Identity
Best ITDR Tools for Identity Threat Detection in 2026
MFA can pass at login while Kerberos still hands an attacker a roastable ticket.
Microsoft’s October 2024 Kerberoasting guidance still centers a blunt failure: service tickets encrypted with weak RC4 are offline-crackable, and identity attacks often start after MFA already looked green.
Identity Threat Detection and Response watches authentications, tickets, and directory changes, then challenges, revokes, or contains. Some products fuse with EDR consoles. Others sit inline on legacy protocols or specialize in AD forest recovery.
If you are buying the IdP itself, use identity protection tools. If the job is vaulting standing admin, see PAM tools.
How we evaluated
We read first-party ITDR, identity threat, and directory-security product pages and licensing notes on 17 Sep 2026. We asked whether the product detects identity attacks (not only login MFA), whether response actions are named, whether AD and/or IdP sessions are in scope, and whether recovery is part of the story. Marketing pages are claims, not bake-off proof.
| Tool | Best for | What to check |
|---|---|---|
| Falcon Identity Protection | ITDR inside Falcon | Commercial ยท Falcon module |
| Defender for Identity | AD detections in Microsoft XDR | Commercial ยท M365/Defender |
| Okta Identity Threat Protection | Continuous Okta session risk | Commercial ยท Okta SKU |
| Silverfort | Inline legacy protocol protection | Commercial ยท specialist |
| Semperis | AD threat + forest recovery | Commercial ยท specialist |
| Singularity Identity | Identity deception + SentinelOne | Commercial ยท module |
CrowdStrike Falcon Identity Protection
Best for ITDR correlated with Falcon endpoint telemetry

Falcon Identity Protection watches authentication and directory behavior and ties identity alerts to the same Falcon console teams already use for endpoints.
Choose it when the SOC wants identity threat response next to EDR, not another disconnected IdP admin console.
Key features:
- Identity threat detection across AD and cloud IdPs they list
- Correlation with Falcon endpoint signals
- Risk-based response including MFA enforcement patterns they document
- Hybrid lateral-movement visibility in their ITDR story
Why we like it:
Falcon customers avoid a second SOC pane when identity detections should fire beside endpoint detections for the same intrusion.
Limits:
Commercial module pricing. Value is highest inside an existing Falcon estate. It is not a forest-recovery product.
License or pricing: Commercial. Module quote. No public list price on 17 Sep 2026.
Microsoft Defender for Identity
Best for Active Directory and Entra-centric identity detections inside Microsoft XDR

Defender for Identity sensors watch on-prem AD signals and feed Microsoft Defender XDR, sitting next to Entra ID Protection risk scores for cloud identities.
It is the default path when the directory and licenses already live in Microsoft 365 E5 / Defender suites.
Key features:
- AD identity threat detections and lateral movement alerts
- Integration with Defender XDR investigation queues
- Works alongside Entra ID Protection risk-based Conditional Access
- Microsoft signal graph context they publish
Why we like it:
Microsoft-heavy estates get directory detections without standing up a separate ITDR brand, especially when Conditional Access already consumes identity risk.
Limits:
Licensing rides Microsoft Defender / M365 bundles. Depth outside Microsoft identity planes is not the center. Confirm sensor coverage for every DC.
License or pricing: Commercial via Microsoft 365 / Defender licensing. Confirm SKU on 17 Sep 2026.
Okta Identity Threat Protection
Best for continuous session risk inside an Okta workforce

Okta Identity Threat Protection evaluates risk continuously during the session, not only at login, and can step up or terminate when shared signals look wrong.
This is the Okta ITDR SKU. It is not the same page as buying Okta as your IdP on the identity protection shortlist.
Key features:
- Continuous risk evaluation after authentication
- Shared signal style partner inputs Okta documents
- Session termination and step-up response actions
- Workforce identity context inside Okta
Why we like it:
Okta-centric companies need mid-session response when MFA at login was green and the token still walks into admin apps.
Limits:
Commercial Okta SKU. Weak if most of the attack lives only in on-prem AD with little Okta telemetry. Confirm ITP is on the order form, not assumed in every Okta tier.
License or pricing: Commercial Okta SKU quote. Checked 17 Sep 2026.
Silverfort
Best for inline MFA and protection on legacy protocols and service accounts

Silverfort sits on the authentication path to extend MFA and policy to Kerberos, NTLM, LDAP, and command-line access that never got a modern agent.
Pick it when legacy service accounts and protocol gaps are the ITDR blind spot, not only IdP risk scores.
Key features:
- Inline protection across legacy authentication protocols
- Coverage for service accounts and non-human logons they emphasize
- MFA and policy extension without rewriting every app
- Hybrid identity security platform positioning
Why we like it:
Enterprises with decades of NTLM and service-account debt get enforcement where IdP-only ITDR never sees a packet.
Limits:
Commercial. Architecture review is mandatory because inline auth paths fail closed if misdesigned. Not a forest backup product.
License or pricing: Commercial. No public list price on 17 Sep 2026.
Semperis
Best for AD threat detection plus directory forest recovery

Semperis specializes in Active Directory attack-path detection and, critically, recovering a directory forest after destructive identity attacks.
ITDR without recovery leaves you detecting a burning forest. Semperis is the recovery-minded seat on this list.
Key features:
- AD and Entra attack-path and change detection
- Directory Services Protector style monitoring
- Forest recovery and identity resilience tooling
- Hybrid directory focus
Why we like it:
Boards that ask “how do we rebuild AD after ransomware” need a product story that includes recovery, not only another alert.
Limits:
Commercial specialist. Not a full IdP session ITDR for Okta-only estates. Scope the AD recovery runbook in the PoC.
License or pricing: Commercial. No public list price on 17 Sep 2026.
SentinelOne Singularity Identity
Best for identity deception and credential defense beside SentinelOne EDR

Singularity Identity adds Active Directory deception and identity threat detection alongside SentinelOne endpoint protection.
It fits SOC teams consolidating on Singularity who want identity detections without a fourth console.
Key features:
- AD deception and identity threat detection features they list
- Credential defense patterns beside endpoint agents
- Singularity platform consolidation
- Hybrid identity attack-path visibility in their docs
Why we like it:
SentinelOne estates can pull identity deception into the same operator morning as endpoint alerts.
Limits:
Commercial module. Deception needs careful production design. Confirm AD coverage versus cloud IdP depth on the quote.
License or pricing: Commercial. Module quote. No public list price on 17 Sep 2026.
How to choose a ITDR tool
Four questions before the quote. Names are the shortlist, not a scored bake-off.
| Critical question | Why it matters | What to evaluate | Red flag |
|---|---|---|---|
| Where do identity attacks show up first? | AD ticket abuse and IdP session risk need different sensors. | Defender/Semperis/Silverfort for AD; Okta ITP for Okta sessions; Falcon/S1 if SOC consolidation wins. | An IdP MFA dashboard sold as Kerberoasting detection. |
| Do you need inline enforcement on legacy auth? | Service accounts and NTLM skip cloud MFA. | Silverfort when protocols are the gap. | Cloud-only ITDR with no AD protocol story. |
| Is forest recovery in scope this year? | Detection without rebuild plans fails ransomware tabletop. | Semperis for recovery drills. | Alert-only AD tools with no restore path. |
| Which console already owns incidents? | Extra panes create missed pages. | Falcon or Singularity modules if those SOCs are home. | A fifth identity console for a two-analyst team. |
What practitioners argue about ITDR
Practitioners argue about Kerberoasting math and whether identity alerts ever become response, not about the ITDR acronym itself.
Hacker News
“The main reason this is significant is that it makes Kerberoasting much more difficult. It’s less about how secure RC4 is as a cipher, and more how fast you can compute it in a bruteforce dictionary attack, vs the modern AES version.”
Comment on Microsoft RC4/Kerberos changes, Dec 2025 (linked in the Okta ITP entry). ITDR still has to catch ticket abuse while encryption migrations finish.
Information Security Stack Exchange
“The new Kerberos AS-REQ-requested attack is somewhat different from a normal Kerberoast, in that instead of requesting a Service Ticket (for offline cracking) via a normal TGS-REQ, it’s requested via an AS-REQ…”
AS-REQ Kerberoast discussion, Dec 2024. Directory attack variants keep moving; detections must track more than one ticket request shape.
If standing admin is still shared, read PAM tools next. If the workforce IdP itself is the project, start with identity protection tools.
FAQs
Is ITDR the same as identity protection / IAM?
No. Identity protection and IAM authenticate and authorize users. ITDR detects and responds to identity attacks and abuse after or beside those controls.
Does ITDR replace EDR?
No. EDR watches endpoints. ITDR watches identity systems. Several vendors correlate both in one console.
Is Okta Identity Threat Protection included with every Okta plan?
Treat ITP as a distinct commercial capability. Confirm it on the order form.
Is this a scored bake-off?
No. Order is editorial.