsoft 365 collaboration controls. No independent test results, detection efficacy figures, false-positive rates or service-level commitments for Collaboration Shield were included in CRN’s report, and Trustifi’s public product pages reviewed on August 5 still center on email protection rather than a separately documented collaboration-security product.
Microsoft’s 2027 Policy Shift Gives This Launch Extra Weight
The timing is notable because Microsoft is retiring Defender for Cloud Apps file policies on January 6, 2027. Microsoft’s own documentation tells customers using those policies to move file-based protection to Microsoft Purview DLP or auto-labeling policies.
That retirement does not mean Microsoft is abandoning SharePoint and OneDrive data protection. Microsoft is directing customers toward Purview, and it has introduced file quarantine capabilities for SharePoint and OneDrive through Purview DLP. The change does mean that organizations and MSPs using older Defender for Cloud Apps file-policy workflows face another migration, another administrative model and potentially another licensing review.
Trustifi can use that disruption to make a straightforward pitch: retain one vendor console for email and collaboration security, with policies that an MSP can copy between tenants. It is a more compelling position for service providers than for large enterprises with mature Microsoft security operations, dedicated Purview administrators and E5 licensing already in place.
The catch is that an add-on platform does not eliminate Microsoft configuration. Collaboration Shield necessarily depends on access to the customer’s Microsoft 365 environment, and the quality of its detection will depend on what it can ingest and what it is authorized to change. MSPs should treat the onboarding design as a security review, not an install checkbox.
Before enabling the product across tenants, providers should establish:
- The exact Microsoft 365 roles, Graph application permissions and customer-consent model that Collaboration Shield requires.
- Whether it monitors Teams chat content, channel messages, files, sharing events, sign-ins, audit events or only selected combinations of those signals.
- Which actions it can automate, whether those actions are reversible, and whether the original Microsoft audit record remains available for investigation.
- How Trustifi handles tenant data, incident metadata, sensitive-content matches and customer offboarding.
- How its policies interact with existing Microsoft Purview, Defender for Office 365, Conditional Access and sensitivity-label policies.
These are not edge cases. An MSP that grants broad tenant-wide application consent to gain monitoring convenience has created a high-value third-party access path. The product may reduce alert-management overhead, but it should not expand access without clear controls around least privilege, credential protection and periodic consent review.
The Channel Story Is Stronger Than the Product Record So Far
CRN’s reporting makes clear that the launch is designed as an upsell to Trustifi’s existing partner base. Schwartz described thousands of customers using Trustifi through the channel and called collaboration protection a natural extension for partners. TekEfficient vice president of operations Moses Castillo told CRN that a consolidated offering would help the Denver MSP deliver more value while simplifying management for technicians and end users.
That channel rationale is sound. Selling email filtering alone can become a low-differentiation service, especially when customers believe Microsoft 365’s default protection is sufficient. Adding collaboration monitoring, DLP and incident response creates more recurring security work for the provider and a wider service bundle for the customer.
Yet Trustifi has not announced pricing, availability by region, required licensing, supported Microsoft 365 plans, the status of the product as generally available versus limited release, or what happens to existing customers’ email policies. It also has not said whether Collaboration Shield will integrate with PSA, RMM, SIEM or ticketing platforms at launch, despite those integrations being central to MSP operations.
There is also a small but telling discrepancy in the company record. CRN identifies Schwartz as vice president of strategic partnerships, while Trustifi’s current leadership page lists him as chief sales officer. That may simply reflect a recent role change or outdated page content, but it underscores how thin the public launch documentation is beyond the exclusive interview.
Trustifi says Google environments and possibly Slack are on the roadmap, alongside AI-driven security-awareness training based on user behavior. Those are future plans, not announced product capabilities. For now, the practical decision is narrower: whether Collaboration Shield can give an MSP clearer, actionable visibility across Microsoft 365 tenants than the collection of Microsoft tools the provider already manages.
The product’s value will be decided by permission scope, enforcement depth and day-two operations—not by the number of built-in data types. Until Trustifi publishes those details, MSPs should regard Collaboration Shield as a potentially useful consolidation layer, but not as a substitute for validating Microsoft 365 identity controls, external sharing rules, Purview coverage and audit readiness in every tenant.
Update: Trustifi says Collaboration Shield can quarantine malicious files and messages (August 5, 2026)
Channel Insider reports that Collaboration Shield adds automated file and message quarantine to its Microsoft 365 response options, alongside continuous scanning for malware, sensitive data and anomalous activity. That is a substantive clarification of the launch: Trustifi’s earlier public description emphasized detection and investigation, while the new reporting indicates the platform can be configured to take containment action rather than only generate alerts.
According to Channel Insider, Trustifi also says the product is available immediately to MSPs and MSSPs and works across all Microsoft 365 plans. The company describes cross-tenant policy deployment and analytics, plus investigation views with event timelines and file-level details. MSPs should still verify the exact licensing, permissions and workload coverage during a proof of concept, particularly whether quarantine actions apply consistently to Teams messages, SharePoint content and OneDrive files.
Update: Trustifi cites five-minute deployment and free MSP trials (August 5, 2026)
In a Technology Reseller News podcast, Trustifi’s Zach Schwartz said Collaboration Shield can be deployed in about five minutes without coding or specialized training. The company also says partners can use free trials to assess customer environments and generate remediation reports.
Trustifi further says new partners face no minimums or long-term commitments, adding commercial onboarding details absent from its earlier launch coverage. Those claims may lower the barrier for MSPs testing the service, but providers should distinguish rapid tenant connection from the work of validating permissions, policy tuning and response actions.