TL;DR: SaaS attackers increasingly rely on valid credentials, stolen tokens, and weak identity monitoring to move undetected across apps, according to Valence Security. ITDR matters because traditional IAM controls authenticate users but often miss suspicious behavior after login, where the real abuse now happens.
Editorial analysis by NHI Mgmt Group, based on content published by Valence Security: “Why ITDR is Essential for SaaS Security”.
Key questions
Q: How should security teams detect SaaS identity abuse after login?
A: Security teams should monitor identity behaviour continuously across sessions, apps, and integrations, not just authentication events.
Q: Why do MFA and SSO not stop SaaS identity attacks on their own?
A: Because they mainly control entry, not what a trusted identity does once the session is active.
Q: What are the signs that SaaS and cloud monitoring is failing to catch identity risk?
A: Common warning signs include strong access controls but little clarity about how privileges are used, where data moves, or whether behavior diverges from normal.
Practitioner guidance
- Strengthen post-login detection Correlate SaaS activity logs, token use, and privilege changes so unusual behaviour is visible after authentication succeeds.
- Baseline normal identity behaviour Define expected access patterns for users, service accounts, and integrations so deviations can be flagged quickly across apps.
- Watch for token abuse and session persistence Alert on legacy OAuth tokens, newly created tokens, and sessions that remain active after the expected identity context has changed.
Bottom line: SaaS identity attacks increasingly succeed by abusing valid access paths after authentication, not by breaking the login flow itself.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
ITDR is becoming the control that closes the post-authentication blind spot in SaaS. Traditional IAM tools are designed to decide whether access should begin, but SaaS abuse often starts after the session is already trusted. That means the real governance problem is not authentication success, it is identity behaviour drift across apps, tokens, and integrations. Practitioners should re-centre detection on how access is exercised, not just how it was granted.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What should organisations prioritise first when comparing SSPM and ITDR for SaaS security?
A: Organisations should prioritise the controls that reveal how identities and permissions actually function across SaaS. SSPM helps reduce misconfiguration risk, while ITDR helps detect identity abuse. In practice, the first question is whether the platform can map access, OAuth relationships, and non-human identities well enough to support governance, response, and remediation.
👉 Read our full editorial: ITDR for SaaS security: why identity behavior now matters most