Talk to us
by DarktraceTechBag Intel Page

Darktrace Identity

A stolen session looks like a normal login. What the account does next shouldn’t — Darktrace Identity learns how each account normally logs in, administers and requests access, then ends the session, forces a new login or restricts access when that pattern breaks — beside your IdP, never instead of it.

Per-account behavioural profilesSession kill, new login, restrictionQuote-only, no India region

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Usage-metric bands written into the order form; Darktrace publishes no IDENTITY price
Quote
Response
End the session, force a fresh login or restrict access for a time, without waiting on a person
3 actions
Analysts
Darktrace’s Gartner Leader placements are for NDR (2025, 2026) and email security (2025)
None for ITDR
India
No Darktrace-hosted India region; a Master appliance in your data centre keeps it local
On-prem Master

Quick answer

Darktrace Identity is Darktrace’s identity threat detection and response. It learns how each account normally logs in, administers and requests access, then acts on its own when that changes: it ends the session, forces re-authentication or briefly restricts access. It is not an identity provider and sits beside Okta or Entra. It is quote-only, and Darktrace hosts nothing in India; an on-premises Master keeps data in the country. Read more ↓ Show less ↑
Part 01 · Orient

The Darktrace platform family

This page covers Darktrace Identity — identity threat detection and response, sold within Darktrace Hybrid Network and Darktrace Email. The rest:

Quick facts

30-second orientation
Product
Identity threat detection and response on the Darktrace Behavioral Defense Platform
Maker
Darktrace, Cambridge, UK; founded 2013; taken private by Thoma Bravo in 2024; CEO Ed Jennings
Former names
DETECT/Apps, RESPOND/Apps, DETECT/Zero Trust and RESPOND/Zero Trust
Watches
Logins, admin activity, sessions and access requests across SaaS, cloud and on-premises identity
Responds
Session termination, forced re-authentication and temporary access restrictions
Is not
An identity provider: it issues no credentials and enforces no MFA
Delivered
Inside Darktrace Hybrid Network (network context) and Darktrace Email (email, SaaS and cloud account takeover)
Price
Quote-only, on usage-metric bands set in the order form; no rupee price published
India
No Darktrace-hosted India region; an on-premises Master appliance keeps the data in the country
In India via
TechBag — scoping against your IdP, a pilot plan, quote in INR with GST
Part 02 · Learn

Understand identity threat detection before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is identity threat detection and response?

ITDR watches what signed-in accounts do and acts when an account starts behaving like an intruder.

Login logs and a password reset vs Darktrace Identity — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionLogin logs and a password resetDarktrace Identity
Spotting a hijacked accountA colleague reports odd mail days laterA break from the account’s profile, raised at once
Who acts firstAn analyst, after the queue clearsDarktrace, with a session kill or new login
What the intruder keepsA live session until a password resetA session ended or access narrowed
Insider misuseFound in an audit, if at allAdmin activity measured against habit
Scope of cleanupGuesswork across scattered logsA record of what the account reached
What it is NOT—An IdP, an MFA product or a published price

The cheapest test is one drill: stage a risky login on a test account and time how fast the session is ended or re-challenged.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the identity modules run

Master

Master appliance or cloud master

The IDENTITY modules run on Darktrace’s own deployment: a physical Master in your data centre or a Darktrace-hosted cloud master, fed by vSensors and other sensors.

02
What normal looks like for each account

Profile

Adaptive AI behavioural profile

Adaptive AI learns each account’s usual logins, admin actions, sessions and access requests, forming the Unique Behavioral Profile that later activity is measured against.

03
What happens when an account turns

Response

Autonomous Response on identities

When an account breaks from its profile, Darktrace can end the session, demand a new login or narrow access for a period, rather than leave the alert waiting in a queue.

04
How the incident is investigated

Analyst

Real-Time AI Analyst

The platform’s Real-Time AI Analyst (Cyber AI Analyst in older documents) investigates on its own, so identity signal and network or email evidence end up in one investigation.

A Master and its sensors learn every account — a break from that profile ends the session, forces a login or narrows access.

Part 03 · Evaluate

Nine capabilities. Baseline, respond, investigate.

Darktrace Identity watches what signed-in accounts do and acts on its own when one starts behaving like an intruder.

Baseline
Logins

Learns how each account signs in

Adaptive AI learns every account’s normal logins, so an odd sign-in is judged against that account’s history, not a generic rule.

Baseline
Admin activity

Watches privileged actions

Administrative activity is profiled too, so an account that suddenly grants rights or changes settings it never touches is raised.

Baseline
Sessions

Follows the session past login

Session behaviour and access requests are tracked after sign-in, which is where a hijacked account usually gives itself away.

Respond
Session kill

Ends a suspicious session

Autonomous Response can terminate a session that strays from the account’s profile, cutting off someone working with live credentials.

Respond
Re-authentication

Makes the user prove it again

Darktrace can force a fresh login: the real user passes it in seconds, while an intruder riding a borrowed session meets a new challenge.

Respond
Restriction

Narrows access for a time

A temporary access restriction limits what a risky account can reach while your team looks into it, instead of disabling it outright.

Investigate
AI Analyst

Investigates before you open it

The Real-Time AI Analyst works through the alert itself and hands over a written incident, so analysts start from findings.

Investigate
Context

Joins accounts to network and mail

Bought with Darktrace Hybrid Network or Darktrace Email, a strange login is read beside the device and mailbox behind it in the same case.

Investigate
Recovery

Shows what the account touched

Recovery and audit views record what a compromised account reached, so cleanup covers what was really involved.

See it, don’t just read it

Watch Darktrace Identity in action

Two short walk-throughs from Darktrace’s official channel: account takeover caught across email and SaaS (2023), and an attempted Dropbox account takeover (2024). Both predate the August 2026 platform rename.

Darktrace (official)·Short, 2023

Identifying Account Takeovers with Integrated Email and SaaS Security | Darktrace

How email and SaaS signal are read together to catch an account takeover; recorded in 2023, before the platform rename.

Darktrace (official)·Short, 2024

Catching an Attempted Dropbox Account Takeover

A 2024 walk-through of an attempted takeover of a Dropbox account and how Darktrace spotted it.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Darktrace Identity

A password check happens once. Darktrace keeps judging the account afterwards.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Response before the damage spreads

Most identity alerts wait for a person. Darktrace Identity can act first: it ends the session, forces a fresh login or restricts access for a while as soon as an account breaks from its learned profile, so your team reviews a contained incident, not a running one.

02

Accounts read with network and email

Darktrace sells IDENTITY inside Darktrace Hybrid Network, where a login is seen beside the device traffic behind it, and inside Darktrace Email, which catches mailbox, SaaS and cloud takeovers. One Real-Time AI Analyst investigation can hold all of it.

03

Each account judged against its own habits

Adaptive AI profiles each account from its logins, admin actions, sessions and access requests, so an insider misusing real rights can stand out like an outsider. It is not rule-free: custom models can be added, and are worth writing for key accounts.

04

Where it stops

It signs nobody in and enforces no MFA, so it never replaces Okta or Entra. Darktrace markets it inside two other products; confirm it is quoted as a line item. No price, no India-hosted region, no ITDR analyst placement, no named identity customer, and network context is only as good as your mirroring.

The idea
Learn each account, act when it changes
The response
End session, new login, restrict access
The price
Quote-only, on usage-metric bands
Proof, not promises

The numbers behind the platform

3 actions
autonomous responses: end the session, force a new login, or restrict access for a time
— Vendor
4 old names
DETECT and RESPOND modules for Apps and Zero Trust, now carried under the IDENTITY spec
— Vendor
~10000
customers across Darktrace as a whole, by its own 2026 count of nearly ten thousand
— Vendor
2400+
Darktrace employees, as stated in its 2026 company description
— Vendor
110 countries
where Darktrace says it serves customers, per its services page
— Vendor
2 years
as a Leader in Gartner’s NDR Magic Quadrant (2025, 2026) — the network product, not IDENTITY
— Analyst

What your Darktrace Identity rollout looks like

Week 1Model

Map identities and the IdP

List your IdPs, AD domains, SaaS apps and privileged accounts, then get Darktrace’s connector list for them in writing.

Week 2Decide

Settle how it is licensed

Confirm whether IDENTITY is a quoted line item or sits inside Darktrace Hybrid Network or Darktrace Email, and on which usage bands.

Week 3Pilot

Connect and let it learn

Link sources to the Master and sensors, check traffic mirroring is complete, and let Adaptive AI build account profiles.

Month 2Prove

Drill an account takeover

Simulate a risky login on a test account and time the session kill, forced login and restriction against your target.

Month 3Commit

Hand it to the SOC

Route incidents to your SIEM or ticketing, write custom models for service accounts, and agree which actions run unattended.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
41+ reviews*
83% would recommend
Account takeover detection4.4
Autonomous response4.3
Network and email context4.4
Ease of tuning3.7
Value for money3.8
5★
46%
4★
35%
3★
13%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“A payments user’s session from an unfamiliar network was ended and re-challenged before our L1 team had finished reading the alert.”
SOC Lead
BFSI
Manufacturing
“We had Darktrace on the network already. With identity added, a strange login and the laptop behind it showed up as one incident.”
Security Architect
Manufacturing
Healthcare
“Early on it flagged admins whose habits really were odd. Writing a few custom models for service desks cut that noise down.”
IT Security Manager
Healthcare
Retail
“Good at stopping sessions, but it is not our MFA. We still run Entra for conditional access, and the quote took several weeks.”
Head of IT
Retail
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity threat detection and response market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag ITDR Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Darktrace IdentityThis page

Quoted on usage-metric bands; no public price.

Grid 02 · The architecture

Identity Coverage × Response Autonomy

The grid nobody publishes — how many identity sources and signal types a product reads vs how much it does on its own when an account turns.

Autonomous but narrowBroad and autonomousNarrow detectorsBroad but advisory
Darktrace IdentityThis page

SaaS, cloud and on-prem identity plus network and email context; session kill.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Darktrace Identity vs the ITDR field

Against Okta Identity Threat Protection, CrowdStrike Falcon Identity Protection, SentinelOne Singularity Identity, Delinea Identity Threat Protection and LinkShadow ITDR — on sources, detection, response, price, analyst standing, India and lock-in.

DimensionDarktrace IdentityOkta Identity Threat ProtectionCrowdStrike Falcon Identity ProtectionSentinelOne Singularity IdentityDelinea Identity Threat ProtectionLinkShadow ITDR
What it isBehavioural ITDRSession risk inside OktaITDR module on FalconITDR with deceptionITDR from a PAM vendorCyberMeshX module
DeploymentAppliance or cloudOkta cloud onlyFalcon cloudSingularity agentDelinea SaaSSaaS or on-premises
Identity sourcesSaaS, cloud, on-premOkta users + SSFAD, Entra ID, OktaAD, Entra, Okta, PingBroad, no named listYour IAM, PAM, SSO
Detection methodPer-account profilesOkta AI session riskML baselines, AD attacksDetection plus decoysAnalytics, list unstatedBehavioural analytics
Response actionsKill, re-auth, restrictUniversal LogoutStep-up MFABlock, re-auth, isolateRecommendations onlyDetects, does not act
Prerequisite stackA Darktrace deploymentOkta as your IdPFalcon platformSingularity platformYour IdP and PAMBest with LinkShadow NDR
Pricing modelUsage-metric bandsAdd-on to WorkforceFalcon module, FlexSingularity moduleQuote, unit unstatedQuote, no unit
Published entry priceNot publishedNot publishedNot publishedNot publishedNot publishedNot published
Included vs add-onInside two productsPaid extra on OktaAdded to FalconAdded to SingularityLicensed on its ownOne of three modules
Signal correlationNetwork + email contextSSF partner signalsIdentity + endpointIdentity + endpointInto SecOps toolsNDR in one console
Analyst standingNone for ITDRNone citedNone for ITDREndpoint MQ onlyPAM-level onlyNDR only
India data locationOn-prem MasterIndia tenants (2026)Not statedNot statedSEA or UAE nearestNo commitment
Lock-in and exitDarktrace-boundOkta-boundFalcon-boundSingularity-boundDelinea PlatformCyberMeshX-bound
Best fitDarktrace estatesOkta-first workforcesFalcon endpoint estatesDeception buyersDelinea PAM estatesLinkShadow NDR owners
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Darktrace Identity if…

  • ✓You already run Darktrace Hybrid Network or Darktrace Email and want account takeover read in the same investigation
  • ✓You want a risky session ended or re-challenged automatically, not just logged as another ticket
  • ✓Identity is spread across SaaS, cloud and on-premises systems that no single IdP sees in full

Compare alternatives if…

  • ✓Your workforce signs in through Okta alone — Okta ITP acts inside the sessions Okta itself brokers
  • ✓You want decoy accounts and credential lures — SentinelOne Singularity Identity builds deception in
  • ✓Falcon sensors already cover your endpoints — CrowdStrike ties identity to them and can step up MFA

Do not expect…

  • ✓An identity provider, MFA enforcement or credentials issued to anyone
  • ✓A Gartner ITDR placement — Darktrace’s Leader spots are for NDR and email security
  • ✓A Darktrace-hosted India region, or any price list for the identity modules

Darktrace Identity is one of 26 IAM, SSO & MFA products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does chasing account takeovers cost you?

Drag the sliders (accounts you monitor; analyst-hour cost). Estimates model the analyst time spent investigating suspicious logins, chasing account takeovers and resetting access by hand, at an assumed 1.5 hours per account a year, with 70% of it removed by autonomous response and AI-led investigation. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual identity-investigation cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Darktrace publishes no price for Darktrace Identity; its contract sells the modules on usage-metric bands set in the order form, and the website now presents identity as a capability inside Darktrace Hybrid Network and Darktrace Email, so confirm it appears as its own line. Darktrace’s only public prices — AWS Marketplace public offer tiers from $30,000 a year — are metered on network bandwidth and hosts and do not price identity. There is no rupee price. TechBag maps your identity sources first, then quotes in INR with GST.

With Darktrace Hybrid Network

Best where identity needs network context

  • Logins read beside device traffic
  • Runs on your Master and sensors
  • Quoted on usage-metric bands

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

With Darktrace Email

Best for mailbox and SaaS account takeover

  • Email, SaaS and cloud takeover
  • Outside the mail flow, no MX change
  • Quoted per estate; no list price

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Identity sources

Which IdPs, AD domains and SaaS apps will it read? Get the connector list in writing before you sign.

2
Licensing

Is IDENTITY a separate line on the quote, or folded into Darktrace Hybrid Network or Darktrace Email? Which usage band applies?

3
Prerequisites

Do you already run a Darktrace Master and sensors, or does this purchase have to bring them in too?

4
Response policy

Which accounts are safe to have sessions ended automatically, and how will you test each action before go-live?

5
Traffic feed

Is mirrored traffic complete for the segments where your identity systems live? Gaps weaken the network context.

6
Data location

Cloud master in Singapore, or an on-premises Master in India? Decide where identity metadata may be stored.

7
Overlap

Do Entra ID Protection, Okta ITP or Falcon Identity already cover these accounts on a bill you pay today?

8
Quote

Does the quote list modules, usage bands, term and support level? Ask for INR with GST and the renewal terms.

FAQ

Questions buyers ask

It is Darktrace’s identity threat detection and response. Adaptive AI learns how each account normally logs in, administers systems, holds sessions and requests access, and when that pattern breaks Darktrace can end the session, force a new login or restrict access for a time.

Ready to evaluate Darktrace Identity?

Map your IdPs and SaaS apps against Darktrace’s connectors first, or let a TechBag advisor confirm the licensing, choose between a cloud master and an on-premises Master, and get the quote itemised in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.