This is an update of our November 2025 report, Identity Threat Detection and Response (ITDR). If you would like to read what it encompassed, please click here.
Solutions considered for inclusion in this Leadership Compass must provide a dedicated ITDR offering or demonstrate substantial ITDR capabilities as an integrated component of a broader identity security or cybersecurity platform. ITDR delivered as a managed service is in scope, provided the underlying detection, investigation, and response capabilities are the vendor's own and are evaluable against the criteria below.
At a minimum, qualifying solutions should demonstrate capabilities across the core ITDR lifecycle, including:
- Continuous collection and analysis of identity-related telemetry across multiple identity sources and systems.
- Detection of identity-specific threats, compromise, misuse, and anomalous behavior beyond basic authentication monitoring, with detections mapped to a recognized framework such as MITRE ATT&CK and the ability for customers to author, tune, and suppress detections.
- Identity context and analytics that support the investigation, prioritization, and understanding of identity-related threats.
- Investigation capabilities that enable security teams to understand affected identities, associated activity, privileges, resources, and attack progression.
- Response and remediation capabilities, either natively or through orchestration and integration with IAM, IGA, PAM, SIEM, SOAR, XDR, or other security controls.
- Coverage of multiple identity types and environments, with support for human identities and at least some forms of NHIs.
- Integration with relevant enterprise identity infrastructure, including major directory, authentication, access management, or identity governance systems.
- Active commercial availability and demonstrated use by existing enterprise customers.
Solutions that form part of broader IAM, PAM, or cybersecurity platforms may be included where they demonstrate differentiated ITDR capabilities across detection, investigation, and response against the evaluation criteria.
Identity security posture and exposure management capabilities, including identity configuration assessment, attack-path analysis, excessive privilege identification, and exposure prioritization, will be evaluated as important components of modern ITDR platforms but are not, on their own, sufficient for inclusion.
Support for AI-agent identities and advanced NHI capabilities will be evaluated as areas of differentiation and market evolution but are not mandatory for inclusion in this edition of the Leadership Compass.