Identity Meets the SOC: Redefining the Last Perimeter

Aug 06, 2026
8 minutes

Why we are at an inflection point with identity

Let’s start with a hard truth that every security leader is waking up to: adversaries aren’t breaking into enterprise networks anymore. They are simply logging in.

For years, the cybersecurity industry operated under a relatively straightforward assumption: if we built higher walls at the perimeter, deployed robust Identity and Access Management (IAM), and rolled out Multi-Factor Authentication (MFA), our environments would be safe. We treated the "front door" of identity as a binary gatekeeper.

But today, with adversarial Frontier AI at the doorsteps, we must assume that the gate has been breached. Identity has officially become the primary attack surface.

Once a threat actor bypasses those initial gatekeepers, whether through sophisticated session hijacking, social engineering, or compromised service accounts, they don't trigger traditional alarms. They don't need to deploy noisy malware. Instead, they blend completely invisibly into your regular, daily corporate traffic.

An explosion of non-human identities, like service accounts, API tokens, and autonomous AI agents, now drives over 90% of incident response cases1.

The crisis is speed: attackers exfiltrate data in 72 minutes, while it takes security teams 12 hours to manually investigate. Fighting machine-speed threats with manual workflows is futile, identity context must live directly inside the SOC.

What an Ideal ITDR Solution Must Solve

Identity Threat Detection and Response (ITDR) is a security discipline focused on monitoring, protecting, and defending identity infrastructure from credential misuse, privilege escalation, and unauthorized access across both human and machine identities.

To outpace modern automated identity attacks, an ideal ITDR solution must fulfill core capabilities within a single continuous workflow. It starts by ingesting and cross-referencing multi-domain telemetry across endpoints, network, cloud infrastructure, SaaS applications, and identity systems. The platform then applies contextual stitching to correlate cross-vector signals, transitioning security operations from standard password verification to actively verifying human and machine intent. Grounded in continuous behavioral baselines, it calculates dynamic, real-time risk scores that immediately trigger adaptive access policies, such as step-up MFA when abnormal behavior is detected. Finally, it must execute an automated, closed-loop playbook to deliver surgical containment, instantly neutralizing active threats before exfiltration can occur.

Introducing Cortex ITDR 2.0

Today, we are proud to unveil Cortex ITDR 2.0, which brings identity intelligence directly into the security operations platform, stitching together endpoints, networks, cloud, SaaS, and Identity.

  • Conditional Access Policy (CAP): Trigger dynamic step-up MFA in Okta and Entra ID based on behavioral drift, and test policies safely in Simulation Mode.
  • Active Directory Security Posture Management (AD-SPM): Continuously audit Active Directory via existing XDR agents to uncover misconfigurations, excessive privileges, and hidden attack paths.
  • Unified Single-Pane Visibility: The Unified User Card consolidates Active Directory, endpoint, and cloud context into a single view with behavioral heat maps and risk trendlines.
  • Idira + Cortex Integration: Fuse privileged access intelligence with cross-domain telemetry to execute surgical, automated containment without business downtime.
  • Secure and Govern Access with Granular RBAC: New standardized structure featuring dedicated roles (Viewer, Administrator), allowing for precise permissions for identity security and Conditional Access Policies.

Let’s take a closer look at these capabilities and how they redefine identity security.

Conditional Access Policy (CAP)

Detection without rapid response is just documenting a breach in real time. Dynamic Conditional Access Policies (CAP) turn passive notifications into active, automated containment.

  • Zero-Friction Deployment: Build new rules instantly using guided templates. The platform translates your security requirements into a plain-English rule summary, so your team can verify, save, and push policies live without any guesswork.
  • Simulation vs. Enforcement: Safely run "dry runs" of new policies in Simulation Mode to monitor real-world impact before flipping the switch to active, real-time Enforcement.
  • Dynamic Step-Up MFA: Automatically trigger a multi-factor authentication challenge in Okta & EntraID the microsecond a user's behavior drifts from their baseline.
Image 1: Conditional Access Policy (CAP) template

Proactive Identity Hardening (AD-SPM)

You cannot secure what you haven't hardened. Active Directory Security Posture Management (AD-SPM) shifts your defense from reactive to proactive. Using your existing XDR agents, Cortex continuously audits Active Directory for structural weaknesses, flagging:

  • Misconfigured accounts and excessive privileges
  • Weak, exposed, or compromised passwords
  • Stale accounts and hidden attack paths that lead straight to your crown jewels

The Unified User Card: All Identity Context in One Place

Pivoting between Active Directory, endpoint consoles, and identity logs during an investigation slows down triage, giving attackers time to move laterally.

The Unified User Card in Cortex ITDR 2.0 consolidates this disjointed data into a single interface. Analysts can immediately track the entire behavioral lifecycle of a user without switching consoles:

  • Geographical Anomalies: Cortex automatically baselines typical login locations. If a user’s login activity suddenly deviates from their normal footprint, it is instantly flagged on the card.
  • Behavioral Heat Maps: Instantly spot spikes in suspicious activity over the course of the week. This interactive visual maps out alert density, allowing analysts to immediately identify when a compromise began.
  • Continuous Risk Trendlines: See at a glance whether a user's risk score is trending upward, pointing to a slow-burn compromise before it turns into a full-scale crisis.
  • Suspicious Behavior Timelines: Every high-risk action, privilege change, or security alert is laid out chronologically on the card, giving analysts the full, contextualized story in seconds.
Image 2: User activity timeline
Image 3: Issues and insights Heat map
Image 4: User Risk Score Trend

Idira Integration with Cortex

Cortex ITDR 2.0 integrates natively with Idira's Identity Security Platform, introducing 17 new, out-of-the-box detectors built specifically to monitor your Idira identity provider environment. By combining Idira's privileged access intelligence with Cortex's behavioral analytics, we’ve built an active, automated security loop inside the SOC. 

  • Full-Lifecycle Identity Telemetry: Cortex ingests deep identity context across the entire user and privileged session lifecycle, capturing anomalies pre-authentication (risky behavior before login) and at-authentication (the login event itself).
  • Cross-Domain Correlation: By stitching Idira’s identity and vault signals together with native endpoint, network, and cloud telemetry, Cortex surfaces complex, multi-stage attacks that any single domain would completely miss on its own.
  • Instant Containment: When an identity threat is validated, the SOC can trigger immediate, automated containment actions directly through Idira, instantly locking the account, rotating compromised secrets, revoking active sessions, credential theft, and signing the user out across the entire ecosystem.
Image 5: Block execution of Risky Applications
  • Intelligent Guardrails: Because these automated playbooks are backed by continuous risk scoring, response actions are surgically targeted. The platform neutralizes active adversary activity instantly without disrupting the daily, legitimate work of your business, and rolls restrictions back once the threat has been alleviated.
Image 6: Idira’s Endpoint Privilege Manager (EPM) Response Playbook

Secure and Govern Identity Access with Granular RBAC

In this release of ITDR we are introducing a new standardized structure featuring dedicated roles (Viewer, Administrator), allowing for precise permissions for identity security and Conditional Access Policies. This will help you with governance by enforcing strict least-privilege access over sensitive Conditional Access Policies, allowing SOC analysts to safely investigate identity context without risking unauthorized system changes.

Identity Security Tools and SecOps Platforms Can No Longer Exist in Silos

For years, enterprises have treated Identity and Access Management (IAM) and the Security Operations Center (SOC) as two entirely separate worlds. That division is a fundamental architectural flaw and threat actors are exploiting it every single day.

Authentication is no longer the finish line of a security strategy; it is merely the starting line for behavioral monitoring. Continuing to treat identity as a separate silo, managed by an isolated team using disconnected tools, is an operational failure.

Cortex ITDR 2.0 is a necessary architectural correction. By forcing identity telemetry directly into the SOC platform, it marks the shift from passive identity management to true IDSecOps (Identity Security Operations), eliminating the blind spots human analysts can no longer bridge on their own. In today’s threat landscape, visibility without immediate containment is useless, and containment without identity context is blind. It’s time to bridge the gap and build a unified defense

See how easy it is to secure your identity infrastructure and automate responses from a single console. Request a live Cortex demo today

Read the IDSecOps Blog

Read the IDSecOps eBook

Visit the ITDR webpage


Sources

[1] https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report
[2] https://www.paloaltonetworks.com/idira/identity-security-landscape-report


Subscribe to Security Operations Blogs!

Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more.