↻ Updated Daily   |   ◉ Global Edition
Newsletter   Advertise   in   f   ◉

IBM and Microsoft Shift Identity Security From Detection to Action

Key Takeaways

⇨ IBM Consulting has expanded its Identity Threat Detection and Remediation service with Microsoft Security to help organisations move from identifying identity threats to taking controlled action against them.

⇨ The combined approach brings together Microsoft’s security capabilities and IBM’s identity expertise, helping enterprises investigate risks, prioritise responses, and manage remediation across complex environments.

⇨ The partnership highlights the growing importance of managed identity security, combining 24/7 operations, AI-assisted recommendations, human oversight, and compliance-focused governance.

Enterprise security teams are not short of alerts.

The real challenge is understanding which alerts matter, how different signals are connected, and what action should be taken without creating unnecessary disruption to the business.

IBM Consulting is addressing that challenge through an expanded collaboration with Microsoft Security focused on Identity Threat Detection and Remediation, or ITDR.

The service is designed to help organisations move beyond simply detecting suspicious identity activity and toward a more structured process for investigating, prioritising, and responding to threats.

The approach combines Microsoft’s security platform with IBM’s identity management expertise and managed security services.

For large enterprises, this is becoming increasingly important.

Identity has become one of the most critical security layers in the organisation. A compromised account, stolen session, or improperly managed privileged credential can potentially provide attackers with access to multiple systems and sensitive business data.

Microsoft Provides the Security Intelligence Layer

The Microsoft side of the architecture brings together security signals from across the enterprise.

These can include information from Microsoft Entra, Microsoft Defender, Microsoft Purview, Microsoft Intune, and Azure activity logs.

The goal is to create a broader view of security activity rather than investigating identity incidents in isolation.

Microsoft Sentinel and the Sentinel data lake can then be used to analyse and correlate information across identity, endpoints, devices, cloud environments, and data systems.

This matters because modern identity attacks rarely involve a single suspicious event.

A compromised account, for example, may involve unusual sign-in behavior, changes in privileges, suspicious sessions, access to sensitive information, and activity across multiple systems.

Looking at each signal independently can make it difficult for security teams to understand the full picture.

By connecting these signals, organisations can investigate threats in context and compare suspicious activity against both real-time and historical behavior.

What This Means for ERP and Enterprise Leaders

Identity security is now directly connected to business resilience.

ERP systems depend on secure identities, role-based access, privileged accounts, and trusted integrations.

Finance, procurement, supply chain, HR, and other business-critical operations can all be affected if the wrong identity gains access to sensitive systems.

This makes identity security more than a cybersecurity concern. It is also an operational continuity issue.

IBM Focuses on Turning Alerts Into Controlled Remediation

While Microsoft provides much of the detection, correlation, and enforcement infrastructure, IBM’s role is focused on operationalising the response.

The ITDR service is designed to bring identity-related signals together into structured cases and translate technical alerts into information that security and business teams can act on.

IBM can then provide recommendations based on the organisation’s policies and response processes.

Depending on the nature of the threat, remediation actions could include:

  • Revoking active sessions
  • Requiring additional MFA verification
  • Restricting privileged access
  • Rotating compromised credentials
  • Taking other policy-approved actions to contain risk

The important difference is that the goal is not simply to automate every response.

IBM is emphasising governed workflows, human oversight, audit trails, and compliance-focused reporting.

This is particularly important when security actions could affect executives, privileged users, employees, or business-critical systems.

The model allows security teams to maintain oversight before high-impact actions are taken.

What This Means

Security maturity is increasingly about how well organisations respond, not how many threats they detect.

Most large organisations already have tools capable of generating enormous volumes of security alerts.

The bigger challenge is deciding which risks require action and ensuring that those actions are consistent with company policy.

A mature identity security model needs to support the full process:

Detect → Investigate → Prioritise → Approve → Remediate → Document

Organisations that can manage this process effectively will be in a better position to reduce risk without creating unnecessary operational disruption.

Seven Identity Threat Scenarios Highlight the Scope

IBM has identified several major identity threat scenarios that the combined service is designed to address.

These include compromised executive accounts, attacks involving service accounts, insider threats, data exfiltration, MFA fatigue attacks, privilege escalation, shadow administrator activity, token theft, session replay, and coordinated identity attack campaigns.

These scenarios demonstrate how identity threats have become increasingly complex.

Consider a compromised executive account.

The problem may not be visible through one alert alone. Security teams may need to connect unusual login activity with session behavior, access to sensitive data, and changes in account privileges before understanding the full level of risk.

Similarly, an attack involving a service account could require teams to analyse identity activity alongside infrastructure changes and privileged access behavior.

The value of the ITDR approach is therefore in connecting these events and coordinating the response.

What This Means

Identity threats need to be managed as connected scenarios rather than isolated alerts.

Attackers often move across systems, accounts, sessions, and access paths.

Security teams need a way to understand how these events are connected and coordinate a response without relying entirely on manual investigation.

A structured case-management approach can help organisations contain threats more quickly while maintaining the necessary controls and approvals.

Managed Identity Security Is Becoming More Important

One of the biggest parts of IBM’s strategy is the managed service model behind the technology.

Many organisations already own powerful security platforms.

However, having the right technology does not automatically mean having the people, processes, and operational capacity needed to respond effectively around the clock.

Security teams still need:

  • Clear response playbooks
  • Identity expertise
  • Governance processes
  • Compliance controls
  • Continuous monitoring
  • Skilled analysts
  • Documentation and audit trails

IBM is positioning its service as a way to provide these capabilities through 24/7 operations and managed delivery.

AI-assisted remediation can help teams process information and recommend appropriate actions, while human oversight remains important for sensitive or high-impact decisions.

This balance between automation and accountability is likely to become increasingly important.

The Bigger Lesson for Enterprise Security Leaders

The IBM and Microsoft collaboration reflects a broader shift happening across enterprise security.

Organisations are moving beyond the idea that more detection tools automatically lead to better security.

Instead, the focus is shifting toward execution.

Can a company identify an identity threat quickly?

Can it understand the business impact?

Can the right people approve the response?

Can the organisation contain the threat without unnecessarily disrupting critical operations?

And can it prove what happened afterward?

What This Means for Enterprise Leaders

Technology alone does not deliver security outcomes.

Microsoft provides the platform, intelligence, detection, and enforcement capabilities.

IBM adds the operational layer through identity expertise, managed response, remediation playbooks, governance, and continuous delivery.

The combination highlights an important lesson for CIOs, CISOs, and ERP security leaders:

Security tools can identify the problem, but organisations still need the operational capability to solve it.

As identity becomes the gateway to more business-critical systems, the ability to move quickly from a security signal to a controlled and auditable response may become one of the most important measures of enterprise security maturity.

Written by

erp-news