📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Identity Threat Detection and Response

What is ITDR (Identity Threat Detection and Response)?

ITDR is the cybersecurity discipline of detecting and responding to attacks against identity systems, such as Microsoft 365, Microsoft Entra ID, Azure AD, and Google Workspace, by analysing authentication events, mailbox configuration changes, OAuth grants, and privileged-role activity. Lavawall® delivers ITDR across cloud tenants from one multi-tenant console.

Start free, no credit card See how it works

Authentication anomalies · mailbox rules · OAuth grants · privileged-role abuse

Definition

ITDR emerged as cyber-attacks shifted from endpoint compromise toward identity compromise. Modern attackers can phish credentials, register malicious OAuth apps, or exploit misconfigured admin roles without planting malware. Once inside the identity system, they can read mail, exfiltrate files, and access downstream resources.

ITDR treats the identity layer as a primary detection surface, pulling signals from Microsoft 365, Entra ID, Azure, Google Workspace, Okta, Auth0, and federated services like Exchange Online, OneDrive, SharePoint, Teams, Gmail, Drive, Calendar, and Meet.

Detections include suspicious mailbox-rule creation, OAuth-app grants to risky parties, anomalous login patterns, impossible-travel logins with distance and speed analysis, privileged role escalations, secret-write events on app registrations, unusual file activity, and admin-abuse patterns.

For MSPs, ITDR provides coverage that endpoint AV and EDR cannot. Attackers using phished credentials remain invisible to endpoint protection but visible through abnormal login patterns, new mailbox rules, or new OAuth grants. ITDR is a complementary layer to XDR and endpoint EDR, not a replacement for either.

Core components

  • Authentication anomaly detection. Detection of unusual login patterns including new countries, devices, and IP ranges, impossible travel, and brute-force or password-spray patterns.
  • Mailbox rule monitoring. Detection of suspicious rules like auto-forwarding to external addresses, auto-deletion of security warnings, and auto-archiving of incident-response emails.
  • OAuth application monitoring. Detection of newly-granted OAuth applications, especially those with broad mailbox or file access from unfamiliar publishers.
  • Privileged role monitoring. Detection of changes to privileged roles (Global Admin, Privileged Role Admin) and abuse patterns by accounts holding those roles.
  • File activity anomalies. Detection of unusual download volumes, mass deletions, mass external-share grants, and similar compromise indicators.
  • Endpoint correlation. Cross-referencing identity signals with endpoint telemetry to suppress false positives. A login from a new country is less suspicious if the user's workstation just connected from there.
  • Configuration assessment. Continuous evaluation of identity configuration (MFA enforcement, conditional access policies, legacy auth, mailbox audit logging, retention) to enable remediation.

Why it matters

Modern attack data shows identity compromise as a leading initial-access vector. Microsoft's Digital Defense Reports and Verizon's DBIR repeatedly highlight phishing and credential-based attacks as primary entry methods. Endpoint EDR cannot catch attackers who phished credentials without installing anything.

For MSPs managing multiple client tenants, ITDR is a multi-tenant problem at scale. An MSP relying solely on Microsoft Entra "Risky Users" alerts spends most of its time chasing false positives (IPv6 privacy, VPN handoffs, benign travel) unless ITDR correlates signals with endpoint telemetry.

Cyber-insurance assessments and CMMC 2.0 / NIST CSF audits increasingly require identity-protection controls (MFA enforcement, privileged-access management, anomaly detection), making ITDR part of the compliance answer.

How Lavawall® helps with ITDR

Lavawall® delivers comprehensive ITDR for Microsoft 365 / Entra ID / Azure and Google Workspace from a single multi-tenant console. It connects in one click per tenant, correlates cloud signals with endpoint telemetry, and surfaces actionable incidents rather than raw alerts.

False-positive reduction is emphasized. Computers running the Lavawall® agent (Windows, macOS, or Linux) are automatically excluded from login sequences with failed then successful unknown-location logins. The platform accounts for IPv6 privacy and other noise sources. Impossible-travel detection displays actual distance and speed, so technicians can assess whether 800 km in 12 minutes is real or a VPN handoff.

Coverage spans mailbox forwarding rules and suspicious mailbox rules, impossible-travel detection, newly-installed Entra / Azure apps, risky OAuth grants, unusual file activities, admin-abuse detection, and unmanaged device gaps. It all flows into compliance evidence automatically (CMMC 2.0 IA, AC, AU; NIST CSF PR.AA, DE.CM; CIS Controls 5, 6, 8).

Start free → Map controls with the GRC wizard

Frequently asked

Is ITDR the same as IAM?
No. IAM (Identity and Access Management) is the authentication and authorization system (Microsoft Entra ID, Okta, Auth0). ITDR is the detection-and-response layer sitting atop IAM, watching for compromise. They are complementary.
Is ITDR the same as EDR?
No. EDR watches the endpoint; ITDR watches the identity system. Modern security stacks typically include both, with integrations between them.
Does Microsoft Entra ID Protection do this?
Microsoft Entra ID Protection provides "Risky Users" and "Risky Sign-ins" feeds, which are useful inputs but produce significant false-positive volume for MSPs without endpoint correlation. Dedicated ITDR like Lavawall® consumes those signals and adds correlation, a multi-tenant console, and configuration-assessment context for actionability.
How quickly can I add a tenant to ITDR?
With Lavawall®, approximately one click per tenant. The MSP technician logs into the client's Microsoft account, grants the required read-only scopes, and ingestion begins within minutes. Google Workspace is similarly fast (three clicks).