Planning Sophos ITDR: Prerequisites, licenses, regions, and roles
Before setting up ITDR, confirm the data region, license activation, Entra P1/P2 licensing, roles, and providers. Clear product and operational …
Sophos ITDR (Identity Threat Detection and Response) reveals identity risks, misconfigurations, and signs of compromised credentials. These guides cover prerequisites and connection, security posture and directory assessment, finding investigation, and controlled configuration or decommissioning.
First clarify scope, permissions, and identity sources, then connect the relevant integration. Next prioritize organizational and identity risks, examine directory objects, and address findings or compromised credentials with authorized actions. Settings, integrations, and offboarding complete the controlled lifecycle.
Check licensing, region, role, and product-boundary requirements. Then connect Microsoft Entra ID or on-premises Active Directory through the appropriate ITDR integration and verify the connection.
Before setting up ITDR, confirm the data region, license activation, Entra P1/P2 licensing, roles, and providers. Clear product and operational …
This runbook covers prerequisites, the Entra ID connection, consent checks, data validation, and safe recovery from provisioning or replication …
The ITDR Sensor reads on-premises AD objects through a read-only account, synchronizes changes hourly by default, and must appear as Healthy and …
Interpret Identity Overview and the organization-wide Risk Posture Score. Then examine identity-related Risk Scores as well as users, non-human identities, groups, devices, and applications in the ITDR Directory.
The Identity Overview summarizes the state of monitored identities. This guide explains every widget, the organization-wide score, and a robust daily …
The Risk Score is calculated individually for each identity and helps with prioritization. This article explains the scale, factors, limitations, …
Practical guide to Directory tabs, filters, Human and NHI context, provider boundaries, and investigating sign-ins, findings, and dark web records.
Prioritize ITDR Findings, review their details and history, and verify the effect of remediation. Address signs of compromised credentials in Dark Web Intelligence only within your own area of responsibility.
This runbook covers the workflow from the prioritized Findings list through detailed review and remediation to controlled resolution, dismissal, or …
From active Credential Leaks to authorised response to controlled validation: with precise views, status rules, metrics, and a severity matrix.
Manage integrations, monitored domains, VIP users, and Posture Checks. Prepare changes and the removal of an integration only after their effects have been documented.
An operations guide to integrations, Dark Web Monitoring, Posture Check Preferences, and controlled decommissioning, with a mandatory stop before …
Sophos ITDR assesses identity security posture and provides ITDR Findings, risk scores, directory information, and Dark Web intelligence. It replaces neither source-directory administration nor a general Detection and Response platform. Before taking action, therefore, establish which product generated the finding and who authorizes changes at the identity provider.
The following firm boundaries apply to adjacent tasks:
In practice, this means connecting sources in a controlled manner, assessing risks and directory data in ITDR, investigating findings, making authorized corrections in the responsible system, and then verifying their effect again in ITDR. Change or remove integrations only after effects and responsibilities have been clarified.