Join our Newsletter — 33% off our NHI Course
Home› Guides› Identity Threat Detection and Response (ITDR) Guide
Guide Identity Visibility, Posture & Threat Detection

Identity Threat Detection and Response (ITDR) Guide

← All guides
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 5 min read
On this page

Attackers increasingly log in rather than break in. Stolen passwords, phished sessions, abused service accounts, forged tokens and social-engineered MFA resets let them move through an environment using valid identities that traditional endpoint and network tools treat as legitimate. Identity threat detection and response (ITDR) focuses on detecting and stopping these identity-based attacks: across directories, identity providers, cloud IAM, SaaS and, increasingly, non-human identities and AI agents. This guide explains what ITDR covers, the attack techniques it targets, the detections that matter and how to respond.

Key takeaways

  • ITDR protects the identity infrastructure itself (directories, IdPs, federation) and detects misuse of identities across the environment.
  • It must cover human and non-human identities. Service accounts, OAuth apps and tokens are some of the most abused.
  • Good ITDR combines posture (fixing weaknesses before they are exploited) with detection and response (catching and containing active attacks).
  • Response for identity attacks means revoking sessions and tokens, resetting credentials and removing persistence, not just isolating a laptop.

What ITDR covers

  • Directory attacks: Kerberoasting, pass-the-hash and pass-the-ticket, DCSync, golden and silver tickets, abuse of delegation and certificate services.
  • Identity provider attacks: password spraying, MFA fatigue, adversary-in-the-middle phishing, session token theft, malicious federation, MFA reset abuse.
  • Cloud identity attacks: access key theft, role assumption chains, privilege escalation through IAM misconfiguration, new credentials added to service principals.
  • SaaS and OAuth attacks: consent phishing, stolen OAuth tokens, malicious inbox rules and mailbox access.
  • Non-human identity misuse: service accounts used from new hosts, API keys used from unfamiliar infrastructure, tokens replayed. See the Service Account Security Guide.
  • AI agent misuse: agents using credentials outside their purpose. See the AI Agent Observability and Incident Response Guide.

Recent identity-led attacks

  • Scattered Spider social-engineered help desks to take over accounts at MGM Resorts and Caesars.
  • Storm-2949 turned one cloud identity, obtained through a phone call, into a full Azure compromise.
  • Midnight Blizzard used password spraying on a legacy account and abused an OAuth application.
  • Snowflake customer breaches used stolen credentials against accounts without MFA.
  • Stryker saw its device management platform used to wipe devices at scale, showing what an attacker with administrative access to a management platform can do.

Core detections

AreaSignals to detect
AuthenticationPassword spraying; MFA fatigue patterns; impossible travel; sign-ins from anonymising infrastructure; legacy protocol use
Sessions and tokensToken replay from new devices or networks; session cookie reuse; refresh token abuse
Account changesMFA method changes, password resets and new devices followed by sensitive activity; help-desk resets for privileged users
PrivilegeNew admin role assignments; changes to privileged groups; just-in-time elevation outside normal patterns
PersistenceNew federation trusts; new credentials on apps and service principals; new OAuth consents with high scopes; mailbox rules
Directory attacksKerberoasting requests; DCSync from non-domain controllers; unusual ticket properties
Non-human identitiesService account interactive logon; keys used from new sources; unusual API volumes; dormant identities becoming active

Posture: reduce the attack surface

Many ITDR tools also assess identity posture. Priorities include:

  • Phishing-resistant MFA for administrators; MFA everywhere; legacy authentication disabled.
  • Fewer standing administrators; just-in-time elevation.
  • Kerberoastable accounts with strong passwords or gMSAs; delegation and certificate template weaknesses fixed.
  • Dormant accounts and unused app credentials removed.

See the ISPM Guide and the Active Directory and Entra ID Hardening Guide.

Response playbook for identity compromise

  1. Contain: disable the account or identity, revoke all sessions and refresh tokens, and block the source.
  2. Reset: reset passwords and MFA methods through a verified process; rotate keys and secrets for affected non-human identities.
  3. Remove persistence: check for new MFA methods, app credentials, OAuth grants, federation trusts, mailbox rules, role assignments and scheduled tasks.
  4. Scope: review activity by the identity across IdP, cloud, SaaS and endpoints since first compromise.
  5. Recover and harden: fix the weakness that enabled the attack.

Automate the first steps through SOAR where confidence is high, and use shared signals (such as CAEP) so revocation propagates to applications quickly.

Where ITDR sits

ITDR overlaps with SIEM and XDR (detection), IdP security features, ISPM (posture) and PAM (privileged access). It adds value by understanding identity-specific context: which accounts are privileged, how they normally behave, and how attack paths connect them. See the ITDR Buyer's Guide.

Practitioner checklist

  • Collect identity telemetry from directories, IdPs, cloud IAM, SaaS and NHI sources.
  • Implement detections for authentication abuse, token replay, account changes, privilege changes and persistence.
  • Baseline and monitor service accounts, OAuth apps and AI agents, not only users.
  • Fix high-risk posture issues: MFA gaps, standing admins, Kerberoastable accounts, dormant identities.
  • Build identity-specific response playbooks, including session and token revocation.
  • Rehearse identity compromise scenarios, including help-desk social engineering.

Standards and references

Related NHI Mgmt Group resources: IdP and SSO Security Guide · Privileged Access Management Guide · 52 Non-Human Identity Breaches · NHI and AI Identity Breaches

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org