Your MSP Covers Endpoints. Who's Watching Your Identities?
Credential misuse is the leading cause of breaches in 2025, according to Verizon's Data Breach Investigations Report. Yet most MSPs don't include Identity Threat Detection and Response (ITDR) in their security stack. ITDR fills the gap between identity management and active threat detection, catching attackers who've already bypassed your perimeter using valid credentials.
Attackers aren't breaking through your firewall. They're logging in.
Credential misuse is now the leading cause of security breaches, according to Verizon's 2025 Data Breach Investigations Report. Meanwhile, the 2025 Gartner Machine Identity Management Survey found that more than 50% of organizations experienced at least one incident involving compromised machine identities. These aren't edge cases. They're the baseline.
The problem isn't that businesses lack security tools. Most have endpoint protection, email filtering and some form of firewall. The problem is that none of those tools were built to detect an attacker who looks like a legitimate user. Once someone has a valid session token or stolen credentials, most security stacks go quiet. That silence is the gap.
The Attack Has Already Changed. The Security Stack Hasn't.
Traditional identity and access management (IAM) tools do one job: control who gets in. They verify credentials at login and enforce access policies. Done correctly, that's essential. But it's not enough.
Modern attackers don't steal passwords the way they used to. They steal sessions.
Session hijacking and token theft have become the preferred entry method for sophisticated threat groups precisely because they bypass the controls businesses rely on most, including multi-factor authentication. When an attacker captures a valid session token, your identity provider sees a trusted user. Your EDR sees normal activity. Your firewall logs nothing unusual. The attacker is already inside.
The 2025 Microsoft Digital Defense Report found that identity attacks increased 32% in the first half of 2025, with more than 97% involving password-based techniques like spraying and brute force. Session-based attacks compound the problem further by bypassing authentication entirely.
What's Actually Happening Out There
These aren't theoretical scenarios. They're happening now.
In mid-2025, a global media firm discovered that an employee's browser extension, installed from an unofficial store, had been quietly exfiltrating session tokens stored in local browser storage. Attackers used those tokens to access Microsoft Teams, SharePoint and Outlook, fully impersonating the user without ever entering a password.
Microsoft's own investigation into the CaptiveCrunch campaign, attributed to Midnight Blizzard, revealed that attackers were compromising hotel and conference Wi-Fi networks to intercept Microsoft 365 session tokens from business travelers. The operation used adversary-in-the-middle techniques to capture credentials and active session tokens, then deployed a companion tool called ChocoShell to steal browser cookies and single sign-on tokens silently. No password prompt. No MFA challenge. Just access.
The Snowflake breach in 2024 followed a similar pattern. Threat actor UNC5537 used credentials harvested by infostealer malware, some of which were years old, to access approximately 165 customer environments. Accounts had no MFA. The stolen credentials still worked. Behavioral monitoring would have flagged the anomalies. There wasn't any.
Gartner's projection adds urgency to the timeline: by 2027, AI agents will automate credential theft and compromise authentication channels, reducing the time from exposure to exploitation by 50%.
Why IAM Alone Leaves You Exposed
IAM manages access. It doesn't monitor behavior after access is granted.
That's not a criticism. It's a design reality. IAM was built for a different threat model, one where attackers were on the outside trying to get in. Today's attackers get in with valid credentials and move laterally without triggering a single prevention control.
Gartner recognized this gap formally in 2022, identifying Identity Threat Detection and Response (ITDR) as a distinct security category separate from IAM. The core distinction is simple: IAM controls who gets access; ITDR detects when that access is subverted, abused or stolen.
Most SOCs aren't built to fill this gap on their own. As Gartner notes in its March 2026 research, most SOCs aren't currently equipped to detect identity-specific threats, leaving organizations with significant blind spots.
The MSP Gap Nobody Talks About
Ask your MSP what's included in your security stack. Most will point to endpoint protection, email security, backup and basic monitoring. Some will include a SIEM or SOC service. Few will mention ITDR.
That's not a vendor problem. It's a market maturity problem. ITDR is a newer category, and most managed service providers haven't integrated it into their standard offering yet.
The result is a coverage gap that most mid-market businesses don't know exists. Your endpoints are watched. Your email is filtered. Your identities, once authenticated, are largely on their own.
For organizations running Microsoft 365, Okta or any cloud-based identity provider, that gap represents a real and measurable risk. The 2025 SpyCloud Identity Exposure Report found that 65.7 billion identity records were recaptured in 2025, a 23% year-over-year increase. The credentials circulating on the dark web right now may include accounts tied to your business.
What ITDR Actually Does
ITDR combines behavioral analytics, deception technology and continuous monitoring to detect identity-based threats that prevention controls miss.
Where IAM asks "is this credential valid?", ITDR asks "is this behavior normal?" The distinction matters because attackers with valid credentials can do enormous damage without ever triggering a prevention alert.
Specifically, ITDR monitors for:
- Unusual login locations, impossible travel or access from unfamiliar devices
- Privilege escalation outside of normal change windows
- Lateral movement between systems using legitimate authentication
- OAuth abuse, unauthorized consent grants or anomalous token usage
- Session reuse from multiple locations or at unusual times
According to research, ITDR acts as the critical second and third layers of defense, activating when preventive controls are insufficient. It doesn't replace your IAM or endpoint tools. It fills the detection gap they leave behind.
ITDR is the capability that makes that collaboration possible.
The Detection Gap Is a Business Risk
Here's the number that should concern your leadership team most.
Research from Darktrace's Annual Threat Report found that 68% of organizations detect identity threats within 24 hours, but only 55% contain them effectively. That's a 13-point gap between detection and containment, and it represents hours of unrestricted attacker access inside your environment.
Unit 42's 2026 research found that AI-assisted attack simulations achieved full data exfiltration in as little as 25 minutes. The fastest observed real-world exfiltration ran at 72 minutes. Detection gaps measured in hours aren't just a security problem. They're a business continuity problem.
What to Ask Your MSP Right Now
You don't need to become a security expert to close this gap. You need to ask the right questions.
Start here:
- Do you provide identity threat detection, not just identity management? These are different capabilities. Confirm which one is included.
- What happens after a user authenticates? If the answer stops at login, behavioral monitoring isn't in place.
- How would you detect a compromised session token? Token theft doesn't trigger password alerts. Ask specifically about session-level monitoring.
- Is identity monitoring integrated into your SOC workflows? Detection without response is a report, not a defense.
- How do you align identity detection to MITRE ATT&CK? A framework-driven approach means detection logic is built around how attackers actually operate.
If your current provider can't answer these questions concisely, the gap is real.
The Cost of Waiting Is Already Accumulating
Identity threats are moving faster than prevention-only security models can respond to. The attacks on Snowflake, Midnight Blizzard and the global media firm in 2025 all followed the same pattern: valid credentials, no behavioral monitoring, unrestricted access.
The question for leadership isn't whether ITDR matters. Gartner, Verizon and the breach data have settled that. The question is whether your current security model includes it, and if not, what that exposure is costing you right now.
Entech can help you answer both questions. Start with a strategy session to review your current identity security coverage and identify gaps before they become incidents.
Frequently Asked Questions About ITDR
What is ITDR and how is it different from IAM?
Identity Threat Detection and Response (ITDR) is a security capability that detects and responds to active threats targeting user and machine identities. IAM controls who gets access to systems. ITDR monitors what happens after access is granted, detecting credential misuse, session hijacking, privilege escalation and lateral movement that IAM tools can't see.
Why don't most MSPs include ITDR in their standard offering?
ITDR is a relatively new category. Most managed service providers built their security stacks around endpoint, email and network controls before identity-based attacks became the dominant threat vector. The market is expanding rapidly, but inclusion in standard MSP service offerings has lagged behind attacker adoption of identity-focused techniques. Explore how Entech leverages ITDR to secure your environment.
Can't MFA protect against credential-based attacks?
MFA protects against password-based attacks. It doesn't protect against session hijacking or token theft. Attackers who capture a valid session token can impersonate a user without ever triggering an MFA challenge. The Browser-in-the-Middle (BitM) technique, documented widely in 2025, demonstrated that MFA bypass through session theft can happen in seconds. ITDR detects the behavioral anomalies that follow token theft, even when MFA was in place during the original login.
What types of organizations need ITDR?
Any organization running cloud-based identity providers like Microsoft Entra ID or Okta, operating in a hybrid environment, managing privileged or service accounts, or relying heavily on SaaS applications has a meaningful identity attack surface. Mid-market organizations are particularly vulnerable because they face the same threat landscape as enterprises but typically without dedicated identity security resources or a formal SOC.
How quickly should a business act on implementing ITDR?
The urgency is real. Gartner projects that by 2027, AI agents will automate credential theft, reducing exploitation time by 50%. Organizations that haven't established identity threat detection by then will be operating with a known, widening gap against an accelerating threat. The practical starting point is a gap assessment against current capabilities, followed by integration of identity monitoring into existing detection and response workflows.
How does ITDR support compliance and cyber insurance requirements?
ITDR maps directly to controls required by NIST CSF 2.0, covering the Detect and Respond functions that many organizations currently underserve. Cyber insurance carriers are increasingly asking about behavioral monitoring and identity-specific detection as part of underwriting. Organizations with documented ITDR capabilities are better positioned during renewals and less likely to face coverage exclusions tied to identity-related incidents.