Section 01
Primary read
What ITDR is, what it is not, and how to sequence it alongside IGA + PAM in a program with finite budget.
Read the sourceSection 02
Standards roadmap
CAEP, SSF, and the shared-signals framework are the substrate for ITDR. Microsoft, Okta, and Cisco have shipped publisher implementations; receiver count is still small.
Section 03
Incident analyzed
Midnight Blizzard at Microsoft remains the canonical OAuth consent phishing case. Two years on, the post-mortem still informs response playbooks.
Section 04
Vendor moves
Permiso acquired by Wiz; Authmind raised Series A; Oort renamed to "Cisco Identity Intelligence" post-acquisition.
Section 05
From the practice
OIDC vs SAML in 2026 — when each still wins, and the three legacy patterns you should be retiring.
Read the source