- ITDR
- Buying
Active Directory is still the target: questions ITDR buyers should ask in 2026
SHORT ANSWER
Published 2026-08-11 · NextGen Identity Security desk · 4 min read
AI agents take up much of the attention in identity security this year, but the directory underneath remains the prize. An attacker who controls Active Directory controls every account it issues. This post sets out the questions that separate ITDR tools for directory environments, using what the ITDR vendors on our ITDR page publish.
What does it watch?
Coverage comes first. Microsoft Defender for Identity monitors on-premises Active Directory, Entra ID and other identity providers such as Okta, using lightweight sensors on identity infrastructure and API connectors. Semperis Directory Services Protector reads the Active Directory replication stream and scans for hundreds of indicators of exposure and compromise across Active Directory and Entra ID. Silverfort states that it covers every human and machine in a hybrid environment. Okta Identity Threat Protection watches Okta sessions.
Which attacks does it name?
Ask for the list, by name. Silverfort's page names brute force, password spraying, credential stuffing, Pass-the-Hash, Pass-the-Ticket, Kerberoasting and DCSync, plus privilege escalation and lateral movement. Okta names session hijacking, impossible travel, token theft, anomalous IP addresses and device posture. A vendor that names the technique can usually say what it does about it.
Can it stop the attack, or only report it?
This is where the tools differ most. Silverfort blocks, challenges with MFA or ends the session inline, before authentication completes. Okta can challenge with MFA, end sessions or trigger Universal Logout. Microsoft Defender for Identity is positioned for detection, investigation and response, with identity alerts correlated into incidents in the Microsoft Defender portal; inline blocking at authentication is not described on its overview page. Semperis responds by rolling back malicious changes rather than blocking sign-ins.
What happens after a bad change?
Detection does not undo damage. Semperis automatically rolls back malicious changes in Active Directory and Entra ID, and sells Active Directory forest recovery, disaster recovery for an Entra tenant and recovery for Okta. Ask every vendor what the recovery plan is if a domain controller or the tenant configuration is compromised, and how often that plan can be rehearsed.
How do I find weaknesses before an attacker does?
Posture tools show the paths an attacker would take. Semperis's Purple Knight is a free assessment that checks 218+ indicators of exposure and compromise across Active Directory, Entra ID and Okta and produces a report card with remediation guidance; Forest Druid maps attack paths to Tier 0 assets. Microsoft Defender for Identity feeds posture assessments into Microsoft Secure Score and shows lateral movement paths.
Where does the identity provider fit?
An ITDR tool assumes some sign-ins will be malicious. The identity provider can reduce how many are possible, especially for forged tokens. NewCore's Secure Split Key needs a key share held in the customer's environment to sign any token, which targets forged assertions of the Golden SAML kind. NewCore does not publish an ITDR detection catalogue; the ITDR page shows how that affects its scores. The two approaches do not replace each other: an organization that keeps Active Directory still needs detection there.
A short list to take into demos
- Which identity systems do you watch, and how: sensor, replication stream, API or inline?
- Name the attacks you detect.
- Which of them can you stop before access is granted?
- What do you do after a malicious change, and can you roll it back?
- Is there a free or trial assessment we can run first?
- How are you priced?
On the last question: Silverfort and Semperis do not publish product prices, Okta prices Identity Threat Protection on request as an add-on, and licensing for Microsoft Defender for Identity is not stated on its overview page.
Related
Sources
- Microsoft Learn: Defender for Identity: https://learn.microsoft.com/en-us/defender-for-identity/what-is
- Semperis Directory Services Protector: https://www.semperis.com/active-directory-security/
- Semperis products: https://www.semperis.com/
- Semperis Purple Knight: https://www.semperis.com/purple-knight/
- Silverfort: ITDR: https://www.silverfort.com/platform/identity-threat-detection-and-response/
- Okta: Identity Threat Protection: https://www.okta.com/products/identity-threat-protection/
- Okta pricing: https://www.okta.com/pricing/
- NewCore: Identity Security: https://newcore.com/platform/identity-security