Release Notes
This page contains information about the new developments and improvements made to Imprivata Identity Threat Detection and Response (ITDR). You can also find release notes to previous versions.
The following is generally available to customers who have purchased Advanced Passwordless Access (APA) or Identity Assurance and Threat Detection (IATD).
ITDR now monitors activity from AI agents and can automatically revoke risky access. “Disable Delegated Agent” cuts off an agent acting on behalf of a human user without locking out the user. For non-human identities that authenticate with an API key (including clients, integrations, and standalone agents acting like service accounts), “Disable User” disables the identity holding the key. Note this feature is only available as part of the AIM package.
Customers can now put automated monitoring on agent activity and shut down a risky agent the moment it's detected, with no human in the loop. And because a delegated agent's access is revoked on its own, a compromised agent no longer takes the clinician or admin down with it. Customers can govern agents like any other identity, without losing control as agent use scales.
For more information, see Updated PAS Integration to ITDR.
Every login event now shows the risk decision behind it: which rule fired, what outcome it produced, and the resulting login activity all sit in one event.
Customers now get a clearer view of which rules determined specific login outcomes, confirming rule sets work as intended and making investigations and troubleshooting easier.
Other enhancements and updates for this release are:
-
Standardizing on Device ID: ITDR had two ways to refer to a shared device, Print ID and Device ID. Device ID is now the single source of truth for (shared) device identification.
Latest Releases
Navigate our previous release notes.
The following is generally available to customers who have purchased Advanced Passwordless Access (APA) or Identity Assurance and Threat Detection (IATD).
Building on last month’s release that moved ITDR user + role provisioning to ICP, ITDR added an authorization adapter which allows single sign-on from Imprivata Access Management (“AM portal”) to the ITDR user interface without relying on third party software.
With deeper AM portal integration, ITDR moves closer to a unified Imprivata platform experience where customers can seamlessly access and manage different product lines in one place. This also enables regional expansion and support for APA deals in the European Union.
ITDR Brute Force Threat Detection now uses machine learning to learn each customer tenant’s expected login-attempt patterns and identify unusual spikes in failed logins that may indicate a brute force attack.
Customers can identify brute force attacks based on what is unusual in their own environment, improving threat accuracy and reducing the chance that meaningful attack patterns are missed.
Other enhancements and updates for this release are:
-
SIEM webhook notifications now use compact, single-line JSON for more reliable CrowdStrike ingestion.
-
Microsoft Entra polling and configuration updates are more reliable, reducing duplicate polling and configuration issues.
-
Fixed an issue where ITDR Event Explorer heat maps did not consistently sort attributes by greatest event volume, making investigation views easier to scan and interpret.
-
Fixed an issue where users launching ITDR from AM portal were forced to sign in again when opening additional ITDR views in new tabs.
-
The Verosint Command Line Interface (CLI) will be deprecated and no longer supported as of August 31, 2026. Reach out to the ITDR team with any questions.
The following is generally available to customers who have purchased Advanced Passwordless Access (APA) or Identity Assurance and Threat Detection (IATD).
User access and role provisioning for ITDR is now managed through the customer’s Imprivata Cloud Platform (ICP) tenant. Users can no longer be invited or added to an ITDR workspace directly from the ITDR user interface.
Managing ITDR access through ICP reduces complexity for customers by giving them one fewer place to manage users and roles, so they can focus on the benefits APA and IATD deliver.
For more information, see Managing Workspace Users.
ITDR prevents deletion of rule sets that have been used for risk-based authentication in the last 24 hours. Rule sets with no evaluation calls in the last 24 hours can still be deleted through the existing confirmation flow.
This safeguard helps prevent unintended removal of risk-based authentication protections, keeping bad actors out while allowing trusted users in seamlessly.
For more information, see Rule Sets.
The following is generally available to customers who have purchased Advanced Passwordless Access (APA) or Identity Assurance and Threat Detection (IATD).
ITDR now includes an Audit Logs interface that gives administrators a centralized, chronological view of key activity across the workspace, including what happened, who performed the action, and when it occurred.
For more information, see View Audit Log Activity.
ITDR now includes a Model Context Protocol (MCP) experience that lets users interact with ITDR data through natural-language prompts. Users can ask questions about unusual workspace activity, review findings, and receive recommended next steps, including creating a test rule set based on identified behavior.
The following is generally available to customers who have purchased Advanced Passwordless Access (APA) or Identity Assurance and Threat Detection (IATD).
Introduces SSF support in ITDR, enabling teams to send Security Event Tokens (SETs) from third-party providers into ITDR, where they are surfaced in Event Explorer for centralized investigation. SETs can also drive adaptive authentication and automated response actions. Twosense.ai will be the first supported integration for a mutual EAM customer.
Introduces a new “Remove from List” action for real-time adaptive authentication and automated response, enabling customers to automatically remove users from enforcement lists in response to detections, including security events received via SSF.
Introduces a new History tab on the rule set. This version history provides an audit of changes made to a rule set, including what changed, who made the change, and when it occurred. An AI-generated change summary highlights key differences between versions.
For more information, see Rule Set Version History.
If changes to a rule set result in unexpected behavior or an incident, restore a prior active version in three clicks.
For more information, see Restore a Previous Version of a Rule Set.
Introduces an AI-generated summary highlighting the differences between an active rule set and a test version on the Test Results page.
Rule set evaluations are now available in a new tab on the rule set. Users can view evaluations that occurred against a rule set over the last 30 days without leaving the rule set experience.