← All services
Add-on

Cloud & Identity Protection (ITDR)

Stop account takeovers where modern breaches often start.

What this service offers

This service extends monitoring into SaaS identity providers to catch impossible travel, MFA abuse, rogue admins, and dangerous mailbox rules.

It covers the SaaS and identity layer for hybrid workforces.

  • Impossible-travel and suspicious login pattern detection
  • MFA fatigue / bypass style risk signals
  • Rogue admin and privilege escalation alerts
  • Dangerous inbox forwarding rule flags
  • Unified view alongside on-prem alerts in the portal

Limitations (honest scope)

Clear boundaries help you buy the right module — not oversell.

  • Requires approved integration/permissions to your identity tenant (e.g. Microsoft 365 / similar).
  • Does not replace Conditional Access policy design by your identity admins.
  • Coverage is identity/SaaS — not a full CSPM for every cloud resource type.
  • Response still needs your identity admins for account disables/resets when required.

Who should go for it

  • Organizations on Microsoft 365 / cloud identity with remote users.
  • Teams hit by business-email-compromise risk.

Usually not the best fit if…

  • Estates with no cloud identity provider and no SaaS login surface.