Identity threat detection and response (ITDR) is the practice, and the category of tools, focused on spotting and stopping attacks against user accounts and the systems that manage them: directories, identity providers (IdP) and privileged accounts. It looks for signs such as impossible sign-in locations, stolen session tokens, suspicious MFA changes, privilege escalation and known directory attack techniques, and then responds by disabling accounts, revoking sessions or alerting your security team. It exists because attackers increasingly log in rather than break in.
At a glance
- Monitors identity systems and sign-in behavior, not just devices or networks.
- Detects account takeover, session hijacking, MFA abuse, privilege escalation and directory attacks.
- Often also flags risky identity configurations, such as stale admin accounts or weak policies.
- Delivered as standalone tools, as features of XDR, EDR, identity or PAM platforms, or within an MDR service.
- Complements prevention controls like MFA and least privilege rather than replacing them.
What problem it solves
Many breaches start with a valid login. Attackers buy or phish credentials, steal session cookies from infected browsers, wear users down with MFA prompts, or trick the help desk into resetting an account. Once inside, they look for admin rights in the directory, add their own MFA device or create new accounts to keep access.
Traditional security tools may miss this. Endpoint detection and response (EDR) sees activity on managed devices, but an attacker signing in to a cloud app from their own computer may never touch those devices. Identity systems produce logs, but without someone or something analyzing them, a successful takeover can look like an ordinary login. ITDR focuses detection where these attacks actually happen.
How it works
Collecting identity signals. ITDR tools ingest sign-in logs, audit logs and configuration data from identity providers, on-premises directories, SaaS applications and sometimes privileged access management (PAM) systems. Some also use sensors on domain controllers to see directory traffic.
Detecting attacks. Analytics and rules look for patterns such as sign-ins from unusual locations or devices, token reuse from a new location, a burst of MFA prompts, a new MFA method added right after a password reset, unexpected admin role assignments, and techniques used to steal or forge directory credentials.
Assessing posture. Many tools also scan for weaknesses that make attacks easier: dormant privileged accounts, accounts without MFA, overly broad permissions, risky application consents and misconfigured trust settings.
Responding. When a threat is confirmed, ITDR can disable the account, revoke sessions and refresh tokens, require re-authentication or an MFA reset, and notify responders. Automated actions are usually configurable, because blocking a legitimate executive by mistake has a cost too.
Feeding the wider picture. Identity alerts typically flow into a security information and event management (SIEM) platform, XDR or an MDR provider so analysts can connect them with endpoint and network activity.
When it matters for buyers
- When credential attacks are your biggest risk. If you rely heavily on SaaS and cloud identity, account takeover is a primary threat.
- When evaluating managed detection and response (MDR). Ask whether identity sources are included in scope or cost extra.
- When you run an on-premises directory. Directory attacks are a common path to full domain compromise.
- After a peer’s breach involving stolen logins. Identity-based intrusions are a frequent pattern.
- When consolidating security tools. Your XDR, EDR or identity platform may already include identity detections you are not using.
Questions to ask vendors
- Which identity systems do you monitor: cloud identity providers, on-premises directories, SaaS apps, PAM?
- What identity attacks do you detect, and how do you reduce false positives for traveling or remote staff?
- What response actions can you take, and which can run automatically?
- Do you assess identity configuration and posture, or only detect live attacks?
- Do you need agents or sensors on domain controllers, or only API access?
- How do your alerts integrate with our SIEM, XDR or MDR provider?
- If you are an MDR provider, is identity monitoring included or an add-on?
How it differs from XDR
Extended detection and response (XDR) correlates signals across endpoints, email, network, cloud and often identity into one detection and response platform. ITDR concentrates on identity: deeper analysis of sign-ins, directories, privileges and identity configuration. Some XDR platforms include ITDR features; standalone ITDR tools often go deeper on directory attacks and identity posture. Both build on identity and access management (IAM) systems but are about detecting misuse, not managing access. For outsourced monitoring that can include identity threats, see our managed detection and response overview.
