A stolen session looks like a normal login. What the account does next shouldn’t — Darktrace Identity learns how each account normally logs in, administers and requests access, then ends the session, forces a new login or restricts access when that pattern breaks — beside your IdP, never instead of it.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Darktrace Identity — identity threat detection and response, sold within Darktrace Hybrid Network and Darktrace Email. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
ITDR watches what signed-in accounts do and acts when an account starts behaving like an intruder.
What consolidation actually replaces, dimension by dimension.
| Dimension | Login logs and a password reset | Darktrace Identity |
|---|---|---|
| Spotting a hijacked account | A colleague reports odd mail days later | A break from the account’s profile, raised at once |
| Who acts first | An analyst, after the queue clears | Darktrace, with a session kill or new login |
| What the intruder keeps | A live session until a password reset | A session ended or access narrowed |
| Insider misuse | Found in an audit, if at all | Admin activity measured against habit |
| Scope of cleanup | Guesswork across scattered logs | A record of what the account reached |
| What it is NOT | — | An IdP, an MFA product or a published price |
The cheapest test is one drill: stage a risky login on a test account and time how fast the session is ended or re-challenged.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The IDENTITY modules run on Darktrace’s own deployment: a physical Master in your data centre or a Darktrace-hosted cloud master, fed by vSensors and other sensors.
Adaptive AI learns each account’s usual logins, admin actions, sessions and access requests, forming the Unique Behavioral Profile that later activity is measured against.
When an account breaks from its profile, Darktrace can end the session, demand a new login or narrow access for a period, rather than leave the alert waiting in a queue.
The platform’s Real-Time AI Analyst (Cyber AI Analyst in older documents) investigates on its own, so identity signal and network or email evidence end up in one investigation.
A Master and its sensors learn every account — a break from that profile ends the session, forces a login or narrows access.
Darktrace Identity watches what signed-in accounts do and acts on its own when one starts behaving like an intruder.
Adaptive AI learns every account’s normal logins, so an odd sign-in is judged against that account’s history, not a generic rule.
Administrative activity is profiled too, so an account that suddenly grants rights or changes settings it never touches is raised.
Session behaviour and access requests are tracked after sign-in, which is where a hijacked account usually gives itself away.
Autonomous Response can terminate a session that strays from the account’s profile, cutting off someone working with live credentials.
Darktrace can force a fresh login: the real user passes it in seconds, while an intruder riding a borrowed session meets a new challenge.
A temporary access restriction limits what a risky account can reach while your team looks into it, instead of disabling it outright.
The Real-Time AI Analyst works through the alert itself and hands over a written incident, so analysts start from findings.
Bought with Darktrace Hybrid Network or Darktrace Email, a strange login is read beside the device and mailbox behind it in the same case.
Recovery and audit views record what a compromised account reached, so cleanup covers what was really involved.
Two short walk-throughs from Darktrace’s official channel: account takeover caught across email and SaaS (2023), and an attempted Dropbox account takeover (2024). Both predate the August 2026 platform rename.
How email and SaaS signal are read together to catch an account takeover; recorded in 2023, before the platform rename.
A 2024 walk-through of an attempted takeover of a Dropbox account and how Darktrace spotted it.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most identity alerts wait for a person. Darktrace Identity can act first: it ends the session, forces a fresh login or restricts access for a while as soon as an account breaks from its learned profile, so your team reviews a contained incident, not a running one.
Darktrace sells IDENTITY inside Darktrace Hybrid Network, where a login is seen beside the device traffic behind it, and inside Darktrace Email, which catches mailbox, SaaS and cloud takeovers. One Real-Time AI Analyst investigation can hold all of it.
Adaptive AI profiles each account from its logins, admin actions, sessions and access requests, so an insider misusing real rights can stand out like an outsider. It is not rule-free: custom models can be added, and are worth writing for key accounts.
It signs nobody in and enforces no MFA, so it never replaces Okta or Entra. Darktrace markets it inside two other products; confirm it is quoted as a line item. No price, no India-hosted region, no ITDR analyst placement, no named identity customer, and network context is only as good as your mirroring.
List your IdPs, AD domains, SaaS apps and privileged accounts, then get Darktrace’s connector list for them in writing.
Confirm whether IDENTITY is a quoted line item or sits inside Darktrace Hybrid Network or Darktrace Email, and on which usage bands.
Link sources to the Master and sensors, check traffic mirroring is complete, and let Adaptive AI build account profiles.
Simulate a risky login on a test account and time the session kill, forced login and restriction against your target.
Route incidents to your SIEM or ticketing, write custom models for service accounts, and agree which actions run unattended.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“A payments user’s session from an unfamiliar network was ended and re-challenged before our L1 team had finished reading the alert.”
“We had Darktrace on the network already. With identity added, a strange login and the laptop behind it showed up as one incident.”
“Early on it flagged admins whose habits really were odd. Writing a few custom models for service desks cut that noise down.”
“Good at stopping sessions, but it is not our MFA. We still run Entra for conditional access, and the quote took several weeks.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity threat detection and response market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted on usage-metric bands; no public price.
The grid nobody publishes — how many identity sources and signal types a product reads vs how much it does on its own when an account turns.
SaaS, cloud and on-prem identity plus network and email context; session kill.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Okta Identity Threat Protection, CrowdStrike Falcon Identity Protection, SentinelOne Singularity Identity, Delinea Identity Threat Protection and LinkShadow ITDR — on sources, detection, response, price, analyst standing, India and lock-in.
| Dimension | Darktrace Identity | Okta Identity Threat Protection | CrowdStrike Falcon Identity Protection | SentinelOne Singularity Identity | Delinea Identity Threat Protection | LinkShadow ITDR |
|---|---|---|---|---|---|---|
| What it is | Behavioural ITDR | Session risk inside Okta | ITDR module on Falcon | ITDR with deception | ITDR from a PAM vendor | CyberMeshX module |
| Deployment | Appliance or cloud | Okta cloud only | Falcon cloud | Singularity agent | Delinea SaaS | SaaS or on-premises |
| Identity sources | SaaS, cloud, on-prem | Okta users + SSF | AD, Entra ID, Okta | AD, Entra, Okta, Ping | Broad, no named list | Your IAM, PAM, SSO |
| Detection method | Per-account profiles | Okta AI session risk | ML baselines, AD attacks | Detection plus decoys | Analytics, list unstated | Behavioural analytics |
| Response actions | Kill, re-auth, restrict | Universal Logout | Step-up MFA | Block, re-auth, isolate | Recommendations only | Detects, does not act |
| Prerequisite stack | A Darktrace deployment | Okta as your IdP | Falcon platform | Singularity platform | Your IdP and PAM | Best with LinkShadow NDR |
| Pricing model | Usage-metric bands | Add-on to Workforce | Falcon module, Flex | Singularity module | Quote, unit unstated | Quote, no unit |
| Published entry price | Not published | Not published | Not published | Not published | Not published | Not published |
| Included vs add-on | Inside two products | Paid extra on Okta | Added to Falcon | Added to Singularity | Licensed on its own | One of three modules |
| Signal correlation | Network + email context | SSF partner signals | Identity + endpoint | Identity + endpoint | Into SecOps tools | NDR in one console |
| Analyst standing | None for ITDR | None cited | None for ITDR | Endpoint MQ only | PAM-level only | NDR only |
| India data location | On-prem Master | India tenants (2026) | Not stated | Not stated | SEA or UAE nearest | No commitment |
| Lock-in and exit | Darktrace-bound | Okta-bound | Falcon-bound | Singularity-bound | Delinea Platform | CyberMeshX-bound |
| Best fit | Darktrace estates | Okta-first workforces | Falcon endpoint estates | Deception buyers | Delinea PAM estates | LinkShadow NDR owners |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Darktrace Identity is one of 26 IAM, SSO & MFA products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (accounts you monitor; analyst-hour cost). Estimates model the analyst time spent investigating suspicious logins, chasing account takeovers and resetting access by hand, at an assumed 1.5 hours per account a year, with 70% of it removed by autonomous response and AI-led investigation. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Darktrace publishes no price for Darktrace Identity; its contract sells the modules on usage-metric bands set in the order form, and the website now presents identity as a capability inside Darktrace Hybrid Network and Darktrace Email, so confirm it appears as its own line. Darktrace’s only public prices — AWS Marketplace public offer tiers from $30,000 a year — are metered on network bandwidth and hosts and do not price identity. There is no rupee price. TechBag maps your identity sources first, then quotes in INR with GST.
Best where identity needs network context
Best for a broader rollout
Best for mailbox and SaaS account takeover
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which IdPs, AD domains and SaaS apps will it read? Get the connector list in writing before you sign.
Is IDENTITY a separate line on the quote, or folded into Darktrace Hybrid Network or Darktrace Email? Which usage band applies?
Do you already run a Darktrace Master and sensors, or does this purchase have to bring them in too?
Which accounts are safe to have sessions ended automatically, and how will you test each action before go-live?
Is mirrored traffic complete for the segments where your identity systems live? Gaps weaken the network context.
Cloud master in Singapore, or an on-premises Master in India? Decide where identity metadata may be stored.
Do Entra ID Protection, Okta ITP or Falcon Identity already cover these accounts on a bill you pay today?
Does the quote list modules, usage bands, term and support level? Ask for INR with GST and the renewal terms.
Map your IdPs and SaaS apps against Darktrace’s connectors first, or let a TechBag advisor confirm the licensing, choose between a cloud master and an on-premises Master, and get the quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.