# Which ITDR tools work alongside an existing identity provider rather than requiring a replacement?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Curious how ITDR reviewers and researchers on G2 think about this one.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Most teams already have an IdP in place and don't want an ITDR purchase to turn into a platform migration. Looking at the<a class="a a--md" elv="true" href="https://www.g2.com/categories/identity-threat-detection-and-response-itdr"> </a><a class="a a--md" elv="true" href="https://www.g2.com/categories/identity-threat-detection-and-response-itdr">ITDR</a> category specifically for tools that sit alongside Okta, Entra, or whatever's already running rather than asking you to move onto theirs.</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/saas-alerts/reviews"><strong>SaaS Alerts</strong></a> (4.4/5, 30+ reviews) is built to monitor across Microsoft 365, Google Workspace, Okta, and Duo directly, explicitly as a layer on top rather than a replacement for any of them. Does that layered approach hold up once you're running more than two or three of those in parallel?</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/falcon-identity-protection/reviews"><strong>CrowdStrike Falcon Identity Protection</strong></a> (4.2/5, 15+ reviews) adds risk-based conditional access on top of existing identity infrastructure across hybrid AD and Entra ID environments. One recent review specifically called out strong detection in hybrid setups but wanted deeper identity-specific depth. Does that gap show up for others too?</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/guardz/reviews"><strong>Guardz</strong></a> (4.6/5, 120+ reviews) is built for MSPs running ITDR as one layer of a broader stack rather than standalone identity infrastructure. Reviewers flag limited API support as a friction point, worth asking about if your stack is integration-heavy.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">If you've actually run one of these next to an existing IdP rather than in place of one, did it stay a clean add-on, or did it start pulling you toward replacing pieces of what you already had?</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p>

##### Post Metadata
- Posted at: 15 days ago
- Author title: Tech Consultant
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;ITDR reviews on G2 for the layer-on-top approach, split by how much of the identity stack a tool actually touches. SaaS Alerts monitoring across several major platforms at once and CrowdStrike adding conditional access on top of existing hybrid identity infrastructure are both staying in the same lane as the post&#39;s framing, sitting beside an IdP rather than replacing it, but the more the tool watches, the more its own configuration starts to resemble a second identity layer, even if it isn&#39;t marketed that way. The CrowdStrike reviewer wanting deeper identity-specific depth alongside strong hybrid detection is a fair tension to expect from a tool that added identity protection onto an existing endpoint platform rather than being purpose-built around identity from day one.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;background-color: transparent; color: rgb(0, 0, 0);&quot;&gt;Guardz&#39;s limited API support is worth taking seriously, specifically for an integration-heavy stack, since the whole appeal of running ITDR next to an existing IdP falls apart if the connection between the two ends up being manual work disguised as an integration. The post&#39;s own closing question is the right test, since a tool marketed as an add-on can still start pulling a team toward replacing pieces of the existing setup the moment its own alerts and workflows become the thing people actually check first.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 13 days ago
- Author title: Marketing





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


