
Falcon Identity Protection
Integration with Entra ID, risk-based authentication
Falcon Identity Protection protects identities against credential-based attacks through deep integration with Microsoft Entra ID, Active Directory, and other identity providers. The system analyzes user behavior in real time, detecting login anomalies, lateral movement, Pass-the-Hash attacks, and Golden Ticket attacks. Risk-based authentication dynamically adjusts authentication requirements based on session context, location, and device posture.
Enterprise-grade protection compliant with regulatory requirements and security standards
Fast deployment with minimal resource overhead
Dedicated support from a certified partner
Easy integration with your existing infrastructure
Key features
- Native integration with Microsoft Entra ID, Active Directory, and Okta/Ping Identity
- Risk-based authentication with dynamic MFA enforcement on anomalies
- Detection of lateral movement, Pass-the-Hash attacks, and Kerberos attacks in real time
- Behavioral analytics with baselining of normal per-user access patterns
- Attack path mapping and identification of excessive privileges in AD
Business benefits
- Reduction of credential attack risk by 95% through behavioral detection
- Detection of account compromise in minutes instead of months of average dwell time
- Adaptive authentication balancing security with user experience
- Full visibility into identity risk with remediation prioritization
- Protection against 80% of attacks using stolen credentials

Why CrowdStrike?
A global leader in endpoint protection and threat intelligence. The Falcon platform uses artificial intelligence and machine learning to detect and stop threats in real time. CrowdStrike offers EDR/XDR, threat hunting, incident response, and one of the best threat intelligence teams in the world.
Need Falcon Identity Protection in your organization?
As a certified CrowdStrike partner, we'll help you deploy and configure the solution.