A small MSP posted on Reddit not long ago asking a question that resonated with a lot of IT admins: they'd heard of ITDR, suspected it mattered, but couldn't get a straight answer on how it fit with the MDR they already had — and every vendor they contacted ignored them because their client base was too small to be worth the sales call.
If that sounds familiar, this post is for you.
What ITDR Actually Is
Identity Threat Detection and Response (ITDR) is a security category focused specifically on detecting and responding to attacks that target user identities — credentials, authentication tokens, session cookies, and access privileges — rather than endpoints or network traffic.
The distinction matters because most attacks today don't start with malware. They start with a stolen password, a hijacked browser session, or a credential phished over hotel Wi-Fi. Your antivirus is looking for malicious files. Your MDR is watching endpoints and network telemetry. Neither one is watching your identity layer.
According to Schneier on Security, attackers are actively hijacking public Wi-Fi DNS to redirect users to fake login pages — harvesting credentials that look completely legitimate to every downstream security tool. No malware is dropped. No endpoint alert fires. The credential just walks out the door.
The Three Tools Are Not the Same Thing
Here's the plain-language breakdown:
Antivirus / EDR watches files and processes on a device. It catches known malware, suspicious executables, and some behavioral anomalies on the endpoint itself.
MDR (Managed Detection and Response) extends that coverage with human analysts and broader telemetry — network traffic, log aggregation, threat hunting across endpoints. It's powerful, but it's still fundamentally oriented around what's happening on your devices and in your network.
ITDR watches what's happening to your identities — across your directory (Active Directory, Entra ID), your SaaS apps, and your authentication flows. It looks for things like: - Impossible travel (login from Chicago, then Tokyo, 20 minutes apart) - Privilege escalation that shouldn't have happened - Dormant accounts suddenly authenticating - Lateral movement using legitimate credentials - Session token theft and reuse
That last one is increasingly urgent. According to The Hacker News, a Chrome DevTools technique now allows attackers to extract authenticated session cookies from live browser sessions — meaning an attacker can hijack an active, authenticated session without ever knowing your password. Antivirus won't catch it. MDR likely won't either, because no malicious process ran. ITDR is the layer designed to spot that the session is being used from an unexpected location or context.
Why IAM Alone Isn't Enough
Some IT admins hear "identity security" and think they're covered because they've set up Azure AD, enforced MFA, and configured some conditional access policies. That's a solid foundation — and if you haven't done it yet, our guide to conditional access policies for small business is worth reading first.
But IAM (Identity and Access Management) is about controlling access. ITDR is about detecting when that control has been bypassed or abused. According to The Hacker News, effective identity security requires continuous, evidence-backed verification — not just policies set at provisioning time. IAM tells the system who should have access. ITDR watches for signs that someone who shouldn't is getting in anyway.
And attackers are patient. A long-running data theft campaign targeting Salesforce and ServiceNow — SaaS platforms used by thousands of small and mid-sized businesses — demonstrated that credential-based access to cloud apps can be exploited for years before detection. ITDR tools are specifically built to monitor for anomalous identity behavior inside these SaaS environments, which traditional endpoint tools have no visibility into.
Does a Small Business Actually Need ITDR?
Honest answer: it depends on your threat model and your existing coverage. Here's a framework:
You probably need ITDR (or at minimum, ITDR-adjacent capabilities) if: - You have 20+ users with SaaS access (Microsoft 365, Salesforce, ServiceNow, etc.) - You've already deployed MFA but have no visibility into post-authentication behavior - You're a government contractor with CMMC obligations (identity monitoring maps directly to access control requirements — see our CMMC Level 1 compliance guide) - You've had a credential incident before, or you're in a high-phishing industry (legal, finance, healthcare) - Your MDR vendor has confirmed they have no identity-layer coverage
You can probably defer ITDR if: - You're under 15 users, fully on-prem, with tight physical and network controls - You have strong MFA, conditional access, and regular access reviews already in place - Your budget is constrained and you haven't yet covered endpoint and network basics
The middle path for small businesses: Many ITDR capabilities are now baked into Microsoft Entra ID P2 (included in some Microsoft 365 Business Premium licenses), Defender for Identity, and platforms like Huntress. You may already be paying for partial ITDR coverage without realizing it. Audit what you have before buying a standalone ITDR tool.
What to Look For in an ITDR Solution
If you do decide ITDR is warranted, evaluate tools on these criteria:
- Directory coverage — Does it monitor Active Directory and/or Entra ID for privilege changes, group modifications, and suspicious authentications?
- SaaS visibility — Can it ingest logs from Microsoft 365, Google Workspace, Salesforce, or whatever your team actually uses?
- Behavioral baselines — Does it learn normal behavior per user and flag deviations, rather than just matching known-bad signatures?
- Response actions — Can it automatically disable an account, revoke a session, or alert your team when anomalies are detected?
- Vendor attention — As the Reddit post noted, many enterprise ITDR vendors won't support small organizations. Look for vendors who serve the SMB market explicitly.
Also worth revisiting: our breakdown of credential exposure in third-party integrations covers a related gap that ITDR doesn't fully address — the accidental kind, not just the malicious kind.
The Bottom Line
Antivirus protects your files. MDR protects your endpoints and network. ITDR protects your identities — and identities are now the primary attack surface. You don't need all three on day one, but you do need to understand the gap so you can make an informed decision about when to close it.
Credential theft is happening right now — at coffee shops, inside browsers, and across the SaaS apps your team uses every day. The question isn't whether your organization is a target. It's whether you'll see it coming.
Take Action
Before you can layer identity detection on top of your security stack, you need to know what's already exposed. Attackers scan your external footprint constantly — open ports, misconfigured services, credential-adjacent vulnerabilities that make identity compromise easier.
Oscar Six Security's Radar gives you an affordable, no-fluff vulnerability scan of your external attack surface for $99/scan — so you can see what they see before they act on it.
Proactive scanning catches the gaps that make credential attacks possible. Don't wait for an incident to find out what was visible all along.
Focus Forward. We've Got Your Six.