CrowdStrike Falcon Identity Protection vs. Identity Rules

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
CrowdStrike Falcon Identity Protection
Score 9.3 out of 10
N/A
CrowdStrike Falcon Identity Protection delivers identity threat detection and response (ITDR) capabilities, protecting organizations from identity-based attacks in real time. It unifies identity and endpoint protection. Falcon® Identity Protection ensures comprehensive visibility and protection across on-premises, cloud, and hybrid identity environments. By baselining normal user behavior, it detects and prevents malicious identity activity, stopping adversaries in their tracks. It also extends…N/A
Identity Rules
Score 0.0 out of 10
N/A
Identity Rules is a unified Identity Threat Detection and Response (ITDR) and Identity Visibility and Intelligence Platform (IVIP) developed for security teams at regulated enterprises. The platform combines real-time detection of identity-based threats with continuous visibility and intelligence across human and non-human identities, spanning Active Directory, Okta, Microsoft Entra ID, AWS IAM, Google Workspace, Oracle Database, and Linux environments. Key…N/A
Pricing
CrowdStrike Falcon Identity ProtectionIdentity Rules
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
CrowdStrike Falcon Identity ProtectionIdentity Rules
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Best Alternatives
CrowdStrike Falcon Identity ProtectionIdentity Rules
Small Businesses

No answers on this topic

No answers on this topic

Medium-sized Companies
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
Enterprises
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
CrowdStrike Falcon Identity ProtectionIdentity Rules
Likelihood to Recommend
9.0
(1 ratings)
-
(0 ratings)
Usability
8.0
(1 ratings)
-
(0 ratings)
User Testimonials
CrowdStrike Falcon Identity ProtectionIdentity Rules
Likelihood to Recommend
CrowdStrike
Identity Protection is well suited for organizations that need to be monitor AD/Entra for suspicious activity. During a Penetration Test our MDR didn't alert on some odd protocol implementations, but ITDR did. It is also simple to setup for MFA on RDP as well. There are other solutions for it, but found I got more out of ITDR than I did from Duo. ITDR is less suited for smaller organizations since it has a 250-seat minimum. They should lower it to at least 100.
Read full review
Identity Rules
No answers on this topic
Pros
CrowdStrike
  • The MFA component has worked great when it comes to privileged accounts accessing RDP.
  • We wanted to stop lateral movement between endpoints and with CrowdStrike Falcon Identity Protection we were able to do that.
  • Identity has done a great job at supplementing our MDR service with telemetry.
Read full review
Identity Rules
No answers on this topic
Cons
CrowdStrike
  • It's not really a fault of the product, but unless you have Falcon installed on all your endpoints your visibility is limited.
  • I've yet to get MFA working on CIFS and Powershell traffic.
  • The interface could be streamlined a little. CrowdStrike Falcon Identity Protection keeps changing where things are.
Read full review
Identity Rules
No answers on this topic
Usability
CrowdStrike
While the product is solid, I do find there are an excessive number of sections you can navigate to. It takes some time getting used to, but it is a very powerful product. It's not something you'll master right off the bat.
Read full review
Identity Rules
No answers on this topic
Alternatives Considered
CrowdStrike
When comparing to Cisco Duo, I felt like the product offered more than just MFA on RDP. When comparing to Silverfort, it came down to pricing. Silverfort was double the cost and I didn't like how Silverfort had separate SKUs. If you wanted MFA on everything the cost increased dramatically.
Read full review
Identity Rules
No answers on this topic
Return on Investment
CrowdStrike
  • Being able to see right away during a Penetration Test that the product detected anomalies, but our MDR service didn't. It allowed us to go back to the MDR service to show them the results and fix the issue from slipping through the cracks.
  • By satisfying the requirements from our insurance provider, our premiums didn't go up (MFA on RDP).
Read full review
Identity Rules
No answers on this topic
ScreenShots

Identity Rules Screenshots

Screenshot of Executive dashboard showing the identity activity funnel — from monitored activities (18) to anomalies detected (4) to active incidents (0) — for a selected date range. Adjacent timeline visualizes incident detection and total AI-driven  analysis events per day, with headline KPIs for active incidents, human vs. non-human identities involved, activities analyzed, and anomalies analyzed.Screenshot of Assets tab of the executive dashboard, delivering a unified inventory of 17 identities, 116 human accounts, 170 non-human identities (NHI), 599 entitlements, and 728 anomalies. Account risk distribution (Critical, High, Medium, Low) sits alongside behavioral anomaly indicators such as "NHI credential never expires" (169) and "NHI credential not rotated" (164), plus account state breakdown between active, locked, deleted, privileged, and shared accounts.Screenshot of Security incident management workspace where SOC and IAM teams triage identity threats across all connected systems. Each incident is displayed with source application (Google Workspace shown here), severity (Critical / High / Medium / Low), lifecycle state (New, In Triage, Closed), 
AI-calculated confidence score, and final verdict — including labels like Token Theft, Lateral Movement, Password Spraying, Legitimate Activity, Business Exception, and Insufficient Evidence.Screenshot of Detailed incident view for a high-severity case: "NHI account without owner and insecure credentials in Google Workspace". The AI Analysis tab maps the finding to MITRE ATT&CK tactic TA0006 (Credential Access) and technique T1556 (Modify Authentication Process) at 80% confidence, showing affected accounts, related activities, and correlated anomalies. An AI-generated Quality Assessment panel surfaces assumptions, evidence gaps, and cross-incident correlations so analysts can act with full context.Screenshot of Analytics view organizing every identity anomaly by MITRE ATT&CK tactic and technique. isplayed here: TA0006 (Credential Access) with 7 detections across 2 techniques, and TA0003 (Persistence) with 2 detections across 2 techniques. The right-hand panel drills into T1556 (Modify uthentication 
Process) showing each individual detection with application, stage, verdict (Legitimate Activity, Business Exception), severity, and affected accounts — giving SOC teams a native ATT&CK-aligned view of their identity attack surface.Screenshot of Interactive graph visualization of account relationships. Central node shows a Linux "root" account on Ubuntu, connected via directional edges to its two entitlements — "root" and "docker" privileged access on Ubuntu Linux. The legend explains node types (accounts, entitlements, child nodes, parent nodes), giving IAM and security teams a visual map of how privileges are structured across systems.