Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Look for a coverage matrix across the major identity providers and clarity on native versus add-on connectors.
Strong answers name specific techniques with real detection evidence, not a generic 'we detect identity attacks' claim.
Look for proactive posture assessment as a distinct capability from real-time attack detection.
Strong answers describe genuinely automated response options with configurable thresholds for when automation is trusted versus requiring human approval.
Non-human identity coverage is an increasingly important and often-missing capability — look for a specific answer, not silence on this category.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Cross-domain correlation materially reduces false positives compared to identity-signal-only detection; look for a real customer-validated false-positive figure.
A passive-first rollout option reduces deployment risk; a product that requires enforcement mode from day one is riskier to adopt.
SaaS-layer identity threats are a distinct and growing category — look for specific coverage rather than an answer that only addresses directory-level attacks.
Look for transparent, predictable scaling economics that account for non-human identity growth specifically, since that population often dwarfs human user counts and could create unexpected cost jumps.
Proactive threat-hunting tooling is a materially more advanced capability than pure alert-driven detection — ask for a specific hunting-workflow example, not just a general claim of 'hunting supported.'
Look for genuine data-sharing integration across ITDR/PAM/IGA; three separate tools that each only see part of the identity risk picture create real blind spots at the seams.
Strong answers cite a concrete, named IR capability and response-time figure — an identity compromise (especially privileged-account takeover) is often the highest-severity incident class and deserves specialized, fast response.
Native compliance-evidence generation is materially more valuable than raw alert logs requiring manual compilation for every audit cycle.
Cloud-infrastructure identity (IAM roles/policies) is a distinct and increasingly critical risk surface from directory-layer identity — a vendor should clarify explicitly whether this is covered, since it's a common scope gap.
A concrete, technique-specific latency figure is far more meaningful than an unqualified 'real-time detection' marketing claim — press for the actual number.
Legitimate admin activity frequently resembles early attack-technique signatures — a vendor with no real answer on this tuning challenge likely generates significant alert fatigue in practice.