Threat detection and posture
Identity threat detection and response (ITDR)
What is identity threat detection and response (ITDR)?
ITDR is the discipline of catching and stopping attacks that use legitimate credentials and sessions rather than malware. It watches identity signals such as sign-in patterns, session behavior, and privilege changes, evaluates risk continuously instead of only at login, and responds inside the session: stepping up authentication, limiting access, or ending the session everywhere at once.
Most successful identity attacks do not break anything. They present a valid credential, or a valid session token, and the systems designed to check validity wave them through. That is why detection has to look at behavior and context, not just whether the login succeeded.
Signals worth watching
| Signal | What it can mean |
|---|---|
| A burst of MFA push prompts | MFA fatigue: the attacker has the password and is hammering approve until the user gives in |
| Sign-in from a new device followed by factor changes | An account takeover consolidating its hold |
| A session token used from a second location | Session theft: the attacker skipped login entirely |
| A dormant privileged account waking up | Compromised credentials found their way to something valuable |
Detection is half of the acronym
A risk signal that lands in a dashboard nobody watches is not a control. Response means the signal reaches the tools your security team already runs, and something happens in the moment: the session is challenged, restricted, or ended across every app at once. On Okta this is the territory of Identity Threat Protection, with continuous risk evaluation and universal logout as the enforcement end.
- Universal logout
- Ending a user's sessions across every connected application simultaneously, so a stolen session dies everywhere rather than only at the app where it was noticed.
Where to start
- Confirm identity logs actually reach your SIEM, with enough context to act on.
- Turn on risk evaluation that runs during the session, not only at sign-in.
- Move factors toward phishing resistance, so fatigue attacks have nothing to hammer.
- Write the response playbook: who is paged, what gets ended, who tells the user.
- Test it with a tabletop exercise before an incident tests it for you.
Frequently asked
How is ITDR different from a SIEM or EDR?
EDR watches endpoints and a SIEM aggregates logs from everything. ITDR is the identity-specific layer: it understands what a risky session or an anomalous privilege change looks like, and it can respond with identity controls such as step-up or universal logout, which neither of the others can do.
Does strong MFA make ITDR unnecessary?
No. MFA raises the cost of getting in, but session tokens issued after a legitimate MFA can still be stolen, and helpdesk social engineering bypasses factors entirely. Detection covers the attacks that authentication cannot.
What are shared signals?
Open standards, CAEP and RISC under the Shared Signals Framework, that let security tools tell each other about risk in near real time, so a detection in one product can trigger a response in another. Okta both sends and receives them.
Last reviewed 2026-08-17 by the Axiom Identity practice.
Want this assessed in your own environment?
Reading about it is not the same as deciding it. The free CIAM assessment asks four quick questions and hands you a personalized report on the spot.