What is identity threat detection and response?
ITDR is the set of controls that monitor identities in use and respond when one starts behaving like it has been taken over. It scores sign-ins and accounts for risk, watches sessions after authentication, and then does something about it: forcing a step-up prompt, killing the session, or resetting the password without waiting for a human to read an alert.
The word covers a capability, not a product category you have to go shopping for. Microsoft and Okta both ship it inside their identity platforms. The interesting question for a buyer is not which ITDR vendor to pick, it is which parts you already hold a licence for and whether any of them are set to act.
What ITDR watches for
Stolen session tokens
A token lifted from a device replays a login that already passed MFA. Nothing is re-prompted, so nothing looks wrong.
MFA fatigue approvals
Repeated push prompts until someone taps approve to make them stop. The sign-in is technically valid.
Impossible travel and anonymised IPs
Two sign-ins that cannot both be genuine, or traffic arriving through anonymising infrastructure.
Leaked credentials
Usernames and passwords found in breach data that still work against your tenant.
Privilege escalation
An ordinary account quietly acquiring admin rights, app consent, or a new authentication method.
Unhealthy devices
A valid user signing in from an endpoint that is unencrypted, out of date, or not managed at all.
What does ITDR cover that MFA and SSO do not?
Single sign-on and multi-factor authentication decide who gets in. Both make their decision once, at the door, and then stop paying attention. ITDR deals with everything after that moment: a session token lifted from a laptop, an attacker who has already passed MFA, a push prompt someone finally approved at the end of a long day.
This is why an estate with strong SSO and enforced MFA can still be compromised without a single failed login appearing anywhere. The attacker did not break authentication, they inherited it. Detection has to run continuously against live sessions and account changes, and the response has to be automatic, because the attack does not wait for office hours.
If you are still working out the layer underneath this, our plain English guide to identity and access management covers SSO, MFA and provisioning first.
Who provides affordable ITDR tools for Microsoft Entra or Okta users?
Microsoft and Okta themselves. The affordable option is almost always a tier already on your invoice: Entra ID Protection comes with the P2 tier that is bundled into Microsoft 365 E5, and Okta includes ThreatInsight in the base platform. The cheapest real coverage is normally the step up to P2, or Okta's Identity Threat Protection add-on, and not a separate vendor at all.
That answer disappoints people who arrive expecting a shortlist of challenger products. It is still the right one. A third product adds a second console, a second alert queue and a second renewal, and it detects a large overlap of what you already hold. Spend the money on getting the licence you own set to act instead.
Volobyte configures either platform and will tell you when you already hold the licence and only need it switched on. Our identity and access management service starts from £4,999 for a single identity provider, and risk policy configuration is part of that work rather than a separate line.
Not sure which tier you are on?
A 20-minute call is usually enough to tell you what your current licences already include and which risk policies are sitting in report-only mode.
How ITDR works with Microsoft Entra ID
Entra ID Protection scores every sign-in and every user for risk, using signals such as leaked credentials, anonymised IP addresses and improbable travel. Its real value is that those scores are available as a condition inside Conditional Access, so a risky sign-in can be forced through step-up authentication or blocked outright with nobody reading an alert. It needs the P2 tier, which is included in Microsoft 365 E5.
Device health is part of the same decision. Conditional Access reads compliance straight from Intune and threat signal from Microsoft Defender, so an unencrypted or out-of-date endpoint can be refused with no extra plumbing.
One thing teams miss: if your estate still has domain controllers, Defender for Identity is the piece that watches on-premise Active Directory, and it is a separate product from Entra ID Protection. A cloud-only risk policy says nothing about what is happening in the directory the cloud syncs from.
How ITDR works with Okta
Okta splits the same job in two. ThreatInsight is included in the base platform and works before authentication, blocking or flagging requests from IP addresses already behaving badly across Okta's customer base. Continuous evaluation during a live session, meaning risk is reassessed after login and the session is cut when it changes, is Okta Identity Threat Protection, a separately licensed add-on.
For device health, Okta Device Trust takes the posture signal from Jamf, IRU, CrowdStrike or SentinelOne. That is the better fit for a Mac-first or mixed fleet that Intune does not manage, and it is the main reason Okta keeps winning in estates with a lot of Apple hardware and a lot of non-Microsoft SaaS.
The blunt version: on Okta, budget for the add-on explicitly or accept that your detection stops at the front door.
The licensing shortcut
Entra ID P1 is included with Microsoft 365 E3 and P2 with E5. If you hold E5, you have already bought identity threat detection twice over, and the honest advice is to switch it on rather than buy a third product.
Okta is priced per user per month, per module, so a quote that only covers single sign-on will look cheaper than the deployment you actually want.
Compare Okta and Entra ID in full →Do I need a third-party ITDR tool on top of Okta or Entra ID?
Usually not, and rarely as the first purchase. Most estates we audit already own detection they have not enabled, or have every risk policy left in report-only mode, which produces alerts nobody reads and no actual protection.
Configure automated response first: step-up authentication, session revocation, forced password reset. That is the part that works outside office hours, and it is the part that costs nothing beyond the licence you hold. A dedicated ITDR product earns its place once identity signals need correlating with endpoint and network data across a security team that is staffed to act on them. If nobody owns the alert queue, a fourth console makes things worse.
How does Okta Identity Engine compare with Entra ID and CrowdStrike?
It is not a three-way choice, because those three products do different jobs. Okta Identity Engine is the authentication policy layer, covering per-application rules, FastPass passwordless and step-up prompts. Entra ID is the equivalent for a Microsoft estate, with Conditional Access as its policy layer. CrowdStrike is endpoint detection that feeds device and threat signal into whichever of the two you run.
So the real decision is Okta or Entra ID as your identity provider, then CrowdStrike wired in behind it as the device signal. Anyone presenting the three as competing line items on the same quote has misread what you are buying.
What Volobyte actually deploys
We deploy and support both identity platforms and recommend on fit, not margin. On the identity threat side the work is almost always the same four steps, in this order.
How we turn ITDR on
Find the licence you already hold
E3, E5, P1, P2 or Okta base and add-ons. Most estates are paying for detection nobody has enabled.
Day one
Take the risk policies out of report-only
Sign-in risk and user risk wired into Conditional Access or Okta authentication policies, set to act.
The part that matters
Wire in the device signal
Intune and Defender for a Microsoft estate; Jamf, IRU, CrowdStrike or SentinelOne through Okta Device Trust for a Mac-first or mixed fleet.
Any fleet
Automate the response
Step-up authentication, session revocation, forced password reset and leaver offboarding, so the reaction does not depend on somebody being awake.
Runs overnight
This sits inside our identity work rather than beside it. A proper rollout with conditional access, provisioning and risk policies configured takes 4 to 8 weeks; our fastest was 21 days, for a 450-person scaleup with 45 applications and a deadline. Projects start from £4,999 for a single identity provider and £7,999 where a migration or a second platform is involved. The price is fixed once the work is scoped.
See the identity and access service →Find out what your licence already covers
Book a free 20-minute call. We will tell you which risk policies you already own, which are set to report instead of act, and what it costs to fix.