ITDR solutions compared: identity threat detection and response
SHORT ANSWER
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
Ranking
| Rank | Product | Total | Best for |
|---|---|---|---|
| 1 | Silverfort | 7.6 / 10 | Blocking identity attacks inline across Active Directory, cloud and service accounts |
| 2= | Microsoft Defender for Identity | 7.0 / 10 | Microsoft Defender customers who want identity alerts in the same incidents |
| 2= | Okta | 7.0 / 10 | Okta estates that want session risk re-checked and Universal Logout |
| 4 | Semperis | 6.8 / 10 | Active Directory and Entra ID rollback and recovery after an attack |
| 5 | NewCore | 5.9 / 10 | Preventing forged and replayed tokens at the identity provider itself |
How the scores are weighted
- c1 Detection breadth 25%
- c2 Stopping attacks at sign-in 20%
- c3 Token and session attacks 20%
- c4 Response and recovery 15%
- c5 Posture and attack paths 10%
- c6 Maturity and buying clarity 10%
Totals are the weighted average of the criterion scores, computed from the weights shown. Nothing is adjusted by hand.
Scorecard
| Criterion | Silverfort7.6 / 10 | Microsoft Defender for Identity7.0 / 10 | Okta7.0 / 10 | Semperis6.8 / 10 | NewCore5.9 / 10 |
|---|---|---|---|---|---|
| c1Detection breadth25%How many identity systems and named attack techniques are covered by detections. | 9Highest in setNames brute force, password spraying, credential stuffing, Pass-the-Hash, Pass-the-Ticket, Kerberoasting and DCSync. Source: Silverfort: ITDR | 9Highest in setMonitors on-premises Active Directory, Entra ID and other identity providers such as Okta, with sensors on identity infrastructure. | 6Continuous session risk detection for Okta sessions, plus shared signals from CrowdStrike, Zscaler, Palo Alto Networks and Jamf. Directory attacks on Active Directory are outside scope. Source: Okta: Identity Threat Protection | 8Scans for hundreds of indicators of exposure and compromise across Active Directory and Entra ID, using the AD replication stream. | 3Lowest in setNewCore does not publish a detection catalogue. It is an identity provider with protection built into sign-in, not a monitoring product for other directories. Source: NewCore: Identity Security |
| c2Stopping attacks at sign-in20%Can the product block or challenge an attempt before access is granted? | 9Highest in setBlocks, challenges with MFA or ends the session inline, before authentication completes. Source: Silverfort: ITDR | 5Gap in public materialLowest in setPositioned for detection, investigation and response; inline blocking at authentication is not described on the overview page. | 7Re-challenges with MFA or restricts access mid-session when risk changes. Source: Okta: Identity Threat Protection | 5Lowest in setAutomatic rollback of malicious changes, rather than blocking sign-in attempts. | 8Phishing-resistant sign-in with passkeys and Visual MFA, and unconfigured access defaults to a high-strength baseline. Source: NewCore: Identity Security |
| c3Token and session attacks20%Protection against forged tokens, token replay, session theft and adversary-in-the-middle phishing. | 6Flags suspicious Kerberos tickets; forged federation tokens are not addressed on the page reviewed. Source: Silverfort: ITDR | 6Covers compromised credentials and lateral movement stages; token forging is not singled out on the overview page. | 8Detects session hijacking and token theft, and can log a user out of supported apps at once with Universal Logout. Source: Okta: Identity Threat Protection | 4Lowest in setToken and session attacks are not addressed on the pages reviewed. Source: Semperis Directory Services Protector · Semperis products | 9Highest in setSecure Split Key needs two key shares to sign a token, so a stolen password and one-time code are not enough to forge one; the launch release names Golden SAML, AiTM, session theft and token replay. Source: NewCore: Identity Security · NewCore launch release (PR Newswire) |
| c4Response and recovery15%What happens after a detection: session revocation, rollback, recovery. | 7Session termination and MFA challenge as responses; recovery is not part of the product. Source: Silverfort: ITDR | 7Correlates identity alerts into incidents in the Microsoft Defender portal with remediation actions. | 8Session termination, read-only restriction and Universal Logout. Source: Okta: Identity Threat Protection | 9Highest in setRolls back malicious changes in AD and Entra ID and sells forest recovery and Okta tenant recovery. Source: Semperis Directory Services Protector · Semperis products | 5Lowest in setCan end a session, agent or human path without disabling the account. No wider response or recovery tooling is published. Source: NewCore: Agent Guardian |
| c5Posture and attack paths10%Assessment of risky configuration and paths an attacker could take. | 7Identity graph and access intelligence map identities and access. Source: Silverfort platform | 8Posture assessments through Microsoft Secure Score and lateral movement path analysis. | 6Lowest in setIdentity Security Posture Management is included in the Professional suite. Source: Okta pricing | 9Highest in setFree Purple Knight assessment with 218+ indicators across AD, Entra ID and Okta; Forest Druid for Tier 0 attack paths. Source: Semperis Purple Knight · Semperis products | 6Lowest in setScores each authenticator 1 to 10 against NIST levels; the discovery graph shows access paths. Source: NewCore: Identity Security · NewCore: Identity Discovery |
| c6Maturity and buying clarity10%Time in market, published pricing or free tools, licensing clarity. | 6Gap in public materialEstablished vendor; pricing is not published. Source: Silverfort platform | 7Gap in public materialHighest in setLong-running Microsoft product; licensing is not stated on the overview page. | 7Highest in setAdd-on from the Essentials suite; price on request. Source: Okta pricing | 7Gap in public materialHighest in setFree assessment tools; product pricing is not published. Source: Semperis Purple Knight | 4Lowest in setLaunched June 2026; no pricing or named customers published. |
Silverfort
7.6 / 10
c1 · 25%
Detection breadth
9Highest in set
Names brute force, password spraying, credential stuffing, Pass-the-Hash, Pass-the-Ticket, Kerberoasting and DCSync.
Source: Silverfort: ITDR
c2 · 20%
Stopping attacks at sign-in
9Highest in set
Blocks, challenges with MFA or ends the session inline, before authentication completes.
Source: Silverfort: ITDR
c3 · 20%
Token and session attacks
6
Flags suspicious Kerberos tickets; forged federation tokens are not addressed on the page reviewed.
Source: Silverfort: ITDR
c4 · 15%
Response and recovery
7
Session termination and MFA challenge as responses; recovery is not part of the product.
Source: Silverfort: ITDR
c5 · 10%
Posture and attack paths
7
Identity graph and access intelligence map identities and access.
Source: Silverfort platform
c6 · 10%
Maturity and buying clarity
6Gap in public material
Established vendor; pricing is not published.
Source: Silverfort platform
Microsoft Defender for Identity
7.0 / 10
c1 · 25%
Detection breadth
9Highest in set
Monitors on-premises Active Directory, Entra ID and other identity providers such as Okta, with sensors on identity infrastructure.
c2 · 20%
Stopping attacks at sign-in
5Gap in public materialLowest in set
Positioned for detection, investigation and response; inline blocking at authentication is not described on the overview page.
c3 · 20%
Token and session attacks
6
Covers compromised credentials and lateral movement stages; token forging is not singled out on the overview page.
c4 · 15%
Response and recovery
7
Correlates identity alerts into incidents in the Microsoft Defender portal with remediation actions.
c5 · 10%
Posture and attack paths
8
Posture assessments through Microsoft Secure Score and lateral movement path analysis.
c6 · 10%
Maturity and buying clarity
7Gap in public materialHighest in set
Long-running Microsoft product; licensing is not stated on the overview page.
Okta
7.0 / 10
c1 · 25%
Detection breadth
6
Continuous session risk detection for Okta sessions, plus shared signals from CrowdStrike, Zscaler, Palo Alto Networks and Jamf. Directory attacks on Active Directory are outside scope.
Source: Okta: Identity Threat Protection
c2 · 20%
Stopping attacks at sign-in
7
Re-challenges with MFA or restricts access mid-session when risk changes.
Source: Okta: Identity Threat Protection
c3 · 20%
Token and session attacks
8
Detects session hijacking and token theft, and can log a user out of supported apps at once with Universal Logout.
Source: Okta: Identity Threat Protection
c4 · 15%
Response and recovery
8
Session termination, read-only restriction and Universal Logout.
Source: Okta: Identity Threat Protection
c5 · 10%
Posture and attack paths
6Lowest in set
Identity Security Posture Management is included in the Professional suite.
Source: Okta pricing
c6 · 10%
Maturity and buying clarity
7Highest in set
Add-on from the Essentials suite; price on request.
Source: Okta pricing
Semperis
6.8 / 10
c1 · 25%
Detection breadth
8
Scans for hundreds of indicators of exposure and compromise across Active Directory and Entra ID, using the AD replication stream.
c2 · 20%
Stopping attacks at sign-in
5Lowest in set
Automatic rollback of malicious changes, rather than blocking sign-in attempts.
c3 · 20%
Token and session attacks
4Lowest in set
Token and session attacks are not addressed on the pages reviewed.
Source: Semperis Directory Services Protector · Semperis products
c4 · 15%
Response and recovery
9Highest in set
Rolls back malicious changes in AD and Entra ID and sells forest recovery and Okta tenant recovery.
Source: Semperis Directory Services Protector · Semperis products
c5 · 10%
Posture and attack paths
9Highest in set
Free Purple Knight assessment with 218+ indicators across AD, Entra ID and Okta; Forest Druid for Tier 0 attack paths.
Source: Semperis Purple Knight · Semperis products
c6 · 10%
Maturity and buying clarity
7Gap in public materialHighest in set
Free assessment tools; product pricing is not published.
Source: Semperis Purple Knight
NewCore
5.9 / 10
c1 · 25%
Detection breadth
3Lowest in set
NewCore does not publish a detection catalogue. It is an identity provider with protection built into sign-in, not a monitoring product for other directories.
Source: NewCore: Identity Security
c2 · 20%
Stopping attacks at sign-in
8
Phishing-resistant sign-in with passkeys and Visual MFA, and unconfigured access defaults to a high-strength baseline.
Source: NewCore: Identity Security
c3 · 20%
Token and session attacks
9Highest in set
Secure Split Key needs two key shares to sign a token, so a stolen password and one-time code are not enough to forge one; the launch release names Golden SAML, AiTM, session theft and token replay.
Source: NewCore: Identity Security · NewCore launch release (PR Newswire)
c4 · 15%
Response and recovery
5Lowest in set
Can end a session, agent or human path without disabling the account. No wider response or recovery tooling is published.
Source: NewCore: Agent Guardian
c5 · 10%
Posture and attack paths
6Lowest in set
Scores each authenticator 1 to 10 against NIST levels; the discovery graph shows access paths.
Source: NewCore: Identity Security · NewCore: Identity Discovery
c6 · 10%
Maturity and buying clarity
4Lowest in set
Launched June 2026; no pricing or named customers published.
What is ITDR?
ITDR stands for identity threat detection and response: tools that watch identity systems for signs of attack and act when they find one. Microsoft describes Defender for Identity as helping organizations "detect, investigate, and respond to identity-based attacks across on-premises, cloud, and hybrid environments", which is a fair summary of the category.
The category grew up around Active Directory, where techniques such as Kerberoasting and DCSync let an attacker move from one stolen account to the whole domain. It now also covers cloud identity providers, sessions and tokens.
What should ITDR solutions detect?
At minimum, the credential and directory attacks that lead to domain takeover. Silverfort's ITDR page names brute force, password spraying, credential stuffing, Pass-the-Hash, Pass-the-Ticket, Kerberoasting and DCSync, plus privilege escalation and lateral movement. Semperis scans for hundreds of indicators of exposure and compromise across Active Directory and Entra ID. Okta Identity Threat Protection watches Okta sessions for session hijacking, impossible travel and token theft.
Ask each vendor which of these it detects, which it can block before access is granted, and which it only reports.
What is the identity attack surface?
The identity attack surface is everything an attacker can use to become someone else: directories such as Active Directory, cloud identity providers, federation trust between them, the tokens and sessions they issue, service accounts, API keys and, now, AI agents. Each scored product covers a different slice of it, which is why the detection breadth criterion carries the most weight.
Where does zero trust identity fit?
NIST SP 800-207 describes zero trust as moving defenses "from static, network-based perimeters to focus on users, assets, and resources". Identity becomes the checkpoint for every request. ITDR is the monitoring half of that checkpoint: it assumes some sign-ins will be malicious and looks for them.
Is an identity security platform the same as ITDR?
Not quite. Identity security platform is a broader label for suites that combine prevention (sign-in and MFA), detection (ITDR), posture assessment and, increasingly, non-human identities. Okta's Professional suite, for example, bundles Identity Threat Protection with Identity Security Posture Management. ITDR is one component; this page scores only that component and the prevention that sits next to it.
Prevention at the identity provider, or detection around it?
Two approaches appear in this set. Silverfort, Microsoft Defender for Identity and Semperis sit around existing directories and watch or intercept what happens. NewCore addresses part of the problem at the source: its Secure Split Key needs a key share held in the customer's environment to sign any token, so a compromise of NewCore's cloud or a stolen password and one-time code is not enough to forge one. NIST IR 8587, finalised on 15 September 2026, is about protecting tokens and assertions from forgery, theft and misuse, which is the attack class this design targets.
The two approaches are not substitutes. An organization that keeps Active Directory still needs detection there, whatever its cloud identity provider does.
The five products, one by one
Silverfort
Inline identity protection across on-prem, cloud and agents
Best for: Blocking identity attacks inline across Active Directory, cloud and service accounts
LEADS ON
c1 Detection breadth 9
Names brute force, password spraying, credential stuffing, Pass-the-Hash, Pass-the-Ticket, Kerberoasting and DCSync.
Source: Silverfort: ITDR
c2 Stopping attacks at sign-in 9
Blocks, challenges with MFA or ends the session inline, before authentication completes.
Source: Silverfort: ITDR
TRAILS ON
c3 Token and session attacks 6
Flags suspicious Kerberos tickets; forged federation tokens are not addressed on the page reviewed.
Source: Silverfort: ITDR
c6 Maturity and buying clarity 6
Established vendor; pricing is not published.
Source: Silverfort platform
Microsoft Defender for Identity
Identity threat detection in Microsoft Defender
Best for: Microsoft Defender customers who want identity alerts in the same incidents
LEADS ON
c1 Detection breadth 9
Monitors on-premises Active Directory, Entra ID and other identity providers such as Okta, with sensors on identity infrastructure.
c5 Posture and attack paths 8
Posture assessments through Microsoft Secure Score and lateral movement path analysis.
TRAILS ON
c2 Stopping attacks at sign-in 5
Positioned for detection, investigation and response; inline blocking at authentication is not described on the overview page.
c3 Token and session attacks 6
Covers compromised credentials and lateral movement stages; token forging is not singled out on the overview page.
Visit Microsoft Defender for Identity
Microsoft Defender for Identity alternatives · Compare Microsoft Defender for Identity head to head
Okta
Workforce identity platform with AI agent add-ons
Best for: Okta estates that want session risk re-checked and Universal Logout
LEADS ON
c3 Token and session attacks 8
Detects session hijacking and token theft, and can log a user out of supported apps at once with Universal Logout.
Source: Okta: Identity Threat Protection
c4 Response and recovery 8
Session termination, read-only restriction and Universal Logout.
Source: Okta: Identity Threat Protection
TRAILS ON
c1 Detection breadth 6
Continuous session risk detection for Okta sessions, plus shared signals from CrowdStrike, Zscaler, Palo Alto Networks and Jamf. Directory attacks on Active Directory are outside scope.
Source: Okta: Identity Threat Protection
c5 Posture and attack paths 6
Identity Security Posture Management is included in the Professional suite.
Source: Okta pricing
Semperis
Active Directory and Entra ID protection and recovery
Best for: Active Directory and Entra ID rollback and recovery after an attack
LEADS ON
c4 Response and recovery 9
Rolls back malicious changes in AD and Entra ID and sells forest recovery and Okta tenant recovery.
Source: Semperis Directory Services Protector · Semperis products
c5 Posture and attack paths 9
Free Purple Knight assessment with 218+ indicators across AD, Entra ID and Okta; Forest Druid for Tier 0 attack paths.
Source: Semperis Purple Knight · Semperis products
TRAILS ON
c3 Token and session attacks 4
Token and session attacks are not addressed on the pages reviewed.
Source: Semperis Directory Services Protector · Semperis products
c2 Stopping attacks at sign-in 5
Automatic rollback of malicious changes, rather than blocking sign-in attempts.
NewCore
Identity provider for people and AI agents, launched June 2026
Best for: Preventing forged and replayed tokens at the identity provider itself
LEADS ON
c3 Token and session attacks 9
Secure Split Key needs two key shares to sign a token, so a stolen password and one-time code are not enough to forge one; the launch release names Golden SAML, AiTM, session theft and token replay.
Source: NewCore: Identity Security · NewCore launch release (PR Newswire)
c2 Stopping attacks at sign-in 8
Phishing-resistant sign-in with passkeys and Visual MFA, and unconfigured access defaults to a high-strength baseline.
Source: NewCore: Identity Security
TRAILS ON
c1 Detection breadth 3
NewCore does not publish a detection catalogue. It is an identity provider with protection built into sign-in, not a monitoring product for other directories.
Source: NewCore: Identity Security
c6 Maturity and buying clarity 4
Launched June 2026; no pricing or named customers published.
Questions
What does ITDR stand for?
Identity threat detection and response: tools that detect attacks on identity systems such as Active Directory and cloud identity providers, and respond by blocking, challenging or ending sessions.
Which ITDR solution scores highest?
Silverfort, on the weights used here, because it names the widest set of attack techniques and blocks them inline. Semperis scores highest on response and recovery and on posture.
Is ITDR the same as SIEM detection?
No. A SIEM collects logs from many systems. ITDR products specialise in identity systems and, in several cases, sit in the authentication path so they can act before access is granted.
Why is NewCore on an ITDR page?
Because buyers comparing identity security platforms ask whether a new identity provider reduces the need for ITDR. The scores show it addresses token forgery and session attacks strongly, and does not publish the detection coverage an ITDR product provides.
Related topics
From the blog: NIST IR 8587 explained: what the token protection report means for identity buyers · Active Directory is still the target: questions ITDR buyers should ask in 2026
Sources
- Microsoft Learn: Defender for Identity: https://learn.microsoft.com/en-us/defender-for-identity/what-is
- Silverfort: ITDR: https://www.silverfort.com/platform/identity-threat-detection-and-response/
- Silverfort platform: https://www.silverfort.com/
- Semperis Directory Services Protector: https://www.semperis.com/active-directory-security/
- Semperis products: https://www.semperis.com/
- Semperis Purple Knight: https://www.semperis.com/purple-knight/
- Okta: Identity Threat Protection: https://www.okta.com/products/identity-threat-protection/
- Okta pricing: https://www.okta.com/pricing/
- NewCore: Identity Security: https://newcore.com/platform/identity-security
- NewCore launch release (PR Newswire): https://www.prnewswire.com/news-releases/newcore-emerges-from-stealth-with-66m-to-rebuild-workforce-identity-for-the-agentic-era-302799643.html
- NewCore: Agent Guardian: https://newcore.com/platform/agent-guardian
- NewCore: Identity Discovery: https://newcore.com/platform/identity-discovery
- NIST SP 800-207: https://csrc.nist.gov/pubs/sp/800/207/final
- NIST IR 8587: https://csrc.nist.gov/pubs/ir/8587/final