
Identity & Access Management
Directory Services Protector
Hybrid AD and Entra ID threat detection with tamperproof change tracking and automated rollback.
Directory Services Protector Overview
What it does
Directory Services Protector is an identity threat detection and response (ITDR) product for hybrid Active Directory (AD) and Entra ID environments. Its distinctive mechanism is monitoring the AD replication stream directly, capturing every directory change even when attackers tamper with or bypass security logs. Hundreds of continuously updated indicators of exposure and compromise surface misconfigurations and active attacks, and automated rollback reverses malicious changes to directory objects before they propagate.
How it works
The platform captures changes from the Active Directory (AD) replication stream and Entra ID, evaluates them against hundreds of built-in security indicators maintained by an in-house threat research team, and scores security posture by severity in one dashboard. Attack pattern detection models flag password spray, credential stuffing, brute force, and anomalous activity. Response rules trigger automated actions, including rolling back risky changes, disabling compromised accounts, forcing password resets, and opening ServiceNow tickets, while native connectors forward directory change data and indicator results to SIEM platforms. Service account discovery builds an inventory of non-human identities and monitors them with specialized indicators.
Credentials and traction
Semperis holds ISO 27001 certification and maintains SOC 2 Type II attestation for its cloud-based services. The company is named a Sample Vendor in the identity threat detection and response (ITDR) profile of the 2025 Gartner Hype Cycle for Digital Identity, was named to the 2025 Deloitte Technology Fast 500 for the sixth consecutive year, and surpassed $100 million in annual recurring revenue in January 2025. Published customers include American Airlines, ADP, Temple Health, and Prime Healthcare.
Key Capabilities
mapped to solution categoriesAnalyzes identity telemetry (authentication events, access patterns, privilege use) in real time with behavioral baselines and risk scoring; leading implementations detect identity attacks in sub-second time.
Executes response actions against active identity attacks through playbooks with configurable automation: session revocation, credential reset, account isolation, inline step-up authentication or access denial at the identity provider, and follow-up policy and configuration hardening so the same attack cannot recur.
Restores the identity environment to a known-good state after an identity attack - directory object and configuration rollback, trust re-establishment, and post-incident hardening of the IAM estate.
Reconstructs an identity incident end to end (authentications, token issuance, MFA events, privilege and group changes, directory and policy modifications) into an identity-centric timeline with blast-radius context, so analysts can scope a compromise and choose the right remediation quickly. Distinct from generic SIEM case management: the pivot is the identity and the IAM objects it touched.
Detects named identity attack techniques with purpose-built detection content: password spraying, credential stuffing, pass-the-hash and pass-the-ticket, Kerberoasting, DCSync and DCShadow, golden and silver tickets, and consent phishing of OAuth applications, each mapped to MITRE ATT&CK so technique coverage can be verified against known identity attack scenarios. Complements Identity Behavioral Analytics (anomaly-based) and Identity Infrastructure Attack Detection (attacks on the IAM control plane).
Detects attacks on the IAM infrastructure itself: misuse of directory and identity provider administrator credentials, changes to token-signing certificates and federation trust, tampering with conditional access, MFA, and admin role configuration, and other signs that an identity tool has been compromised, continuously monitoring root and global administrator accounts and their configuration changes.
Exchanges identity risk signals with identity providers, IGA, PAM, endpoint, and SIEM or SOAR platforms through bidirectional integrations and the Shared Signals Framework (CAEP, RISC), so a detection can revoke a session or force step-up in the identity provider within seconds and lands in the SOC as an enriched, correlated alert instead of a siloed one.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
See how Directory Services Protector fits your stack
Add Directory Services Protector to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.