Intent
Product intent memo
Why We Built ITDR and where it fits
Strategic reference for product, engineering, and SOC stakeholders. This page combines validated platform capability evidence with externally researched ITDR market context.
Evidence timestamp
April 22, 2026
Claims here are split between: 1) current platform capability, and 2) competitor/category references verified from official vendor documentation.
Executive answer
Are we building the right thing?
Yes for our chosen scope: Microsoft tenant identity operations with practical detection, incident response, and governance continuity. This is not intended to replace every SIEM/XDR function.
Product-validated scope
What ITDR already delivers
Ingestion + Evidence
Detection + Incidenting
Response + Governance
Production + Reporting
Platform proof anchors
Product strategy and operating model
Clear operating intent and decision discipline keep the platform focused on practical identity operations outcomes.
Detection and incident workflow
Detection output is consistently correlated into alerts and incidents with explainable evidence and timelines.
Connector ingestion and feed reliability
Microsoft and Office 365 feeds are ingestion-aware and surface readiness states when optional data lanes degrade.
Operator frontend surface
Operators can move across incidents, identities, connectors, logs, reports, and posture workflows in one experience.
External research anchors
Market facts used in this narrative
Official documentation and vendor sources reviewed to avoid stale competitive assumptions.
| Reference | Fact used | Source | Currency |
|---|---|---|---|
| Microsoft Entra ID Protection | Risk-based access control uses sign-in risk and user risk signals, with policy actions like MFA, password change, or block. | Microsoft Learn | Updated March 20, 2026 |
| Microsoft Defender for Identity | Positions as identity threat detection/investigation/response across on-prem, cloud, and hybrid, with unified incident context. | Microsoft Learn | Updated February 25, 2026 |
| Microsoft Sentinel | Cloud-native SIEM with broad connector coverage and data-lake-first security operations model. | Microsoft Learn | Updated September 30, 2025 |
| Okta Identity Threat Protection | Emphasizes continuous risk evaluation and automated responses including MFA challenge and session termination. | Okta Product Page | Reviewed April 22, 2026 |
| CrowdStrike Falcon Identity Threat Protection | Positions real-time identity breach detection/response with cross-domain correlation and risk-based access controls. | CrowdStrike Data Sheet | Reviewed April 22, 2026 |
| Silverfort ITDR | Positions hybrid identity detection with inline response controls and SIEM/XDR enrichment. | Silverfort Platform Page | Reviewed April 22, 2026 |
Competitive reality
How we compare in the current ITDR landscape
Category-level comparison focused on operations and production behavior, not marketing checklists.
| Competitor archetype | Typical strength | Current ITDR edge | Current ITDR gap |
|---|---|---|---|
| Native Microsoft security stack | Deep prevention and policy controls with broad Microsoft-native incident correlation. | Purpose-built tenant workflow linking connector health, normalized evidence, incidents, containment, and posture debt in one operator console. | Less native control-enforcement depth than full Entra/Defender/Sentinel adoption; still feed- and license-dependent. |
| SIEM-first identity programs | Very broad telemetry ingestion, custom analytics flexibility, and mature large-SOC workflows. | Lower operational overhead for identity-centric investigations with built-in entity model and response controls. | Narrower integration footprint and less cross-domain breadth than a full SIEM/XDR data platform. |
| Point ITDR vendors | Focused detection depth, often with strong identity-risk analytics and adaptive policy hooks. | Combines detection with posture governance, remediation ownership, and practical incident/report artifacts. | Still closing selected depth areas like advanced chain analytics, full isolation orchestration, and broader notification channels. |
Where we are stronger
Where we are weaker
Alignment review
Keep / extend / refactor / deprioritize
The current product thesis is correct for our target operator.
Extend depth where current feeds and operator behavior already validate demand.
Refactor for operational scale before adding new broad feature classes.
Avoid prototype traps that dilute production value.
Prototype risk check
Why this is not just a wrapper prototype
The platform already includes tenant-scoped evidence models, ingestion workflows, detection correlation, incident response flows, and exportable artifacts. The largest remaining risk is not product absence; it is execution discipline around scaling and operational hardening.