Skip to main content
Has your work email already leaked?Run the 10-second check
Managed ITDR

The credential is working perfectly. That is the problem.

Endpoint tooling is built to find something wrong on a machine. When the intruder holds a real account and uses it the way that account is supposed to be used, there is nothing wrong on any machine. Identity threat detection and response is the layer that sees it anyway.

What managed ITDR is

Identity threat detection and response is the monitoring of identity systems, principally Active Directory and Entra ID, for signs that an account rather than a machine is under an adversary's control, together with the ability to respond at the account level.

Managed ITDR means somebody else runs it: deployment onto the directory, the behavioral baselining that makes identity detection work, 24/7 monitoring, and response executed under a pre-approved runbook rather than emailed to you.

Vijilan delivers it on CrowdStrike Falcon® Identity Threat Protection. Response at the account level means disabling the account, forcing a reset, revoking sessions or challenging with MFA, because isolating an endpoint does not help when the credential is the compromise.

Why it needs its own layer

Four things nothing else is watching.

Credentials that are working correctly

The intrusion that matters uses a real account, authenticating the way that account always authenticates. Nothing is malformed, nothing is blocked, and nothing about the individual events is wrong. The pattern is what is wrong.

Lateral movement inside normal permissions

Once inside, an adversary moves using access the account already had. This is why endpoint telemetry alone reports a quiet week: no malware ran, no policy was violated, and a server was reached by somebody permitted to reach it.

Privilege escalation that looks like administration

Group changes, delegation, service account abuse and certificate misuse all appear as legitimate directory operations. Catching them requires knowing what your directory normally looks like, which is a baseline nobody has on day one.

Identity infrastructure as the target

Domain controllers and identity providers are where the keys live, so they are where a capable intruder goes. Monitoring them is different work from monitoring a laptop, and it is frequently nobody’s job.

The CrowdStrike 2026 Global Threat Report puts valid account abuse at 35% of cloud incidents and malware-free detections at 82% of the 2025 total, up from 51% in 2020. Figures are CrowdStrike’s, covering January to December 2025. What those findings mean.

The service

What we actually run.

  1. 01

    Deployment on the directory, not just the endpoints

    Sensors on domain controllers and traffic inspection across the identity estate, covering Active Directory and Entra ID under one control plane. This is the part customers most often start and do not finish.

  2. 02

    A baseline before an alert

    Detection on identity is comparative: it needs to know what normal looks like for this directory, these accounts and these service principals. Establishing that is the first weeks of the engagement and the reason a tool alone underperforms.

  3. 03

    Response that reaches the account

    Disabling an account, forcing a password reset, revoking sessions or challenging with MFA, executed by the SOC under a runbook you approved. Isolating the endpoint does not help when the credential is the compromise.

  4. 04

    Correlated with everything else

    Identity events land in the same investigation queue as endpoint, cloud and email, because an intrusion crossing three domains is invisible to three teams watching one each.

Questions

ITDR, answered plainly.

What is ITDR?

Identity threat detection and response: monitoring identity systems such as Active Directory and Entra ID for compromise, and responding when an account rather than a machine is the thing under an adversary’s control. It exists as a category because endpoint and network tooling are structurally poor at it.

How is ITDR different from identity and access management?

IAM decides who should have access, and does it before anything happens. ITDR watches what actually happens afterwards and assumes that at some point a legitimate credential will be in the wrong hands. They are complements, and an organization with excellent IAM and no ITDR is a common and dangerous shape.

Is ITDR the same as privileged access management?

No. PAM controls and brokers privileged access; it is a control. ITDR detects and responds to identity compromise, including compromise of privileged accounts that PAM is managing. Vijilan operates both, and managed PAM has its own page.

Does our EDR not already cover this?

Only incidentally. EDR watches processes and files on hosts. When an adversary signs in with a valid credential, opens a legitimate remote administration tool and reaches a file share the account is permitted to reach, the endpoint has nothing anomalous to report. The CrowdStrike 2026 Global Threat Report puts valid account abuse at 35% of cloud incidents and malware-free detections at 82% of the total, which is the same observation from the other direction.

What does Vijilan actually run?

CrowdStrike Falcon® Identity Threat Protection, deployed onto your directory and operated by our 24/7 SOC. We operate the platform; CrowdStrike builds it. Where identity is part of a wider engagement it runs inside ThreatDefend™ alongside the rest of the Falcon estate.

We are an MSP. Can we deliver this to clients?

Yes, white-label like every tier, and it tends to be an easier conversation than endpoint because the client has usually already had a credential incident. We never compete with our partners for their clients.

How long before it is useful?

Deployment is fast. Useful detection takes longer, because identity detection is comparative and the baseline has to exist first. Any provider promising meaningful identity detection on day one is describing a product installation rather than a working service.

We're online · book a SOC walkthrough today

Find out who can reach what
before somebody else does.

The identity assessment maps accounts, privilege and the paths between them, run on CrowdStrike Falcon at no license cost for a sixty day window. You keep the findings either way.