The Identity Threat Detection and Response (ITDR) add-on delivers comprehensive identity analytics and proactive posture management capabilities to secure organizational environments against identity-based threats. By integrating automated asset classification, behavior-based detection rules, and dynamic access policies, ITDR enables you to continuously monitor risk exposure, uncover anomalous activity, and enforce directory protections.
The ITDR add-on includes the following capabilities:
* [User Risk View](identity-threat-module-itdr/investigate-user-risk) which provides additional information about the asset for easy uncovering of hidden threats.
* [Risk Management Dashboard](identity-threat-module-itdr/monitor-user-risk-exposure) to help you review the risk exposure of the organization and enable faster decision making.
* Automated and customizable [Asset Role](identity-threat-module-itdr/asset-roles) classification based on constant analysis of the users in your network. You can edit and manage the User Asset Roles to meet the needs of your organization.
* Detection rules which monitor identity and authentication activity to identify identity-based threats, such as compromised accounts, privilege escalation, and anomalous access, and trigger issues when suspicious behavior is detected. See a complete list of the [Analytics rules](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/).
* Dedicated view for quickly reviewing all identity related issues at a glance under **Modules** → **Identity Security** → **Issues → Threats**.
* Active Directory Security Posture Management (AD-SPM) which scans your infrastructure to uncover security vulnerabilities and misconfigurations, including weak and compromised passwords, across all identity types and provides targeted remediation steps. For more information, see [Improve Active Directory Posture with AD-SPM](identity-threat-module-itdr/active-directory-security-posture-management).
* Conditional Access Policy which enforces dynamic, context-driven access control by evaluating real-time authentication requests against user-centric security contexts and risk levels to immediately allow, block, or require multi-factor authentication. For more information, see [Enforce dynamic access control with CAP](identity-threat-module-itdr/conditional-access-policy).
* LDAP protection which analyzes and acts upon suspicious LDAP queries received by the Domain Controller, to detect and block Active Directory reconnaissance attacks. For more information, see [Prevent malicious LDAP queries](identity-threat-module-itdr/prevent-malicious-ldap-queries)**.**
* Remediation actions using the [Cortex Response and Remediation content packs](investigation-and-response/analyze-and-resolve-cases/resolve-the-case/cortex-response-and-remediation-content-pack), a collection of automated playbooks that enable you to focus on high-priority threats while automating repetitive tasks.\
For additional remediation capabilities, see the [Idira](https://www.paloaltonetworks.com/idira) documentation.