Its scope can include human and workload accounts, credentials, authenticators, sessions, tokens, directories, identity providers, federation, privileges, and the policies that govern access.
ITDR correlates identity-specific evidence with endpoint, application, cloud, and network context. It looks for behaviors such as password spraying, suspicious token creation, unexpected role assignment, illicit application consent, authentication-policy changes, session theft, and abnormal use of valid accounts. Response may revoke sessions or credentials, disable an identity, remove unauthorized privileges, restore policy, isolate a system, and preserve evidence for the wider incident investigation.
Key points
Key telemetryAuthentication outcomes, token and session events, directory changes, privilege grants, application registrations, device enrollment, policy administration, and resource access.
Response actionsChallenge or block access, revoke tokens, rotate credentials, disable accounts, remove persistence, reverse unauthorized changes, and escalate through incident response.
Program requirementsBaseline expected identity behavior, protect and retain logs, define high-risk playbooks, test containment paths, and coordinate identity, security operations, and application owners.
Important limitationITDR is not a standardized NIST control category, and product coverage varies. Missing logs, short retention, forged tokens, or activity outside integrated identity systems can leave serious blind spots.