Identity & Access
Identity Threat Detection ITDR
A layer that detects attacks on Active Directory and Entra ID (Kerberoasting, golden ticket, password spraying, suspicious privilege escalation, MFA fatigue) and shows identity configuration weaknesses.
When you need it
- You use Active Directory (almost every ransomware attack takes over AD)
- You have suffered an account takeover or ransomware
- You can't see where admin accounts are used and what they do
When you do not need it
- Smaller organizations may already have this in their M365 E5 license; check before buying a separate product.
- Free AD audit tools can reveal configuration weaknesses.
Sensors on domain controllers + an Entra ID connection. Alerts go to the SIEM/MDR; high-risk sign-ins are blocked automatically with conditional access.



