Watch the identities you own. Attackers log in rather than break in — LinkShadow ITDR detects identity attacks on the IAM, PAM and SSO you already run. It sits beside your identity provider — never instead of one. Honest: check what you already own first.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers ITDR — the identity module. The rest of the platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Detection across the identities you already run — behavioural analytics on your IAM, PAM and SSO to surface credential misuse, privilege escalation and identity-based attacks. It detects; it does not authenticate.
What consolidation actually replaces, dimension by dimension.
| Dimension | Identities nobody is watching | ITDR (LinkShadow) |
|---|---|---|
| What it does | Authenticates and authorises | Detects misuse of those identities |
| Where it sits | In the login path | Beside your IdP, watching it |
| Enforcement | Blocks, steps up, disables | Raises a finding; your IdP acts |
| Overlap risk | One identity provider | May duplicate Entra ID Protection or CrowdStrike |
| The real edge | Identity signal alone | Identity correlated with network traffic |
| Analyst standing | Specialists evaluated in this space | None for this module — the MQ is for NDR |
ITDR detects; it does not authenticate. It sits beside Okta or Entra, never instead of one — and the 2026 Gartner Visionaries placement is for LinkShadow's NDR, not this module.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
This module integrates with the IAM, PAM and SSO you already run rather than replacing any of it. So the first evaluation question is coverage: does it read the specific systems in YOUR estate? A system it cannot see is one it has no opinion about.
Models learn what normal looks like for each account — where it signs in from, what it reaches, at what hours, with what privilege — then surface deviation. As with any behavioural system, expect a baseline period before precision is useful.
This module raises a finding. Blocking a session, forcing re-authentication or disabling an account all happen in your identity provider. That division is correct — but it means the value depends on the response path being wired before the first real detection.
The strongest case for this module specifically. An anomalous identity is moderate. A beaconing host is moderate. The same identity, on that host, reaching something new is high-confidence — and neither product produces it alone. It requires owning more than one module.
Human accounts get attention; service accounts, API credentials and machine identities often outnumber them and are rarely baselined. Ask how this module treats non-human identities — a service account behaving interactively is among the highest-value detections there is.
One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.
LinkShadow ITDR watches the identities you already run — behavioural detection layered on the portfolio, and paired with the human firewall.
Integrates with existing IAM, PAM and SSO rather than replacing them. Check coverage against YOUR specific systems — an ITDR tool that cannot see a directory has no opinion about what happens inside it.
Where it signs in from, what it reaches, at what hours, with what privilege. Deviation from that baseline is the signal — which means a tuning period before the detections are precise enough to act on.
Sudden privilege changes, additions to sensitive groups and service accounts behaving interactively are among the highest-value identity detections, because they usually sit directly on an attack path rather than at its edges.
Impossible travel, unusual client or location, and access patterns inconsistent with the account's history. Useful, and precisely the area where an existing Entra ID Protection or CrowdStrike deployment may already give you the same answer.
Blocking, forcing re-authentication and disabling accounts happen in your identity provider. Wire that response path during deployment, because a detection nobody can act on quickly does not reduce risk.
The genuine differentiator: the same account, on a beaconing host, reaching something new, correlated in one console with LinkShadow NDR. A compound detection neither product produces alone — and it needs both modules.
The identity module explained, and the platform argument behind it.
The identity-detection module and what it covers.
The CyberMeshX consolidation argument.
The case against tool sprawl, from the vendor.
The company and the platform, in its own words.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s the honest case for this module — and why to audit what you already own first.
The single most common evaluation error with ITDR is treating it as an identity-provider alternative. LinkShadow ITDR issues no credentials, enforces no multi-factor authentication and replaces nothing in your identity stack. It reads the IAM, PAM and SSO systems you already run and applies behavioural analytics on top of them to surface identity-based attacks, credential misuse and privilege escalation. It belongs beside Okta or Microsoft Entra, never instead of one. This is not a shortcoming of the product — it is what the entire ITDR category is — but it changes the comparison completely. A buyer who lines this up against Okta on a feature grid is comparing a smoke detector to a door lock. The right comparison set is Microsoft Entra ID Protection, CrowdStrike Identity Protection and Silverfort, and TechBag will run that comparison honestly, including the case where you already own one of them.
The strongest and most specific argument for this module is not its identity analytics in isolation — it is what happens when those findings sit beside LinkShadow’s NDR traffic analysis in one console. Consider the detections separately. An account behaving anomalously is a moderate-confidence finding that a busy team may or may not chase. A host beaconing outbound on a regular interval is a moderate-confidence finding of the same kind. But the SAME account, on THAT host, reaching a resource it has never touched before, is a high-confidence detection that describes an actual attack in progress — and neither product produces it alone, because neither sees the other half. That compound detection is a genuine architectural advantage over running two separate best-of-breed tools that never exchange signal. Its precondition, as with the DSPM module, is that you own more than one. Buying ITDR by itself gets you a console; buying it beside the NDR gets you the argument.
This module layers on identity infrastructure, which makes duplication a real and expensive risk rather than a theoretical one. If you run Microsoft Entra ID Protection, you already have risk-based detection across your Entra identities. If you run CrowdStrike Identity Protection, you have identity threat detection tied into your endpoint estate. If you run Silverfort, you have detection and enforcement across systems that were never built for modern MFA. Each of those may already cover a substantial share of what LinkShadow ITDR would detect, and paying twice for overlapping coverage is a poor outcome that a proof of concept run properly will expose early. The honest evaluation is therefore not ‘does this detect identity threats’ — it will — but ‘what does this detect that our existing tools do not, on our estate’. TechBag would rather run that comparison before a purchase order than defend a redundant licence afterwards.
Three facts belong in front of a shortlist rather than behind it. First, there is no independent analyst evaluation of LinkShadow ITDR. The company’s 2026 Gartner placement in Visionaries is for its NDR flagship, and citing the Magic Quadrant in support of this module misreads what it covers — a claim that will not survive a technical evaluation. Second, LinkShadow publishes no pricing at all: its marketplace listings are bring-your-own-licence with no figure, and the pricing pages that appear on aggregator sites are generated rather than vendor-published. Third, there is no India data residency; LinkShadow’s privacy policy states that data may be used, processed or stored anywhere in the world, and the company makes no DPDP Act, RBI, SEBI, IRDAI or CERT-In claim anywhere. For a module that processes identity telemetry about your workforce, a regulated Indian buyer should establish exactly what leaves the country and get it contractually. None of this makes the technology poor; it does mean the buying case has to rest on the correlation argument rather than on external validation.
ITDR detects; it does not authenticate. Make sure everyone in the evaluation understands it sits beside your identity provider rather than replacing part of it, because that misunderstanding derails comparisons early.
Entra ID Protection, CrowdStrike Identity Protection and Silverfort each cover a share of this. TechBag runs the overlap analysis before a PoC, because paying twice for the same detections is the most common bad outcome here.
Which IAM, PAM and SSO systems does it read, at what fidelity? A system it cannot see is a system it has no opinion about, and coverage gaps in a detection tool are invisible by definition.
Blocking, step-up authentication and account disablement happen in your identity provider. Decide who acts and how fast during deployment, not after the first real detection.
If you run LinkShadow NDR, this is the thing to actually validate: does the combined identity-plus-network detection fire on a scenario neither module catches alone? That is the whole buying case.
Identity platforms add detections constantly. What is differentiated today may be included in your identity provider next year, so revisit the overlap analysis at each renewal rather than assuming it holds.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“The correlation is the product. Identity anomalies on their own we already had; the same account on a beaconing host is what actually got us out of bed, and that only exists because we run their NDR too.”
“Solid identity detections once baselined. Do check overlap with what you own — we found perhaps half of it duplicated our existing Entra risk detections.”
“Worth being clear internally that this is not an identity provider. Two people in our evaluation assumed it replaced part of our SSO, which it does not.”
“We already ran Silverfort and could not justify the overlap. TechBag flagged that in the first call rather than letting us discover it in the PoC.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity threat detection market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Thinnest module; strongest beside its own NDR.
The grid nobody publishes — depth in identity detection vs how much the platform correlates with network signal.
Thin alone; strong network correlation.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Entra ID Protection may already be licensed to you — the honest question is what this detects that your existing tools do not.
| Dimension | LinkShadow ITDR | Entra ID Protection | CrowdStrike Identity | Silverfort |
|---|---|---|---|---|
| Replaces your identity provider | No — by design | No — part of Entra | No | Adds enforcement |
| Correlation with network traffic | Yes — with its NDR | No | Endpoint-correlated | No |
| Analyst recognition for ITDR | None | Established | Established | Established |
| Overlap with what you may own | High | Included | Bundled | Distinct |
| Published pricing | None at all | Published | Quote-only | Quote-only |
| India data residency | Not offered | Region options | Confirm | Confirm |
| Named public customers | None published | Published | Published | Published |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
ITDR is one of 18 IAM, SSO & MFA products TechBag carries. The IAM, SSO & MFA guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (identities in scope; IT-hour cost as loaded rate). Estimates model analyst time investigating identity incidents without behavioural baselining — the avoided-breach value of catching credential misuse early is the larger, unpriced win. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
LinkShadow publishes NO price. TechBag audits overlap with what you already own FIRST, then scopes and quotes in INR with GST — modules priced separately.
Best beside LinkShadow NDR
Best for a broader rollout
Best if you own both
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Does everyone in the evaluation understand this DETECTS rather than authenticates? It sits beside your IdP, never instead of it.
Do you run Entra ID Protection, CrowdStrike Identity or Silverfort? Audit the duplication BEFORE a PoC, not during.
Which of YOUR IAM, PAM and SSO systems does it actually read, and at what fidelity? A system it cannot see, it cannot judge.
Are you running LinkShadow NDR too? If not, the main argument for this module does not apply to you.
Who acts on a detection, in which system, how fast? Enforcement happens in your identity provider, not here.
Does your board expect independent validation? There is none for this module — the 2026 Visionaries placement is for NDR.
What identity telemetry about your workforce leaves India? No residency is offered — get the answer in writing.
Can you approve without a list price? LinkShadow publishes none; TechBag returns a scoped INR quote with GST.
Start with an overlap audit against Entra ID Protection, CrowdStrike or Silverfort — TechBag runs that before a proof of concept, because paying twice for the same detections helps nobody.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.