Info
Silverfort is the pick when identity spans on-premises Active Directory and cloud at once, Push Security when the attacks you keep missing happen inside the browser, and Semperis when Active Directory recovery is the requirement. All seven were compared on coverage, published pricing, official MCP support, and API access.
Silverfort is the best overall ITDR software for most enterprises in 2026 because it sits inline with existing identity infrastructure instead of asking you to consolidate first. If your identity estate is mostly cloud and SaaS, Push Security is the better buy, and it is one of only two products here that publishes a price, at a per-user rate that also makes it the best ITDR software for small business teams under 500 employees.
ITDR exists because authentication succeeding is not the same as authentication being legitimate. An attacker with a valid session token looks identical to an employee to every identity provider on the market. Endpoint tools miss it too, because nothing malicious runs on the device.
The category has split along one axis, and it should drive your shortlist: where your identity risk actually sits. Active Directory specialists, unified inline platforms, and browser or SaaS-layer tools all call themselves ITDR. They detect different attacks, and buying the wrong one fails quietly rather than loudly.
One more shift this year: identity vendors are now likelier to sell you controls over AI agents than to expose their own data through MCP. Two of the seven do both.
Why You Need Identity Threat Detection and Response
- Valid credentials defeat perimeter controls. Microsoft documents Defender for Identity detections across reconnaissance, credential compromise, lateral movement, and full domain dominance, none of which involve malware.
- Session theft bypasses MFA entirely. Adversary-in-the-middle phishing captures the session after the second factor, so the login record looks clean.
- Service accounts rarely get watched. Semperis added dedicated service account protection precisely because dormant and misplaced non-human identities are high-value and low-visibility.
- SaaS sprawl moves identity outside the directory. Accounts created directly in a SaaS app never reach the identity provider your logging depends on.
- AI agents authenticate with borrowed privilege. Agents act autonomously using delegated identities, which makes accountability hard to reconstruct later.
Related controls sit in our cybersecurity software category, and account-proofing tools in our identity verification software category.
How We Evaluated
Each platform was scored on where its coverage actually lands (on-premises directory, cloud identity provider, SaaS and browser), whether any pricing is published, the maturity of AI and MCP support with first-party servers separated from community builds, and the state of the public API. Every price below came from the vendor's own pricing page in August 2026, never from a review aggregator. Full criteria live in our methodology.
1. Silverfort
Silverfort's design choice is the whole argument for it. Instead of sitting in the network path or on the endpoint, it hooks into the identity infrastructure and evaluates each authentication request inline, returning a verdict before access is granted. Network re-architecture and agent rollouts drop out of the plan.
Pricing: Not published. Silverfort directs buyers to a demo request.
Top Features
- Runtime Access Protection inline with the IAM stack
- Coverage for legacy apps and command-line access
- Service account and machine identity protection
- Behavioral analytics for lateral movement detection
- AI agent identity controls with an MCP gateway
- First-party hosted MCP server for policy and risk
Pros
- Works across on-premises, hybrid, OT, and multi-cloud together
- Protects resources that cannot take an agent
- Extends MFA to systems that never supported it
Cons
- No published pricing at any tier
- Inline placement means a deeper integration review before rollout
AI/MCP Integration: Official. Silverfort launched a first-party hosted MCP server on July 31, 2025 at raven.silverfort.io/mcp, exposing policy management and risk assessment tools. It also sells an MCP gateway that inspects agent tool calls inline before they reach the target resource.
API Integration: Yes. API credentials are scoped by permission, with separate Policy Management and Risk Assessment grants required for MCP access.
Cloud Based: Yes, with coverage extending to on-premises and OT environments.
Platforms: Integrates with Active Directory, Entra ID, Okta, and RADIUS rather than shipping endpoint agents.
Best For: Enterprises with a hybrid identity estate they cannot consolidate in the near term.
Editor score: 4.6/5. The broadest coverage here and the only vendor doing both halves of the MCP story.
2. Push Security
Push works from the browser, which sounds like a limitation until you notice that is where identity attacks now happen. Phishing pages, stolen session tokens, ghost logins that bypass SSO, and malicious OAuth grants are all visible there and largely invisible in identity provider logs. It also publishes a price, which in this category is nearly a differentiator on its own.
Pricing: Standard is $5 per user per month billed annually, or $6 billed monthly, for organizations up to 500 employees. Enterprise is custom quoted with volume discounts above 500. A free trial requires no upfront payment.
Top Features
- Browser extension across Chrome, Edge, Firefox, Safari, and others
- Adversary-in-the-middle phishing detection
- Session hijacking detection from stolen tokens
- Ghost login discovery for SSO bypass paths
- Malicious OAuth integration and consent monitoring
- Shadow SaaS and AI app discovery
Pros
- Published per-user price on the website
- No enterprise browser migration required
- REST API access included on every plan
Cons
- Standard tier caps at 500 employees
- Coverage depends on the extension being deployed everywhere
AI/MCP Integration: None documented as of August 2026. Push covers AI app visibility and policy enforcement inside the browser but publishes no MCP server of its own.
API Integration: Yes. REST API access is listed on both plans, alongside SIEM integrations for Sentinel, Splunk, Datadog, Panther, and Cribl.
Cloud Based: Yes, SaaS.
Platforms: Browser extension for Chrome, Edge, Firefox, Brave, Arc, Safari, Opera, Island, Prisma, Dia, Comet, and Atlas.
Best For: Cloud-first organizations losing accounts to phishing and session theft rather than to Active Directory attacks.
Editor score: 4.5/5. Best pricing transparency in the group and the only tool here that sees the browser layer.
3. Semperis Directory Services Protector
Semperis is the Active Directory specialist, and it earns that with one design decision: DSP reads the AD replication stream rather than security event logs. An attacker who disables logging still gets caught. Add attribute-level rollback and you have the strongest recovery story of the seven.
Pricing: Not published. Semperis quotes through sales.
Top Features
- Replication stream monitoring that survives disabled logs
- Hundreds of built-in indicators of exposure and compromise
- Real-time rollback of malicious AD and Entra ID changes
- Attribute-level restoration granularity
- Service account and non-human identity discovery
- Identity Runtime Protection for password spray and stuffing
Pros
- Detects changes even when audit logging is tampered with
- Rollback works at attribute granularity, not just whole objects
- Covers on-premises AD and Entra ID in one view
Cons
- No published pricing
- No first-party MCP server or open API reference
AI/MCP Integration: None documented as of August 2026. Semperis ships machine learning models inside Identity Runtime Protection for detection, but publishes no MCP server.
API Integration: Not documented publicly. Semperis documents SIEM streaming with dedicated integrations for Microsoft Sentinel and Splunk instead of an open developer API reference.
Cloud Based: Hybrid, covering on-premises Active Directory alongside Entra ID.
Platforms: Windows Server and Active Directory infrastructure, with Entra ID coverage through the cloud service.
Best For: Large enterprises where an Active Directory compromise is the scenario that keeps the CISO awake.
Editor score: 4.4/5. Unmatched at what it does; the thinnest integration surface of the seven.
4. Microsoft Defender for Identity
Defender for Identity is the default answer for anyone already holding an E5 license, and it is a genuinely capable one. Lightweight sensors sit on identity infrastructure, parse traffic and Windows events locally, and send only the required signals to the cloud service. Alerts land as correlated incidents in the Microsoft Defender portal rather than in a separate console.
Pricing: No standalone price is published. Defender for Identity is included in Microsoft 365 E5 at $60 per user per month paid yearly, in Microsoft 365 A5, and in the Microsoft Defender Suite at $12 per user per month paid yearly.
Top Features
- Lightweight sensors on domain controllers and identity servers
- API connectors for external IAM systems including Okta
- Detections mapped to reconnaissance through domain dominance
- Lateral movement path analysis
- Identity posture assessments surfaced in Microsoft Secure Score
- Correlated incidents in the Microsoft Defender portal
Pros
- Already licensed for most Microsoft 365 E5 customers
- Detections cover Golden Ticket, DCShadow, and replication abuse
- Identity alerts correlate with endpoint and email signals automatically
Cons
- No standalone price, so real cost depends on your licensing position
- Value drops steeply outside the Microsoft security stack
AI/MCP Integration: Official at the platform level, not the product level. Microsoft's Sentinel MCP server reached general availability on November 18, 2025 and exposes the Sentinel data lake including Defender XDR data. No Defender for Identity specific MCP server is documented as of August 2026.
API Integration: Yes. Defender for Identity signals and alerts are reachable through the Microsoft Defender XDR APIs.
Cloud Based: Yes, as a cloud analytics service fed by on-premises sensors.
Platforms: Sensors run on Windows identity infrastructure; management is through the Microsoft Defender portal.
Best For: Microsoft-first organizations that already pay for E5 and want identity detection without another contract.
Editor score: 4.3/5. Strong detections and effectively free at E5, weak as a standalone purchase.
5. Huntress Managed ITDR
Huntress assumes most companies buying ITDR have nobody to run it. Managed ITDR bundles the product with a 24/7 SOC that investigates and remediates, which changes what you are buying.
Pricing: Not published. Huntress describes a per-identity annual subscription covering Microsoft 365 and Google Workspace identities, on a 12-month term, and requires a form submission for a quote.
Top Features
- 24/7 SOC monitoring, detection, and remediation included
- Microsoft 365, Google Workspace, and hybrid AD coverage
- Account takeover and rogue app detection
- Shadow workflow and rogue inbox rule monitoring
- One year of SIEM data retention at no extra cost
- PSA integrations for Autotask, HaloPSA, Kaseya BMS, and ConnectWise
Pros
- Human analysts included rather than sold as an add-on
- No premium Microsoft licensing required
- Official read-only MCP server available
Cons
- No published pricing despite a dedicated pricing page
- 12-month commitment with no shorter term offered
AI/MCP Integration: Official. Huntress publishes a first-party MCP server with read-only access covering agents, organizations, incident reports, signals, escalations, remediations, invoices, reports, and external recon data. It authenticates through OAuth or API key and cannot make changes to the account.
API Integration: Yes. Huntress runs a public API with key and secret credentials issued from the account, and its MCP server is built directly on that API.
Cloud Based: Yes, SaaS.
Platforms: Microsoft 365 and Google Workspace tenants, plus hybrid Active Directory scenarios.
Best For: Small and mid-sized companies and MSPs that need the detection and the analysts in one line item.
Editor score: 4.2/5. The managed model is the differentiator; the missing price list is an odd choice for this buyer.
Teams pairing this with device-level coverage should review our endpoint security software category.
6. Obsidian Security
Obsidian covers the part of the identity estate living outside your directory: third-party SaaS applications and the AI agents connected to them. It connects to Salesforce, Snowflake, Microsoft 365, ServiceNow, GitHub, and Workday, then watches for account takeover, excessive privilege, and access violations.
Pricing: Not published. Obsidian directs buyers to a demo or free trial request.
Top Features
- SaaS posture management across major business applications
- Account takeover detection inside third-party apps
- Excessive privilege and access violation detection
- Third-party integration supply chain visibility
- AI agent visibility, governance, and runtime security
- Shadow AI discovery with MCP and prompt security
Pros
- Covers SaaS identity risk that directory tools cannot see
- AI agent and MCP inventory is unusually developed for this category
- Audit and compliance automation included in the platform
Cons
- No published pricing
- Value is limited if your identity risk is mostly on-premises
AI/MCP Integration: Security for MCP rather than an MCP server. Obsidian inventories and classifies MCP servers across platforms, scores them by effective authority, and its research team has disclosed one-click account takeover flaws in remote MCP servers run by other organizations. It does not publish an MCP server of its own as of August 2026.
API Integration: Yes. Obsidian issues role-scoped API access tokens from platform settings, and audit, alert, and event logs are consumable by external SIEM tooling.
Cloud Based: Yes, connecting to SaaS platforms through their own APIs.
Platforms: SaaS applications and AI platforms including Bedrock, Azure, Claude, OpenAI, and Vertex AI.
Best For: SaaS-heavy organizations that also need to govern AI agent access before it gets away from them.
Editor score: 4.1/5. The most forward-looking coverage here, priced entirely behind a sales call.
Data-layer controls that pair with this sit in our data security software category.
7. Proofpoint Identity Threat Defense
Proofpoint built this from its Illusive acquisition, and the deception heritage still defines it. Spotlight inspects Active Directory, Entra ID, and PAM systems for identity vulnerabilities; Shadow distributes more than 75 deception techniques to catch lateral movement. Proofpoint states the platform has defended 160 red team attacks with zero defeats.
Pricing: Not published. Proofpoint quotes Identity Threat Defense through sales.
Top Features
- More than 75 deception techniques deployed across the estate
- Agentless deception distribution with no endpoint installs
- Shadow administrator and misconfiguration discovery
- Privileged access management gap detection
- Endpoint-based credential exposure identification
- Integration with Proofpoint TAP and TAP ATO
Pros
- Deception catches lateral movement that log analysis misses
- Agentless deployment lowers rollout friction
- Ties identity risk to Proofpoint's email threat data
Cons
- No published pricing
- Identity products lack a dedicated public API reference
AI/MCP Integration: Official at the platform level. Proofpoint Satori MCP Access connects Satori agents to other systems over MCP, and Proofpoint sells MCP security controls including a Secure Agent Gateway. No Identity Threat Defense specific MCP server exists; a community server covering Proofpoint TAP and Essentials is on GitHub with no vendor support.
API Integration: Partial. Identity Threat Defense integrates with Proofpoint TAP, TAP ATO, and NPRE, but no public API reference for the identity products is published on the product pages as of August 2026.
Cloud Based: Yes, with deception artifacts distributed across on-premises and cloud assets.
Platforms: Active Directory, Entra ID, and PAM systems, with endpoint credential inspection.
Best For: Organizations already running Proofpoint email security that want identity risk on the same platform.
Editor score: 3.9/5. Real depth in deception, the least transparent of the seven on price and APIs.
Comparison Table
| Tool | Best For | Starting Price | Standout Feature | AI-MCP Support | API Integration |
|---|---|---|---|---|---|
| Silverfort | Hybrid identity estates | Quote only | Inline runtime access protection | Official server and gateway | Yes, permission-scoped |
| Push Security | Cloud-first companies | $5 per user monthly | Browser-layer session detection | None documented | Yes, all plans |
| Semperis DSP | Active Directory recovery | Quote only | Attribute-level rollback | None documented | SIEM streaming only |
| Defender for Identity | Microsoft 365 E5 holders | $12 per user monthly | Domain dominance detections | Platform server, GA | Yes, via Defender XDR |
| Huntress Managed ITDR | Small teams and MSPs | Quote only | 24/7 SOC included | Official, read-only | Yes, public API |
| Obsidian Security | SaaS and AI agent risk | Quote only | AI agent governance | MCP security, no server | Yes, token-scoped |
| Proofpoint ITD | Existing Proofpoint sites | Quote only | 75-plus deception techniques | Platform server only | Partial |
More identity tooling breakdowns live in our IT security and DevOps blog category.
How to Choose
- Map where your identity risk actually lives before shortlisting. On-premises AD, cloud identity provider, and SaaS are three different problems with three different winners.
- Ask whether the tool can see a stolen session. Most cannot, because a hijacked session is a valid authenticated request everywhere except the browser.
- Check service account coverage explicitly. Non-human identities carry standing privilege and almost never get reviewed.
- Decide whether you are buying software or an outcome. Huntress includes analysts; the rest assume you have a SOC.
- Confirm the rollback story, not just the alert. Detecting a malicious group membership change is worth far less than reversing it.
- Separate official MCP servers from community builds, and separate both from MCP security products, which solve a different problem.
- Price against your existing licensing. If you hold E5 already, Defender for Identity changes the math for everything else here.
What This Actually Costs
Take a 750-identity organization with a small security team. Push Security's Standard tier caps at 500 employees, so this buyer lands in Enterprise pricing, though the published $5 per user per month is a defensible anchor of roughly $45,000 a year to negotiate against. Microsoft Defender Suite at $12 per user per month runs near $108,000 a year at the same headcount, and buys far more than identity detection.
The remaining five will not quote without a call, including Huntress, which runs a dedicated ITDR pricing page and still gates the numbers behind a form. Budget three to six weeks of procurement, and go in with the two published figures as reference points.
Final Thoughts
The instinct here is to buy the biggest platform and assume coverage follows. It does not. Every product on this list is strong inside its own boundary and blind outside it, and those boundaries overlap less than the marketing suggests.
Silverfort takes the overall pick because inline placement in the IAM stack gives it the widest real coverage without a consolidation project first. Choose Push Security if your incidents are phishing and session theft, and enjoy the rare experience of seeing a price before a sales call. Choose Semperis if Active Directory recovery is the requirement. Choose Huntress if you need the analysts more than the console.
Five of seven publishing no pricing is worse than the attack surface management market, which is not exactly transparent either. Buyers should push back harder.
