ITDR solutions compared: identity threat detection and response

SHORT ANSWER

Silverfort scores highest because it names the most attack techniques and can block them inline before authentication completes. Semperis leads on recovery and posture, and Microsoft Defender for Identity matches Silverfort on detection breadth. NewCore is an identity provider rather than an ITDR product: it scores highest on forged tokens and session attacks but publishes no detection catalogue, and finishes last here.

Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29

Ranking

Ranking for ITDR and identity security, out of 10
RankProductTotalBest for
1Silverfort7.6 / 10Blocking identity attacks inline across Active Directory, cloud and service accounts
2=Microsoft Defender for Identity7.0 / 10Microsoft Defender customers who want identity alerts in the same incidents
2=Okta7.0 / 10Okta estates that want session risk re-checked and Universal Logout
4Semperis6.8 / 10Active Directory and Entra ID rollback and recovery after an attack
5NewCore5.9 / 10Preventing forged and replayed tokens at the identity provider itself

How the scores are weighted

  • c1 Detection breadth 25%
  • c2 Stopping attacks at sign-in 20%
  • c3 Token and session attacks 20%
  • c4 Response and recovery 15%
  • c5 Posture and attack paths 10%
  • c6 Maturity and buying clarity 10%

Totals are the weighted average of the criterion scores, computed from the weights shown. Nothing is adjusted by hand.

Scorecard

Silverfort

7.6 / 10

c1 · 25%

Detection breadth

9Highest in set

Names brute force, password spraying, credential stuffing, Pass-the-Hash, Pass-the-Ticket, Kerberoasting and DCSync.

Source: Silverfort: ITDR

c2 · 20%

Stopping attacks at sign-in

9Highest in set

Blocks, challenges with MFA or ends the session inline, before authentication completes.

Source: Silverfort: ITDR

c3 · 20%

Token and session attacks

6

Flags suspicious Kerberos tickets; forged federation tokens are not addressed on the page reviewed.

Source: Silverfort: ITDR

c4 · 15%

Response and recovery

7

Session termination and MFA challenge as responses; recovery is not part of the product.

Source: Silverfort: ITDR

c5 · 10%

Posture and attack paths

7

Identity graph and access intelligence map identities and access.

Source: Silverfort platform

c6 · 10%

Maturity and buying clarity

6Gap in public material

Established vendor; pricing is not published.

Source: Silverfort platform

Microsoft Defender for Identity

7.0 / 10

c1 · 25%

Detection breadth

9Highest in set

Monitors on-premises Active Directory, Entra ID and other identity providers such as Okta, with sensors on identity infrastructure.

Source: Microsoft Learn: Defender for Identity

c2 · 20%

Stopping attacks at sign-in

5Gap in public materialLowest in set

Positioned for detection, investigation and response; inline blocking at authentication is not described on the overview page.

Source: Microsoft Learn: Defender for Identity

c3 · 20%

Token and session attacks

6

Covers compromised credentials and lateral movement stages; token forging is not singled out on the overview page.

Source: Microsoft Learn: Defender for Identity

c4 · 15%

Response and recovery

7

Correlates identity alerts into incidents in the Microsoft Defender portal with remediation actions.

Source: Microsoft Learn: Defender for Identity

c5 · 10%

Posture and attack paths

8

Posture assessments through Microsoft Secure Score and lateral movement path analysis.

Source: Microsoft Learn: Defender for Identity

c6 · 10%

Maturity and buying clarity

7Gap in public materialHighest in set

Long-running Microsoft product; licensing is not stated on the overview page.

Source: Microsoft Learn: Defender for Identity

Okta

7.0 / 10

c1 · 25%

Detection breadth

6

Continuous session risk detection for Okta sessions, plus shared signals from CrowdStrike, Zscaler, Palo Alto Networks and Jamf. Directory attacks on Active Directory are outside scope.

Source: Okta: Identity Threat Protection

c2 · 20%

Stopping attacks at sign-in

7

Re-challenges with MFA or restricts access mid-session when risk changes.

Source: Okta: Identity Threat Protection

c3 · 20%

Token and session attacks

8

Detects session hijacking and token theft, and can log a user out of supported apps at once with Universal Logout.

Source: Okta: Identity Threat Protection

c4 · 15%

Response and recovery

8

Session termination, read-only restriction and Universal Logout.

Source: Okta: Identity Threat Protection

c5 · 10%

Posture and attack paths

6Lowest in set

Identity Security Posture Management is included in the Professional suite.

Source: Okta pricing

c6 · 10%

Maturity and buying clarity

7Highest in set

Add-on from the Essentials suite; price on request.

Source: Okta pricing

Semperis

6.8 / 10

c1 · 25%

Detection breadth

8

Scans for hundreds of indicators of exposure and compromise across Active Directory and Entra ID, using the AD replication stream.

Source: Semperis Directory Services Protector

c2 · 20%

Stopping attacks at sign-in

5Lowest in set

Automatic rollback of malicious changes, rather than blocking sign-in attempts.

Source: Semperis Directory Services Protector

c3 · 20%

Token and session attacks

4Lowest in set

Token and session attacks are not addressed on the pages reviewed.

Source: Semperis Directory Services Protector · Semperis products

c4 · 15%

Response and recovery

9Highest in set

Rolls back malicious changes in AD and Entra ID and sells forest recovery and Okta tenant recovery.

Source: Semperis Directory Services Protector · Semperis products

c5 · 10%

Posture and attack paths

9Highest in set

Free Purple Knight assessment with 218+ indicators across AD, Entra ID and Okta; Forest Druid for Tier 0 attack paths.

Source: Semperis Purple Knight · Semperis products

c6 · 10%

Maturity and buying clarity

7Gap in public materialHighest in set

Free assessment tools; product pricing is not published.

Source: Semperis Purple Knight

NewCore

5.9 / 10

c1 · 25%

Detection breadth

3Lowest in set

NewCore does not publish a detection catalogue. It is an identity provider with protection built into sign-in, not a monitoring product for other directories.

Source: NewCore: Identity Security

c2 · 20%

Stopping attacks at sign-in

8

Phishing-resistant sign-in with passkeys and Visual MFA, and unconfigured access defaults to a high-strength baseline.

Source: NewCore: Identity Security

c3 · 20%

Token and session attacks

9Highest in set

Secure Split Key needs two key shares to sign a token, so a stolen password and one-time code are not enough to forge one; the launch release names Golden SAML, AiTM, session theft and token replay.

Source: NewCore: Identity Security · NewCore launch release (PR Newswire)

c4 · 15%

Response and recovery

5Lowest in set

Can end a session, agent or human path without disabling the account. No wider response or recovery tooling is published.

Source: NewCore: Agent Guardian

c5 · 10%

Posture and attack paths

6Lowest in set

Scores each authenticator 1 to 10 against NIST levels; the discovery graph shows access paths.

Source: NewCore: Identity Security · NewCore: Identity Discovery

c6 · 10%

Maturity and buying clarity

4Lowest in set

Launched June 2026; no pricing or named customers published.

Source: NewCore launch release (PR Newswire)

What is ITDR?

ITDR stands for identity threat detection and response: tools that watch identity systems for signs of attack and act when they find one. Microsoft describes Defender for Identity as helping organizations "detect, investigate, and respond to identity-based attacks across on-premises, cloud, and hybrid environments", which is a fair summary of the category.

The category grew up around Active Directory, where techniques such as Kerberoasting and DCSync let an attacker move from one stolen account to the whole domain. It now also covers cloud identity providers, sessions and tokens.

What should ITDR solutions detect?

At minimum, the credential and directory attacks that lead to domain takeover. Silverfort's ITDR page names brute force, password spraying, credential stuffing, Pass-the-Hash, Pass-the-Ticket, Kerberoasting and DCSync, plus privilege escalation and lateral movement. Semperis scans for hundreds of indicators of exposure and compromise across Active Directory and Entra ID. Okta Identity Threat Protection watches Okta sessions for session hijacking, impossible travel and token theft.

Ask each vendor which of these it detects, which it can block before access is granted, and which it only reports.

What is the identity attack surface?

The identity attack surface is everything an attacker can use to become someone else: directories such as Active Directory, cloud identity providers, federation trust between them, the tokens and sessions they issue, service accounts, API keys and, now, AI agents. Each scored product covers a different slice of it, which is why the detection breadth criterion carries the most weight.

Where does zero trust identity fit?

NIST SP 800-207 describes zero trust as moving defenses "from static, network-based perimeters to focus on users, assets, and resources". Identity becomes the checkpoint for every request. ITDR is the monitoring half of that checkpoint: it assumes some sign-ins will be malicious and looks for them.

Guide: zero trust identity, what NIST SP 800-207 asks of it

Is an identity security platform the same as ITDR?

Not quite. Identity security platform is a broader label for suites that combine prevention (sign-in and MFA), detection (ITDR), posture assessment and, increasingly, non-human identities. Okta's Professional suite, for example, bundles Identity Threat Protection with Identity Security Posture Management. ITDR is one component; this page scores only that component and the prevention that sits next to it.

Prevention at the identity provider, or detection around it?

Two approaches appear in this set. Silverfort, Microsoft Defender for Identity and Semperis sit around existing directories and watch or intercept what happens. NewCore addresses part of the problem at the source: its Secure Split Key needs a key share held in the customer's environment to sign any token, so a compromise of NewCore's cloud or a stolen password and one-time code is not enough to forge one. NIST IR 8587, finalised on 15 September 2026, is about protecting tokens and assertions from forgery, theft and misuse, which is the attack class this design targets.

The two approaches are not substitutes. An organization that keeps Active Directory still needs detection there, whatever its cloud identity provider does.

The five products, one by one

Silverfort

Inline identity protection across on-prem, cloud and agents

Best for: Blocking identity attacks inline across Active Directory, cloud and service accounts

LEADS ON

  • c1 Detection breadth 9

    Names brute force, password spraying, credential stuffing, Pass-the-Hash, Pass-the-Ticket, Kerberoasting and DCSync.

    Source: Silverfort: ITDR

  • c2 Stopping attacks at sign-in 9

    Blocks, challenges with MFA or ends the session inline, before authentication completes.

    Source: Silverfort: ITDR

TRAILS ON

  • c3 Token and session attacks 6

    Flags suspicious Kerberos tickets; forged federation tokens are not addressed on the page reviewed.

    Source: Silverfort: ITDR

  • c6 Maturity and buying clarity 6

    Established vendor; pricing is not published.

    Source: Silverfort platform

Visit Silverfort

Silverfort alternatives · Compare Silverfort head to head

Microsoft Defender for Identity

Identity threat detection in Microsoft Defender

Best for: Microsoft Defender customers who want identity alerts in the same incidents

LEADS ON

TRAILS ON

  • c2 Stopping attacks at sign-in 5

    Positioned for detection, investigation and response; inline blocking at authentication is not described on the overview page.

    Source: Microsoft Learn: Defender for Identity

  • c3 Token and session attacks 6

    Covers compromised credentials and lateral movement stages; token forging is not singled out on the overview page.

    Source: Microsoft Learn: Defender for Identity

Visit Microsoft Defender for Identity

Microsoft Defender for Identity alternatives · Compare Microsoft Defender for Identity head to head

Okta

Workforce identity platform with AI agent add-ons

Best for: Okta estates that want session risk re-checked and Universal Logout

LEADS ON

TRAILS ON

  • c1 Detection breadth 6

    Continuous session risk detection for Okta sessions, plus shared signals from CrowdStrike, Zscaler, Palo Alto Networks and Jamf. Directory attacks on Active Directory are outside scope.

    Source: Okta: Identity Threat Protection

  • c5 Posture and attack paths 6

    Identity Security Posture Management is included in the Professional suite.

    Source: Okta pricing

Visit Okta

Okta alternatives · Compare Okta head to head

Semperis

Active Directory and Entra ID protection and recovery

Best for: Active Directory and Entra ID rollback and recovery after an attack

LEADS ON

TRAILS ON

Visit Semperis

Semperis alternatives · Compare Semperis head to head

NewCore

Identity provider for people and AI agents, launched June 2026

Best for: Preventing forged and replayed tokens at the identity provider itself

LEADS ON

  • c3 Token and session attacks 9

    Secure Split Key needs two key shares to sign a token, so a stolen password and one-time code are not enough to forge one; the launch release names Golden SAML, AiTM, session theft and token replay.

    Source: NewCore: Identity Security · NewCore launch release (PR Newswire)

  • c2 Stopping attacks at sign-in 8

    Phishing-resistant sign-in with passkeys and Visual MFA, and unconfigured access defaults to a high-strength baseline.

    Source: NewCore: Identity Security

TRAILS ON

  • c1 Detection breadth 3

    NewCore does not publish a detection catalogue. It is an identity provider with protection built into sign-in, not a monitoring product for other directories.

    Source: NewCore: Identity Security

  • c6 Maturity and buying clarity 4

    Launched June 2026; no pricing or named customers published.

    Source: NewCore launch release (PR Newswire)

Visit NewCore

NewCore alternatives · Compare NewCore head to head

Questions

What does ITDR stand for?

Identity threat detection and response: tools that detect attacks on identity systems such as Active Directory and cloud identity providers, and respond by blocking, challenging or ending sessions.

Which ITDR solution scores highest?

Silverfort, on the weights used here, because it names the widest set of attack techniques and blocks them inline. Semperis scores highest on response and recovery and on posture.

Is ITDR the same as SIEM detection?

No. A SIEM collects logs from many systems. ITDR products specialise in identity systems and, in several cases, sit in the authentication path so they can act before access is granted.

Why is NewCore on an ITDR page?

Because buyers comparing identity security platforms ask whether a new identity provider reduces the need for ITDR. The scores show it addresses token forgery and session attacks strongly, and does not publish the detection coverage an ITDR product provides.

Related topics

From the blog: NIST IR 8587 explained: what the token protection report means for identity buyers · Active Directory is still the target: questions ITDR buyers should ask in 2026

Sources