What ITDR Is, and What Continuous User Baselining Actually Does
Published: 04/23/2026
Written by: Nadine Rozell
Identity attacks move fast. A stolen password or hijacked session can turn into an account takeover in minutes, long before a weekly report or a manual review would ever catch it. Identity Threat Detection and Response (ITDR) exists to close that gap, and continuous user baselining is one of the analytical approaches that helps it do that.
This guide breaks down what ITDR is, what "baselining" really means across the industry, and where the two ideas diverge. It also draws a clear line between generic ITDR/User and Entity Behavior Analytics (UEBA) capabilities and what Huntress Managed ITDR documents and delivers today, so you know what to expect from the category and what to expect from us specifically.
Key takeaways
Baselining supports earlier detection; it doesn't stop abuse on its own. Containment depends on validated detection paired with an actual response action.
Huntress Managed ITDR documents behavior-based detection and SOC-backed response for Microsoft 365 and Google Workspace identities. Supported detection areas include suspicious logins, location-based and VPN anomalies, session hijacking, credential theft, rogue OAuth applications, and malicious inbox or forwarding rules. Exact response actions and availability vary by environment and configuration.
ITDR and Identity Security Posture Management (ISPM) are complementary, not competing: ISPM hardens identity configuration before an attack, ITDR detects and responds to attacks already underway.
What is ITDR?
ITDR is a set of capabilities that monitors identities, detects identity-centric threats, and helps coordinate a response across your environment. Analysts and vendors define it a bit differently, but the core idea holds steady: ITDR focuses on identity and access infrastructure — accounts, directories, identity providers, tokens — complementing IAM (which grants access) and SIEM/XDR (which correlates telemetry across your stack).
Depending on the solution, ITDR tools can include some combination of:
Behavioral analytics for logins, devices, and access patterns
Detection logic tuned to identity-specific attack techniques
Analyst investigation and validation
Automated or human-directed response actions
What continuous user baselining means
Continuous user baselining generally refers to establishing expected behavioral patterns for an identity and identifying activity that deviates from those patterns. The signals and detection logic used to create those baselines vary by vendor, so a product’s documentation, not the category definition, should determine what a specific platform monitors. Some ITDR and UEBA platforms baseline a wide range of signals: login times, devices, application access, data access patterns, and peer-group comparisons.
UEBA is one analytical approach that can support ITDR. It isn't the whole of ITDR, and not every ITDR tool baselines the same set of signals or uses the same detection logic. A vendor's documentation — not a generic industry description — is the only reliable way to know what's actually being monitored in a given product.
What capabilities vary across ITDR tools
Because "ITDR" covers a range of products with different architectures, a few things are worth checking before you assume a capability applies broadly:
Detection speed. Detection and response speed varies by telemetry source, integration depth, and configuration. Some platforms advertise seconds-to-minutes detection; actual performance depends on how quickly logs and signals reach the platform.
Response actions. "Adaptive MFA," step-up verification, and conditional access changes show up in some ITDR products, usually ones tightly integrated with an identity provider's policy engine. Other platforms, including Huntress Managed ITDR, focus on session revocation, identity disablement, and remediation of malicious inbox rules. Check what a specific product actually does before assuming a capability is standard.
Orchestration. Some enterprise deployments wire ITDR into SOAR platforms to orchestrate lockouts and token revocations across tools. That's an integration pattern some organizations choose to build, not a core requirement of ITDR itself.
Identity scope. ITDR can encompass non-human identities: service accounts, machine identities, APIs, certificates, and OAuth tokens. Coverage of these identity types varies significantly by vendor and by which identity provider you're running. Don't assume a given ITDR product covers all of them just because "ITDR" as a category can.
How Huntress Managed ITDR baselines behavior
Huntress Managed ITDR continuously baselines a specific, documented set of signals for Microsoft 365 and Google Workspace identities:
Login location and travel patterns
VPN and network origin
Browser and operating system signals
Device signals tied to a given identity
Because baselines take time to learn what's normal for your environment. Detection behavior can vary during onboarding as integrations, telemetry, and configuration are established. Confirm expected alerting and tuning behavior with Huntress during deployment.
Baselining helps identify suspicious identity activity earlier. It doesn't stop abuse on its own; what actually contains a threat is validated detection paired with a real response action, which is where Huntress's SOC comes in.
Huntress detections: unwanted access, shadow workflows, and rogue apps
Huntress Managed ITDR is built to detect specific, documented identity threats across Microsoft 365 and Google Workspace:
Session hijacking and credential theft. Stolen session tokens and compromised credentials that let an attacker skip the login screen entirely.
Location-based and VPN anomalies. Logins from unusual places, unusual networks, or infrastructure attackers favor.
Shadow workflows. Malicious inbox and forwarding rules attackers use to hide their tracks during business email compromise (BEC), plus related activity like password changes and suspicious calendar invites.
Rogue apps. Malicious OAuth applications attackers use to steal data and maintain persistent access, even after a password reset.
These detections are behavior-based. Huntress isn't just forwarding logs and letting you sort through the noise — a security operation center (SOC) analyst investigates the full attack chain before anything reaches you.
Huntress response: SOC validation, session revocation, identity disablement, and inbox-rule remediation
Response at Huntress starts with a person, not a script. While a SOC analyst validates isolation-worthy incidents, they do not need to manually confirm every single case for Huntress to take action. Once an incident is identified, Huntress can:
Revoke active sessions tied to a compromised identity
Disable a compromised Microsoft 365 or Google Workspace identity
Remediate malicious inbox rules used in BEC attempts
Some of this happens automatically once a SOC analyst validates the threat; other cases call for analyst-directed remediation with clear guidance for your team. Either way, the distinction matters: this is SOC-reviewed response, not autonomous analytics acting alone. That's also why Huntress reports a low false-positive rate and a three-minute mean time to respond numbers that reflect analyst-validated action, not just an alert firing.
Best practices for evaluating ITDR and baselining
Instrument every identity source your chosen platform actually supports, and confirm what's in and out of scope before you assume coverage.
Ask how a vendor validates detections: human review, automated logic, or both, before you rely on response speed claims.
Confirm exactly which response actions a platform takes (session revocation, identity disablement, inbox-rule remediation, MFA challenges, and so on) rather than assuming a generic ITDR feature list applies.
If you're evaluating non-human identity coverage, ask specifically which identity types a vendor documents support for, since this varies widely.
Treat ISPM and ITDR as a pair, not a choice. Posture hardening and active detection solve different problems.
FAQs about ITDR and real-time user baselining
Many ITDR and UEBA platforms baseline some combination of login behavior, device signals, and access patterns, but the specific signals monitored vary by vendor. Huntress Managed ITDR baselines location, VPN usage, browser and OS signals, and device signals for Microsoft 365 and Google Workspace identities.
Huntress Managed ITDR baselines login location and travel patterns, VPN and network origin, browser and operating system signals, and device signals, learning what's normal for each identity over time.
Some ITDR platforms can, depending on the product and its integrations. Huntress Managed ITDR can revoke active sessions and disable a compromised Microsoft 365 or Google Workspace identity; while SOC analysts validate incidents, they do not need to confirm every case for Huntress to take action.