ITDR Integrations

ITDR (Identity Threat Detection and Response) integrations connect Incode to your threat detection platform, enabling your security team to trigger identity verification as part of an active incident response workflow.

When a suspicious activity alert is raised — such as anomalous login behavior, lateral movement, or credential misuse — your security team can send the flagged user a biometric verification link directly from within the ITDR platform. The result is returned automatically, giving your team the identity confirmation they need to determine whether the alert is a genuine threat or a false positive caused by a legitimate employee.

These integrations are designed for security operations teams who need high-assurance identity confirmation without interrupting their existing incident response tooling.

📘

Note: Integrations require the Integrations Ecosystem feature to be enabled for your organization. Once enabled, you will have access to a new page called Integrations. Contact your Incode representative to enable this feature.

IntegrationDescriptionAvailability
Microsoft Defender for IdentityConnects Incode verification to Microsoft Sentinel via Azure Logic Apps. When Defender raises a suspicious activity incident, the playbook sends the flagged user a verification link and posts the result back to Sentinel.Available
CyberArkAdd biometric identity verification as a step-up authentication trigger within CyberArk's privileged access and identity threat detection workflows.Coming soon