
Identity & Access Management
Directory Services Protector
Hybrid AD and Entra ID threat detection with tamperproof change tracking and automated rollback.
Directory Services Protector Overview
What it does
Directory Services Protector is an identity threat detection and response (ITDR) product for hybrid Active Directory (AD) and Entra ID environments. Its distinctive mechanism is monitoring the AD replication stream directly, capturing every directory change even when attackers tamper with or bypass security logs. Hundreds of continuously updated indicators of exposure and compromise surface misconfigurations and active attacks, and automated rollback reverses malicious changes to directory objects before they propagate.
How it works
The platform captures changes from the Active Directory (AD) replication stream and Entra ID, evaluates them against hundreds of built-in security indicators maintained by an in-house threat research team, and scores security posture by severity in one dashboard. Attack pattern detection models flag password spray, credential stuffing, brute force, and anomalous activity. Response rules trigger automated actions, including rolling back risky changes, disabling compromised accounts, forcing password resets, and opening ServiceNow tickets, while native connectors forward directory change data and indicator results to SIEM platforms. Service account discovery builds an inventory of non-human identities and monitors them with specialized indicators.
Credentials and traction
Semperis holds ISO 27001 certification and maintains SOC 2 Type II attestation for its cloud-based services. The company is named a Sample Vendor in the identity threat detection and response (ITDR) profile of the 2025 Gartner Hype Cycle for Digital Identity, was named to the 2025 Deloitte Technology Fast 500 for the sixth consecutive year, and surpassed $100 million in annual recurring revenue in January 2025. Published customers include American Airlines, ADP, Temple Health, and Prime Healthcare.
Key Capabilities
mapped to solution categoriesDetects attacks against the IAM infrastructure itself - directories, identity providers, federation, and IAM configurations - including admin credential misuse and manipulation of identity controls.
Executes platform-native response actions to active identity attacks - session revocation, credential reset, account isolation, step-up authentication - automatically or with analyst approval.
Restores the identity environment to a known-good state after an identity attack - directory object and configuration rollback, trust re-establishment, and post-incident hardening of the IAM estate.
Analyzes identity telemetry (authentication events, access patterns, privilege use) in real time with behavioral baselines and risk scoring; leading implementations detect identity attacks in sub-second time.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on July 27, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.