Skip to main content

Guide

What is ITDR, and why you probably already pay for it

Identity threat detection and response is the layer that watches what happens after a login succeeds. If you run Microsoft Entra ID or Okta, most of it is already on your invoice and switched off.

Okta · Microsoft Entra ID · Intune · Jamf · CrowdStrike

Call +44 20 7971 1111

We configure both platforms. Mon to Fri, 9am to 6pm.

P2

Entra Tier That Includes ID Protection

Included

Okta ThreatInsight In The Base Platform

4-8 Weeks

Identity Rollout, 21 Days At Fastest

From £4,999

Identity Project, Single IdP

What is ITDR, and who needs it?

ITDR stands for identity threat detection and response: the tooling that spots an attacker who is already inside a valid account, using a stolen session token or an MFA prompt someone approved by mistake, and then acts on it automatically. Any company whose staff sign in to Microsoft 365, Okta or Google Workspace needs it, and almost all of them already own a version of it inside a licence tier they are paying for.

Entra
ID Protection, P2 tier
Okta
ThreatInsight, plus ITP add-on
Usual finding
Licence already owned
Identity project
From £4,999

What is identity threat detection and response?

ITDR is the set of controls that monitor identities in use and respond when one starts behaving like it has been taken over. It scores sign-ins and accounts for risk, watches sessions after authentication, and then does something about it: forcing a step-up prompt, killing the session, or resetting the password without waiting for a human to read an alert.

The word covers a capability, not a product category you have to go shopping for. Microsoft and Okta both ship it inside their identity platforms. The interesting question for a buyer is not which ITDR vendor to pick, it is which parts you already hold a licence for and whether any of them are set to act.

What ITDR watches for

Stolen session tokens

A token lifted from a device replays a login that already passed MFA. Nothing is re-prompted, so nothing looks wrong.

MFA fatigue approvals

Repeated push prompts until someone taps approve to make them stop. The sign-in is technically valid.

Impossible travel and anonymised IPs

Two sign-ins that cannot both be genuine, or traffic arriving through anonymising infrastructure.

Leaked credentials

Usernames and passwords found in breach data that still work against your tenant.

Privilege escalation

An ordinary account quietly acquiring admin rights, app consent, or a new authentication method.

Unhealthy devices

A valid user signing in from an endpoint that is unencrypted, out of date, or not managed at all.

What does ITDR cover that MFA and SSO do not?

Single sign-on and multi-factor authentication decide who gets in. Both make their decision once, at the door, and then stop paying attention. ITDR deals with everything after that moment: a session token lifted from a laptop, an attacker who has already passed MFA, a push prompt someone finally approved at the end of a long day.

This is why an estate with strong SSO and enforced MFA can still be compromised without a single failed login appearing anywhere. The attacker did not break authentication, they inherited it. Detection has to run continuously against live sessions and account changes, and the response has to be automatic, because the attack does not wait for office hours.

If you are still working out the layer underneath this, our plain English guide to identity and access management covers SSO, MFA and provisioning first.

Who provides affordable ITDR tools for Microsoft Entra or Okta users?

Microsoft and Okta themselves. The affordable option is almost always a tier already on your invoice: Entra ID Protection comes with the P2 tier that is bundled into Microsoft 365 E5, and Okta includes ThreatInsight in the base platform. The cheapest real coverage is normally the step up to P2, or Okta's Identity Threat Protection add-on, and not a separate vendor at all.

That answer disappoints people who arrive expecting a shortlist of challenger products. It is still the right one. A third product adds a second console, a second alert queue and a second renewal, and it detects a large overlap of what you already hold. Spend the money on getting the licence you own set to act instead.

Volobyte configures either platform and will tell you when you already hold the licence and only need it switched on. Our identity and access management service starts from £4,999 for a single identity provider, and risk policy configuration is part of that work rather than a separate line.

Not sure which tier you are on?

A 20-minute call is usually enough to tell you what your current licences already include and which risk policies are sitting in report-only mode.

How ITDR works with Microsoft Entra ID

Entra ID Protection scores every sign-in and every user for risk, using signals such as leaked credentials, anonymised IP addresses and improbable travel. Its real value is that those scores are available as a condition inside Conditional Access, so a risky sign-in can be forced through step-up authentication or blocked outright with nobody reading an alert. It needs the P2 tier, which is included in Microsoft 365 E5.

Device health is part of the same decision. Conditional Access reads compliance straight from Intune and threat signal from Microsoft Defender, so an unencrypted or out-of-date endpoint can be refused with no extra plumbing.

One thing teams miss: if your estate still has domain controllers, Defender for Identity is the piece that watches on-premise Active Directory, and it is a separate product from Entra ID Protection. A cloud-only risk policy says nothing about what is happening in the directory the cloud syncs from.

How ITDR works with Okta

Okta splits the same job in two. ThreatInsight is included in the base platform and works before authentication, blocking or flagging requests from IP addresses already behaving badly across Okta's customer base. Continuous evaluation during a live session, meaning risk is reassessed after login and the session is cut when it changes, is Okta Identity Threat Protection, a separately licensed add-on.

For device health, Okta Device Trust takes the posture signal from Jamf, IRU, CrowdStrike or SentinelOne. That is the better fit for a Mac-first or mixed fleet that Intune does not manage, and it is the main reason Okta keeps winning in estates with a lot of Apple hardware and a lot of non-Microsoft SaaS.

The blunt version: on Okta, budget for the add-on explicitly or accept that your detection stops at the front door.

The licensing shortcut

Entra ID P1 is included with Microsoft 365 E3 and P2 with E5. If you hold E5, you have already bought identity threat detection twice over, and the honest advice is to switch it on rather than buy a third product.

Okta is priced per user per month, per module, so a quote that only covers single sign-on will look cheaper than the deployment you actually want.

Compare Okta and Entra ID in full →

Do I need a third-party ITDR tool on top of Okta or Entra ID?

Usually not, and rarely as the first purchase. Most estates we audit already own detection they have not enabled, or have every risk policy left in report-only mode, which produces alerts nobody reads and no actual protection.

Configure automated response first: step-up authentication, session revocation, forced password reset. That is the part that works outside office hours, and it is the part that costs nothing beyond the licence you hold. A dedicated ITDR product earns its place once identity signals need correlating with endpoint and network data across a security team that is staffed to act on them. If nobody owns the alert queue, a fourth console makes things worse.

How does Okta Identity Engine compare with Entra ID and CrowdStrike?

It is not a three-way choice, because those three products do different jobs. Okta Identity Engine is the authentication policy layer, covering per-application rules, FastPass passwordless and step-up prompts. Entra ID is the equivalent for a Microsoft estate, with Conditional Access as its policy layer. CrowdStrike is endpoint detection that feeds device and threat signal into whichever of the two you run.

So the real decision is Okta or Entra ID as your identity provider, then CrowdStrike wired in behind it as the device signal. Anyone presenting the three as competing line items on the same quote has misread what you are buying.

What Volobyte actually deploys

We deploy and support both identity platforms and recommend on fit, not margin. On the identity threat side the work is almost always the same four steps, in this order.

How we turn ITDR on

01

Find the licence you already hold

E3, E5, P1, P2 or Okta base and add-ons. Most estates are paying for detection nobody has enabled.

Day one

02

Take the risk policies out of report-only

Sign-in risk and user risk wired into Conditional Access or Okta authentication policies, set to act.

The part that matters

03

Wire in the device signal

Intune and Defender for a Microsoft estate; Jamf, IRU, CrowdStrike or SentinelOne through Okta Device Trust for a Mac-first or mixed fleet.

Any fleet

04

Automate the response

Step-up authentication, session revocation, forced password reset and leaver offboarding, so the reaction does not depend on somebody being awake.

Runs overnight

This sits inside our identity work rather than beside it. A proper rollout with conditional access, provisioning and risk policies configured takes 4 to 8 weeks; our fastest was 21 days, for a 450-person scaleup with 45 applications and a deadline. Projects start from £4,999 for a single identity provider and £7,999 where a migration or a second platform is involved. The price is fixed once the work is scoped.

See the identity and access service →

Find out what your licence already covers

Book a free 20-minute call. We will tell you which risk policies you already own, which are set to report instead of act, and what it costs to fix.

ITDR FAQs

Is ITDR the same thing as EDR or XDR?

No. EDR watches the device and XDR correlates signals across devices, network and mail. ITDR watches the identity: accounts, sessions, tokens and the privileges attached to them. An attacker who signs in with a valid password and an approved MFA prompt has done nothing your endpoint tooling considers unusual, which is the gap ITDR exists to close.

How much does ITDR cost for a UK company?

In most cases the detection itself is already paid for. Entra ID Protection is part of the P2 tier bundled into Microsoft 365 E5, and Okta ThreatInsight is included in the base platform, so the spend is configuration rather than a new product. Okta Identity Threat Protection is the exception: it is a separately licensed add-on and has to be budgeted for explicitly.

How long does it take to get ITDR working properly?

It is configured as part of an identity rollout rather than as a standalone project. A proper rollout with conditional access, provisioning and risk policies set to act runs 4 to 8 weeks; our fastest was 21 days, for a 450-person scaleup with 45 applications and a deadline.

Does a 50-person company need ITDR?

If it runs Microsoft 365 or Okta, it already has some. The question at that size is not whether to buy identity threat detection but whether the risk policies are set to act or set to report, because a report-only policy protects nobody at 2am. Turning on step-up authentication and session revocation is free at 50 people and takes an afternoon.

What is the most common ITDR mistake?

Leaving every risk policy in report-only mode. We have walked into estates paying for the top licence tier with nothing configured to act on what it detects, which produces a dashboard nobody opens and no actual protection. Automated response is the only part of this that works while everyone is asleep.