Identity threat detection and response (ITDR)
Watches the identity layer: Entra ID and Active Directory sign-ins, privilege changes, token abuse and account takeover.
Know the exact item? Search above to go straight to it. Or buy from the options below.
| Signal | What it catches |
|---|---|
| Anomalous sign-ins | Impossible travel, unfamiliar device or location |
| Privilege escalation | Accounts gaining rights they should not have |
| Token abuse | Session tokens replayed or stolen |
| Dormant account use | Accounts that should not be active suddenly being used |
| Why endpoint tools miss it | An attacker with valid credentials is doing nothing technically suspicious on the device |
What is identity threat detection and response?+
ITDR monitors the identity layer, including Entra ID and Active Directory, for account takeover, privilege abuse, token theft and anomalous sign-in behaviour. It catches attacks that arrive with valid credentials.
Why is this separate from endpoint security?+
An attacker using stolen credentials is performing legitimate actions from the endpoint point of view. ITDR looks at identity behaviour rather than device behaviour, which is where that activity is visible.
Does MFA make ITDR unnecessary?+
No. MFA raises the bar but does not stop token theft, session hijacking or abuse by an account that has already authenticated. ITDR covers what happens after sign-in.
How does it fit with MDR?+
ITDR generates the identity signals. MDR is the service that watches and acts on them 24/7. Many businesses buy both.

