Transcript
Identity Threat Detection and Response, otherwise known as ITDR. Attackers no longer break into networks, they log in with valid credentials. As we all know, identity has become the new security perimeter, and organizations need more than just the ability to detect and respond to identity attacks. They also need to proactively reduce risk before attackers can exploit it and enforce access decisions in real time. That's why we're introducing ITDR 2.0. We've expanded identity security with risk-based conditional access policies and posture management for Active Directory. Together, these deliver a complete single-solution approach combining prevention, detection, response, and hygiene. Let's dive in. One of the biggest advantages of Cortex ITDR 2.0 is that it runs natively on the Cortex platform and leverages the XDR agent to deliver new identity security capabilities. Getting started is simple. Just create an Identity Agent profile and enable Active Directory security posture management and conditional access policies. Once configured, Cortex ITDR automatically begins assessing your Active Directory environment and enforcing your security policies. Let's start with configuring a policy. I'll create a new rule using our pre-configured template, MFA for high-risk users. This dynamically triggers multi-factor authentication whenever abnormal behaviors are detected. We can deploy this in simulation mode to test the rule's impact or enforcement mode to actively defend resources. Let's select enforcement. Now we target our user group, establish our triggers, and review. The simple summary makes it easy to double-check our policy before saving. Now let's see this policy in action. Watch what happens when I try to access a sensitive resource. The system analyzes my risk profile in real-time and flags this attempt as high-risk. Notice how Cortex instantly triggers a step-up MFA prompt, gating my access completely until I verify my identity. Next, let's look at detections. Detection has always been the foundation of Cortex ITDR, and it continues to be at the core of the solution. Our ITDR solution delivers a comprehensive set of detections across identity providers, cloud providers, and SaaS apps to identify compromised accounts, privilege abuse, suspicious auth activity, and other identity threats. With this launch, we're expanding those capabilities with support for IDIRA IAM and additional SaaS apps such as Google Workspace, giving customers broader visibility and stronger protection across their identity ecosystem. ITDR 2.0 also introduces security posture management for Active Directory. The solution automatically discovers identities across your on-prem AD accounts and continuously evaluates your environment using more than 150 built-in security checks. That's a lot. These assessments identify misconfigurations, excessive privileges, weak credentials, unsecure settings, and risky identities before they are exploited. With stronger feasibility comes faster response. Cortex ITDR is powered by native automation to orchestrate fast, consistent remediation across your environment. For organizations using IDIRA, the integration becomes even more powerful, with more identity signals, detections, context, and workflows. This enables both platforms to bidirectionally accelerate investigations, automate identity remediation, and reduce the time required to contain and respond to identity threats. It's literally the best of both worlds. With Cortex ITDR 2.0, we're taking identity security to the next level. By combining conditional access policies, advanced threat detection, AD security posture management, and automated response in a single platform, organizations can proactively reduce identity risk, stop attacks before they happen, and respond faster when they do. Thank you for joining me in this overview of Cortex ITDR 2.0. If you'd like to see how these capabilities can help secure your identity infrastructure, reach out to us through the link below to schedule a personalized demo with our team.