Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • Data Security

Cohesity Boosts Identity Resilience with New ITDR


Cohesity Boosts Identity Resilience with New ITDR
  • by: Source Logo
  • |
  • January 22, 2026

Cohesity has expanded its Identity Resilience portfolio with new advanced Identity Threat Detection and Response (ITDR) features, providing comprehensive protection, real-time threat stopping, and accelerated recovery for critical identity systems including Active Directory and Microsoft Entra ID.

Quick Intel

  • Cohesity introduces advanced ITDR capabilities to secure hybrid identity environments across Active Directory and Entra ID.
  • Features proactive posture monitoring, automated remediation, and rapid post-attack recovery with natural language summaries.
  • New additions include vulnerability assessment, automatic rollback, tamperproof change tracking, and service account protection.
  • Delivers near real-time visibility into Entra ID changes, compliance reporting templates, and integrations with Splunk and Microsoft Sentinel.
  • Offers measurable benefits: 90% faster AD recovery, 25% lower attack success likelihood, and 40% reduction in manual monitoring time.
  • Builds on Cohesity’s partnership with Semperis to unify threat detection, response, and recovery in one platform.

Strengthening Hybrid Identity Security in an Evolving Threat Landscape

Cohesity, the leader in AI-powered data security, announced significant enhancements to its Identity Resilience portfolio through advanced Identity Threat Detection and Response (ITDR) capabilities. These additions deliver a unified, comprehensive approach to securing, protecting, and recovering essential identity systems such as Active Directory (AD) and Microsoft Entra ID.

Identity forms the foundation of enterprise security, controlling all access and enabling operations. Compromises in identity systems can halt business activities and expose sensitive data. Attackers frequently exploit misconfigurations, privilege escalations, and weak controls to infiltrate environments. Cohesity addresses these risks with purpose-built tools that proactively improve security posture, detect and stop identity-based attacks in real time, and enable precise, accelerated recovery.

“Identity is at the heart of cyber resilience. When identity systems are compromised, the impact can be immediate and business-wide,” said Vasu Murthy, chief product officer, Cohesity. “By bringing together threat detection, automated response, and rapid recovery across Active Directory and Entra ID, Cohesity delivers an industry-leading solution with a single, unified view of hybrid identity risk. This enables organizations to reduce risk, stop identity driven attacks faster, and recover with confidence before, during, and after an attack.”

Unified Protection Across Attack Phases

Leveraging the ongoing partnership with Semperis, the expanded ITDR capabilities integrate leading technologies for AD and Entra ID resilience.

Before an attack, Cohesity continuously assesses identity posture, identifies misconfigurations, flags risky changes, and detects early indicators of identity-based attack patterns to reduce the attack surface and expose potential lateral movement in hybrid environments.

During an attack, automated remediation instantly counters malicious changes across AD and Entra ID, performing critical rollback actions without requiring manual intervention. Security teams can create custom rules, alerts, and workflows to interrupt attacker progress effectively.

After an attack, Cohesity streamlines incident response by translating complex identity change data into natural language summaries, supporting rapid investigation, granular search, and object/attribute-level rollback. This enables teams to trace attacker actions, isolate threats, evict intruders, and prevent recurrence through detailed point-in-time forensics.

Key New Capabilities Introduced

The launch includes several targeted enhancements:

  • Vulnerability Assessment: Continuous monitoring for indicators of exposure (IOEs) and compromise (IOCs) in AD and Entra ID, informed by expert threat intelligence.
  • Automatic Rollback: Real-time reversal of malicious or risky identity modifications.
  • Tamperproof Tracking: Immutable logging of changes, resistant to log disabling or bypass attempts.
  • Service Account Protection: Identification and remediation of dormant, misconfigured, or over-privileged service accounts.
  • Entra ID Change Tracking: Near real-time monitoring of role assignments, group memberships, and user attribute updates.
  • Compliance Reporting: Pre-configured templates supporting GDPR, HIPAA, PCI, SOX, and other standards.
  • SIEM/SOAR Integrations: Direct connectivity with Splunk and Microsoft Sentinel to enhance SOC operations.

Demonstrated Impact on Cyber Resilience

These capabilities provide tangible improvements, including 90% faster AD forest recovery, a 25% reduction in successful AD attack likelihood, a 40% decrease in time spent on manual identity monitoring, and significant cost savings through enhanced business continuity and reduced operational overhead.

“What we hear most from customers is how difficult identity incidents are to detect and prevent,” said Justin Hall, vice president of Strategic Partner Growth, Pellera. “Cohesity gives teams innovative solutions to spot risky identity changes early, respond automatically when needed, and cleanly recover their identity systems quickly, helping customers stay operational even in the face of sophisticated attacks.”

The enhanced ITDR features are now available within the Cohesity Identity Resilience offering.

About Cohesity

Cohesity protects, secures, and provides insights into the world’s data. As the leader in AI-powered data security, Cohesity helps organizations strengthen resilience, accelerate recovery, and reduce IT costs. With Zero Trust security and advanced AI/ML, Cohesity Data Cloud is trusted by customers in more than 140 countries, including 70% of the Fortune Global 500. Cohesity is also backed by industry leaders such as NVIDIA, Amazon, Google, IBM, Cisco, and HPE.

  • Identity SecurityCyber ResilienceData SecurityAI Cybersecurity
News Disclaimer
  • Share