Identity & Access

Identity Threat Detection ITDR

A layer that detects attacks on Active Directory and Entra ID (Kerberoasting, golden ticket, password spraying, suspicious privilege escalation, MFA fatigue) and shows identity configuration weaknesses.

When you need it

  • You use Active Directory (almost every ransomware attack takes over AD)
  • You have suffered an account takeover or ransomware
  • You can't see where admin accounts are used and what they do

When you do not need it

  • Smaller organizations may already have this in their M365 E5 license; check before buying a separate product.
  • Free AD audit tools can reveal configuration weaknesses.

Sensors on domain controllers + an Entra ID connection. Alerts go to the SIEM/MDR; high-risk sign-ins are blocked automatically with conditional access.