Your employee successfully authenticates.MFA works. The account is valid. The permissions are legitimate.There's just one problem:
The person using the identity may be an attacker.
That scenario gets to the heart of one of the biggest changes happening in enterprise security. For years, organizations have invested heavily in Identity and Access Management (IAM) to answer an essential question:
Who should have access to what?
What is that identity doing right now?
The identity problem has changed
IAM isn’t becoming less important. Quite the opposite.
Gartner says human and machine identities have emerged as the primary attack surface, while increasing complexity and isolated IAM tools create visibility gaps.
But preventing unauthorized access is only one part of the problem.
Gartner’s March 2026 Implement ITDR Practice to Combat Identity-Based Attacks puts the distinction clearly: traditional IAM solutions are essential, but they are primarily preventative controls and are not designed to address attacks that leverage existing human or machine identities.
In other words:
IAM determines whether an identity should be trusted. ITDR determines whether that trusted identity is behaving like an attacker.
That’s a critical distinction when legitimate credentials themselves have become an attack path.
According to the Gartner ITDR report, credential misuse was the leading cause of security breaches cited from the 2025 Verizon DBIR. Gartner’s own machine identity research also found that more than 50% of surveyed organizations had experienced one or more cybersecurity incidents involving compromised machine identities.
And the window defenders have to react could get smaller.
Gartner predicts that by 2027, AI agents will automate credential theft and compromise authentication communication channels, reducing exploitation time for exposed accounts by 50%.
That’s why identity security increasingly needs to operate in the now.
Prevention before the attack. Detection while it's happening.
This is not an IAM-versus-ITDR argument.
Organizations need both.
IAM establishes identity hygiene, access policies, authentication and privileges. ITDR provides another layer when those preventive controls are bypassed or abused.
Gartner describes ITDR as the second and third layers of identity defense: detection and response after prevention. Its research distinguishes preattack identity hygiene from monitoring and stopping active attacks using real-time threat intelligence.
That changes the questions the SOC can ask.
- Is this user logging in from somewhere unexpected?
- Has this service account suddenly changed behavior?
- Is a privileged identity accessing systems it normally doesn't?
- Is this identity moving laterally?
- Does apparently legitimate identity activity correlate with suspicious endpoint, network or cloud behavior?
- Set up a cron job to watch a Google Form for new submissions, auto-create tickets, and ping me when something comes in. No code. It took about ten minutes.
The outcome is reducing the time between identity compromise, understanding what's happening and taking action.
Identity can't become another security silo
There’s another important consideration for IT and security leaders.
An identity attack rarely stays inside the identity system.
An attacker may compromise an account, authenticate successfully, access a cloud application, move across the network and ultimately interact with an endpoint or sensitive data.
That means identity context needs to reach the SOC.
Gartner specifically recommends integrating IAM-originated incidents into SOC response and threat-hunting processes.
And there’s a measurable reason to bring those teams together. Gartner’s 2024 IAM Leadership Survey found that collaboration between IAM and cybersecurity functions across controls, risk assessment and threat management led to a 30% improvement in achieving IAM goals.
This is where Stellar Cyber takes a different approach to ITDR.
Rather than creating another identity security console for analysts to monitor, ITDR is built into the Stellar Cyber SecOps Platform. Identity telemetry from technologies such as Active Directory, Microsoft Entra ID and Okta can be correlated with endpoint, network, cloud and other security signals.
The objective is straightforward:
See the identity as part of the attack, not as an isolated event.
From identity anomaly to action
Stellar Cyber 6.6 pushes that approach further.
The release improves login-anomaly fidelity for detections including Impossible Travel and User Login Location anomalies, adding customizable suppression, better username prioritization and ASN enrichment for Impossible Travel detections.
And this isn’t simply historical analysis.
For on-time data, Stellar Cyber documents an expected detection delay of 5–10 minutes after ingestion for Impossible Travel anomalies, although ingestion delays can extend that window.
Once suspicious identity behavior is identified, response matters just as much. With Microsoft Entra ID, for example, Stellar Cyber can enrich events with identity information and support actions including disabling a user, confirming compromise and revoking sign-in sessions.
That creates the operational progression ITDR should deliver:
Detect suspicious identity behavior.
Understand it in the context of the broader attack.
Prioritize the risk.
Respond before the attacker can do more damage.
Trust is no longer a one-time decision
IAM remains essential.
Strong authentication remains essential. MFA remains essential. Privilege management and identity hygiene remain essential.
But successful authentication cannot be the end of the security decision.
Gartner predicts that by 2028, 70% of CISOs will use identity visibility and intelligence capabilities to shrink the IAM attack surface and reduce credential-compromise risk.
The shift is from asking only:
“Should this identity have access?”
to continuously asking:
“What is this identity doing now—and should we trust it?”
Because attackers don’t care that your IAM controls worked.
They care whether they can become someone your organization already trusts.
IAM protects the identity. ITDR protects the moment.
References
- Gartner, 2026 Predicts: Identity and Access Management, Paul Mezzera, Rebecca Archambault, James Hoover and Shubham Gera, 22 January 2026, ID G00841403.
- Gartner, Implement ITDR Practice to Combat Identity-Based Attacks, James Hoover, Peter Firstbrook and Rebecca Archambault, 5 March 2026, ID G00845676.


