Definition

Identity Threat Detection and Response (ITDR) detects and remediates identity-based attacks after authentication — covering human, machine, non-human-identity, and AI agentic identities across cloud and SaaS.

Key Points

  • Complements IAM/IdP controls that stop at login
  • Signals: overprivileged access, unused permissions, anomalous agent behavior, high blast radius
  • okta acquiring permiso-security (Jul 2026) to unify ITDR with identity fabric
  • Distinct from runtime agent-control-plane (action approve/block) — ITDR is identity/threat detection layer

Sources