Identity Threat Protection (ITP) is a month-to-month Okta add-on available through ZeroTek, a platform for MSPs. ZeroTek is the only provider authorized to sell these Okta SKUs month-to-month, and offers them solely to MSPs, MSSPs, and IT service providers to deploy for their clients. For details, see how month-to-month add-ons work.
Identity Threat Protection (ITP) helps organizations detect and respond to identity-based threats using risk signals, behavioral analysis, and adaptive policy enforcement across Okta authentication flows.
Example scenarios
A user logs in from the US and then attempts another login from Europe 15 minutes later. ITP identifies impossible travel behavior and blocks access pending verification.
A customer requires stronger authentication controls when accessing financial or healthcare systems from unmanaged devices.
A phishing attack leads to credential theft. ITP detects the abnormal behavior and triggers adaptive security controls.
Key use cases
Suspicious login monitoring
Session risk evaluation
Automated respond to compromised accounts
Adaptive MFA enforcement
Identity-driven Zero Trust initiatives
Risk-based authentication
Impossible travel detection
Device trust and security monitoring
Continuous session and policy re-evaluation
Security Event Ingestion and Signal Sharing (SSF/CAEP) - applicable to apps that support SSF. Enhances Zero Trust models where identity providers share real-time security events with applications
Security operations auditing and investigation
Threat detection tuning and analyst feedback
Workflow-driven security automation
Account takeover detection and mitigation
Continuous identity assurance
Real-time risk response and access control
Identity threat detection and response (ITDR) enablement
Compliance and security monitoring
Insider threat and anomalous behavior detection
When to use
The customer is worried about account compromise
The organization is adopting a Zero Trust security model
High-risk users or sensitive applications are in scope
The customer has a remote or hybrid workforce
The security team need better visibility into authentication risk
Why it wins
Enhances traditional MFA with contextual risk analysis
Detects and responds to brute force attacks and session hijacks
Integrates directly with Okta authentication policies
Before you sell
Adaptive MFA should already be in place. (Included in ZeroTek's Okta Pro license.)
Security monitoring processes are recommended,
Policy tuning is required to reduce false positives — plan for an initial calibration period.
Admins should define response strategies for high-risk events before rollout.
Not the right fit for customers without basic MFA in place, or low-risk customers whose threat profile doesn't justify the additional monitoring overhead.
Pricing
Email [email protected] to get started with this add-on, or learn more about how month-to-month add-ons work.
Get add-on
Email [email protected] to get started with this add-on.
