TL;DR: Gartner’s Security & Risk Management Summit surfaced a clear convergence point for security teams: identity security, endpoint detection and response, and XDR are increasingly being discussed as linked building blocks rather than separate disciplines, according to SentinelOne’s conference recap. The practical question is no longer whether identity belongs in detection strategy, but how tightly governance, visibility, and response are integrated.
NHIMG editorial — based on content published by SentinelOne: Gartner summit takeaways on XDR, ITDR, and identity security
Questions worth separating out
Q: How should security teams correlate identity and endpoint signals in XDR?
A: Teams should define cross-source incident patterns that combine authentication failures, privilege changes, endpoint process behaviour, and unusual data movement.
Q: Why does identity now matter so much in detection and response programmes?
A: Identity is the control plane for most access decisions, so abuse often shows up first as unusual authentication, permission change, or delegation behaviour.
Q: What do security teams get wrong about composable security?
A: They often treat composability as a buying preference rather than a governance requirement.
Practitioner guidance
- Integrate identity events into SOC detections Feed authentication, privilege-change, and directory events into SIEM and XDR workflows so analysts can correlate identity misuse with endpoint and cloud activity.
- Align ITDR with entitlement review cycles Use access reviews to validate entitlement accuracy, then layer detection rules on top of high-risk accounts, admin paths, and delegated access paths that are rarely exercised.
- Assess API readiness across security tools Prioritise identity platforms and adjacent security controls that expose events, webhooks, and APIs cleanly enough to support composable security operations.
What's in the full article
SentinelOne's full article covers the operational detail this post intentionally leaves for the source:
- How the XDR and identity security capabilities were presented alongside the Attivo Networks acquisition context.
- The specific identity security capabilities shown for Active Directory and Azure AD attack surface reduction.
- The article's fuller discussion of CIEM, identity as a perimeter, and why composable security was central to the summit takeaways.
- The vendor's broader reflections from Gartner sessions and practitioner meetings that informed the recap.
👉 Read SentinelOne's summit recap on XDR, ITDR, and identity security →
XDR and identity security: what practitioners need to prioritise now?
Explore further
Identity security is no longer a separate control domain from detection. The summit recap reflects a market shift in which identity evidence is increasingly treated as operational telemetry, not just governance data. That has direct consequences for IAM and NHI programmes because access control now feeds threat detection and incident response in real time. Security teams that keep these functions separated will continue to miss abuse patterns that only become visible when identity and endpoint data are correlated.
A question worth separating out:
Q: How should organisations govern non-human identities in an XDR-driven stack?
A: Treat service accounts, tokens, and workload identities as monitored assets with named ownership, lifecycle controls, and detection coverage. NHI governance should not stop at issuance and rotation. It must also ensure the security stack can see abnormal use, privilege drift, and suspicious delegation across the runtime environment.
👉 Read our full editorial: Identity security and XDR are converging as attack surfaces expand