Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Cortex ITDR 2.0: Real-Time Identity Threat Prevention

Palo Alto Networks
10/06/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Identity Threat Detection and Response, otherwise known as ITDR. Attackers no longer break into networks, they log in with valid credentials. As we all know, identity has become the new security perimeter, and organizations need more than just the ability to detect and respond to identity attacks. They also need to proactively reduce risk before attackers can exploit it and enforce access decisions in real time. That's why we're introducing ITDR 2.0. We've expanded identity security with risk-based conditional access policies and posture management for Active Directory. Together, these deliver a complete single-solution approach combining prevention, detection, response, and hygiene. Let's dive in. One of the biggest advantages of Cortex ITDR 2.0 is that it runs natively on the Cortex platform and leverages the XDR agent to deliver new identity security capabilities. Getting started is simple. Just create an Identity Agent profile and enable Active Directory security posture management and conditional access policies. Once configured, Cortex ITDR automatically begins assessing your Active Directory environment and enforcing your security policies. Let's start with configuring a policy. I'll create a new rule using our pre-configured template, MFA for high-risk users. This dynamically triggers multi-factor authentication whenever abnormal behaviors are detected. We can deploy this in simulation mode to test the rule's impact or enforcement mode to actively defend resources. Let's select enforcement. Now we target our user group, establish our triggers, and review. The simple summary makes it easy to double-check our policy before saving. Now let's see this policy in action. Watch what happens when I try to access a sensitive resource. The system analyzes my risk profile in real-time and flags this attempt as high-risk. Notice how Cortex instantly triggers a step-up MFA prompt, gating my access completely until I verify my identity. Next, let's look at detections. Detection has always been the foundation of Cortex ITDR, and it continues to be at the core of the solution. Our ITDR solution delivers a comprehensive set of detections across identity providers, cloud providers, and SaaS apps to identify compromised accounts, privilege abuse, suspicious auth activity, and other identity threats. With this launch, we're expanding those capabilities with support for IDIRA IAM and additional SaaS apps such as Google Workspace, giving customers broader visibility and stronger protection across their identity ecosystem. ITDR 2.0 also introduces security posture management for Active Directory. The solution automatically discovers identities across your on-prem AD accounts and continuously evaluates your environment using more than 150 built-in security checks. That's a lot. These assessments identify misconfigurations, excessive privileges, weak credentials, unsecure settings, and risky identities before they are exploited. With stronger feasibility comes faster response. Cortex ITDR is powered by native automation to orchestrate fast, consistent remediation across your environment. For organizations using IDIRA, the integration becomes even more powerful, with more identity signals, detections, context, and workflows. This enables both platforms to bidirectionally accelerate investigations, automate identity remediation, and reduce the time required to contain and respond to identity threats. It's literally the best of both worlds. With Cortex ITDR 2.0, we're taking identity security to the next level. By combining conditional access policies, advanced threat detection, AD security posture management, and automated response in a single platform, organizations can proactively reduce identity risk, stop attacks before they happen, and respond faster when they do. Thank you for joining me in this overview of Cortex ITDR 2.0. If you'd like to see how these capabilities can help secure your identity infrastructure, reach out to us through the link below to schedule a personalized demo with our team.

TL;DR

  • Cortex ITDR 2.0 adds risk-based conditional access and Active Directory posture management to its existing detection and response capabilities, forming a unified identity security platform.
  • The solution runs natively on the Cortex platform using the XDR agent, enabling dynamic step-up MFA that triggers automatically when abnormal user behavior is detected in real time.
  • More than 150 built-in AD security checks continuously evaluate on-premises environments for misconfigurations, excessive privileges, weak credentials, and risky identities before exploitation occurs.
  • Integration with Idira enables bidirectional sharing of identity signals and workflows, accelerating investigations and reducing time to contain identity-based threats across hybrid environments.

Summary

This product demonstration introduces Cortex ITDR 2.0, Palo Alto Networks' expanded identity threat detection and response solution built natively on the Cortex platform. The video addresses a core attacker behavior shift: rather than breaking through network defenses, adversaries now log in using valid credentials, compromised accounts, or hijacked sessions — making identity the new security perimeter. ITDR 2.0 responds with three new capability pillars: risk-based conditional access policies, Active Directory security posture management with more than 150 built-in security checks, and deeper integration with Idira for bidirectional investigation and automated remediation. The demo walks through policy creation using a pre-configured MFA template for high-risk users, showing how the system can be deployed in simulation or enforcement mode. A live access attempt triggers a real-time risk assessment and step-up MFA prompt, illustrating how enforcement works in practice. Detection coverage spans identity providers, cloud providers, and SaaS applications including Google Workspace, with the solution identifying compromised accounts, privilege abuse, and suspicious authentication activity. The Idira integration enables both platforms to share identity signals and workflows, accelerating containment. Palo Alto Networks positions ITDR 2.0 as a complete single-solution approach combining prevention, detection, response, and hygiene — eliminating the tool-switching that slows security teams in fragmented identity environments.

Chapters

0:00 - Introduction & Overview
0:13 - Why Identity Is the New Perimeter
0:33 - ITDR 2.0 New Capabilities
0:57 - Deployment & Policy Configuration
2:06 - Step-Up MFA in Action
2:27 - Detection & AD Posture Management
3:35 - Idira Integration & Automated Remediation
4:10 - Summary & Demo Request

Key Quotes

0:13 "Attackers no longer break into networks, they log in with valid credentials."
0:33 "That's why we're introducing ITDR 2.0. We've expanded identity security with risk-based conditional access policies and posture management for Active Directory."
0:47 "Together, these deliver a complete single-solution approach combining prevention, detection, response, and hygiene."
3:43 "For organizations using IDIRA, the integration becomes even more powerful, with more identity signals, detections, context, and workflows."

FAQ

How does Cortex ITDR 2.0 differ from the original ITDR offering?

ITDR 2.0 adds two major new capability areas: risk-based conditional access policies that enforce real-time access decisions, and Active Directory security posture management with more than 150 built-in security checks. Together with existing detection and response, these form what Palo Alto Networks calls a complete single-solution approach covering prevention, detection, response, and hygiene.

What environments and identity sources does Cortex ITDR 2.0 support?

The solution covers identity providers, cloud providers, SaaS applications including Google Workspace, on-premises Active Directory, and environments using Idira IAM. It is designed for hybrid environments where identity spans multiple systems and providers.


Categories:
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Security Operations
  • Zero Trust
  • Demo
  • Cloud Security
  • Technical Deep Dive
  • Identity Threat Detection and Response
  • Conditional Access Policies
  • Active Directory Security
  • Step-Up MFA
  • Privilege Abuse Detection
  • Hybrid Identity Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Cortex ITDR 2.0: Real-Time Identity Threat Prevention

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version