July 22, 2026

Microsoft Defender for Identity - Simply Explained

Microsoft Defender for Identity - Simply Explained
Microsoft Defender for Identity - Simply Explained
M365 FM Podcast
Microsoft Defender for Identity - Simply Explained

Passwords have become the new attack surface. Modern cybercriminals no longer need to bypass firewalls or install malware to compromise an organization—they simply steal legitimate credentials and log in like a trusted user. That's why identity security has become one of the most critical components of modern cybersecurity. In this episode of Microsoft Knowledge Nuggets, we explore Microsoft Defender for Identity, Microsoft's cloud-powered identity threat detection solution, and explain how it protects Active Directory environments against sophisticated identity-based attacks that traditional security tools often miss. WHY IDENTITY HAS BECOME THE NEW SECURITY PERIMETER For years, organizations focused on protecting networks, endpoints, and email. Today, attackers increasingly target identities instead. Compromised credentials obtained through phishing, password reuse, or previous data breaches allow attackers to authenticate as legitimate users without triggering traditional security defenses. Because these attacks use valid usernames and passwords, they often appear completely normal unless organizations continuously monitor authentication behavior and user activity. WHAT MICROSOFT DEFENDER FOR IDENTITY ACTUALLY DOES Microsoft Defender for Identity is a cloud-based identity threat detection solution that monitors on-premises Active Directory environments, including domain controllers and Active Directory Federation Services (ADFS). Rather than searching for malware or suspicious files, Defender for Identity analyzes authentication patterns, user behavior, and network activity to identify attacks such as Pass-the-Hash, Pass-the-Ticket, Kerberoasting, DCSync, Golden Ticket attacks, credential theft, privilege escalation, and lateral movement. By learning what "normal" behavior looks like for every user and device, it can quickly identify suspicious activity that would otherwise remain invisible. HOW BEHAVIORAL ANALYTICS DETECT MODERN ATTACKS Defender for Identity installs lightweight sensors on domain controllers that continuously collect authentication events, Windows security logs, and network traffic. This information is securely analyzed in Microsoft's cloud, where behavioral analytics establish baselines for every account and device. When users suddenly authenticate at unusual times, access unfamiliar systems, or begin performing abnormal administrative actions, Defender generates contextual security alerts that help analysts investigate potential compromises before attackers gain full control of the environment. COMPLETE ATTACK VISIBILITY ACROSS THE ATTACK LIFECYCLE One of Defender for Identity's greatest strengths is its ability to visualize the complete attack lifecycle instead of generating isolated alerts. Security teams can follow attackers from initial reconnaissance and compromised credentials through lateral movement, privilege escalation, and domain dominance using detailed attack timelines and MITRE ATT&CK mappings. Rather than responding to disconnected security events, analysts receive a complete incident story that significantly reduces investigation time and improves incident response. ADVANCED FEATURES INCLUDING HONEYTOKENS AND SENSITIVE ACCOUNT MONITORING The platform also includes advanced capabilities designed for enterprise security operations. Honeytoken accounts help detect attackers attempting to compromise high-value credentials, while entity tagging allows organizations to apply additional monitoring to privileged users, executives, and critical infrastructure. Flexible exclusion rules reduce false positives, allowing security teams to focus on genuine threats while minimizing alert fatigue across large environments. HOW DEFENDER FOR IDENTITY FITS INTO MICROSOFT DEFENDER XDR Microsoft Defender for Identity becomes even more powerful when integrated with the broader Microsoft security ecosystem. It shares intelligence with Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Sentinel, and Microsoft Entra ID Protection through Microsoft Defender XDR. This enables organizations to correlate phishing emails, compromised endpoints, suspicious authentication events, and cloud identity risks into a single incident timeline, giving security teams complete visibility across hybrid environments.

Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

🚀 Want to be part of m365.fm?

Then stop just listening… and start showing up.

👉 Connect with me on LinkedIn and let’s make something happen:

  • 🎙️ Be a podcast guest and share your story
  • 🎧 Host your own episode (yes, seriously)
  • 💡 Pitch topics the community actually wants to hear
  • 🌍 Build your personal brand in the Microsoft 365 space

This isn’t just a podcast — it’s a platform for people who take action.

🔥 Most people wait. The best ones don’t.

👉 Connect with me on LinkedIn and send me a message:
"I want in"

Let’s build something awesome 👊

1
00:00:00,000 --> 00:00:04,560
What happens when an attacker steals a legitimate password instead of breaking in through a firewall?

2
00:00:04,560 --> 00:00:08,880
I'm your host, Mirko Peters, and today we're talking about Microsoft Defender for Identity.

3
00:00:08,880 --> 00:00:11,440
Most security tools focus on the perimeter.

4
00:00:11,440 --> 00:00:14,640
They watch for malware, suspicious files, unusual network traffic,

5
00:00:14,640 --> 00:00:17,360
but identity attacks skip all of that entirely.

6
00:00:17,360 --> 00:00:20,080
An attacker with a stolen password doesn't need to break in.

7
00:00:20,080 --> 00:00:23,040
They just log in, and from the outside everything looks normal.

8
00:00:23,040 --> 00:00:27,520
By the end of this episode, you'll understand what Microsoft Defender for Identity actually is,

9
00:00:27,520 --> 00:00:32,320
why it exists, and how it watches for threats that traditional security tools completely miss.

10
00:00:32,320 --> 00:00:36,080
Let's start with why identity security has become the new battleground.

11
00:00:36,080 --> 00:00:37,760
The identity security problem.

12
00:00:37,760 --> 00:00:40,720
20 years ago, securing a network meant locking down the building,

13
00:00:40,720 --> 00:00:43,600
you set up a firewall, ran antivirus on every machine,

14
00:00:43,600 --> 00:00:45,760
and advised everyone to use strong passwords.

15
00:00:45,760 --> 00:00:49,600
That worked pretty well back then because attackers had to break through your defences to get in.

16
00:00:49,600 --> 00:00:54,080
They needed to find a vulnerability, exploit it, and then move around inside your network.

17
00:00:54,080 --> 00:00:57,040
The perimeter was the wall and the wall was strong, but here's the thing.

18
00:00:57,040 --> 00:00:58,480
That approach doesn't work anymore.

19
00:00:58,480 --> 00:01:00,320
Attackers don't break in, they just log in,

20
00:01:00,320 --> 00:01:02,640
they scoop up a legitimate password through phishing,

21
00:01:02,640 --> 00:01:06,560
a data breach, or a simple guess, and then stroll right through the front door.

22
00:01:06,560 --> 00:01:09,680
Compromised credentials are now behind 79% of ransomware attacks.

23
00:01:09,680 --> 00:01:10,720
That's not a niche problem.

24
00:01:10,720 --> 00:01:12,320
That's the main way attackers get in.

25
00:01:12,320 --> 00:01:13,440
And the numbers are serious.

26
00:01:13,440 --> 00:01:18,560
70% of organizations experienced at least one identity-related security breach in 2025.

27
00:01:18,560 --> 00:01:22,320
The average recovery cost, 1.64 million, that's not just the ransom payment.

28
00:01:22,320 --> 00:01:25,600
It's downtime, forensic investigation, legal fees, regulatory fines,

29
00:01:25,600 --> 00:01:26,960
and reputational damage.

30
00:01:26,960 --> 00:01:31,040
For mid-sized organizations, the median cost is still $750,000.

31
00:01:31,040 --> 00:01:33,440
So this isn't a theoretical risk. It's happening everywhere.

32
00:01:33,440 --> 00:01:35,200
Here's the core problem.

33
00:01:35,200 --> 00:01:40,000
Traditional security tools watch for malware, suspicious files, and unusual network connections.

34
00:01:40,000 --> 00:01:41,760
But they don't understand user behavior.

35
00:01:41,760 --> 00:01:43,840
They don't know if a login is normal or suspicious.

36
00:01:43,840 --> 00:01:47,200
An attacker with a stolen password looks exactly like a legitimate user.

37
00:01:47,200 --> 00:01:50,160
The same username, the same password, the same authentication process.

38
00:01:50,160 --> 00:01:51,680
The only difference is intent.

39
00:01:51,680 --> 00:01:54,480
And unless you're watching for abnormal patterns of behavior,

40
00:01:54,480 --> 00:01:56,160
you won't see it until it's too late.

41
00:01:56,160 --> 00:01:58,880
This is the gap that Defender for Identity was built to fill.

42
00:01:58,880 --> 00:02:00,240
It watches the watches.

43
00:02:00,240 --> 00:02:04,640
It monitors your identity infrastructure, learns what normal looks like for each user and device,

44
00:02:04,640 --> 00:02:06,240
and flags anything that doesn't fit.

45
00:02:06,240 --> 00:02:07,520
It's not looking for malware.

46
00:02:07,520 --> 00:02:09,760
It's looking for behavior that doesn't make sense.

47
00:02:09,760 --> 00:02:11,760
So what exactly is Defender for Identity?

48
00:02:11,760 --> 00:02:12,560
And how does it work?

49
00:02:12,560 --> 00:02:14,800
What is Defender for Identity?

50
00:02:14,800 --> 00:02:16,400
Here's the simplest definition.

51
00:02:16,400 --> 00:02:19,760
Microsoft Defender for Identity is a cloud-based security tool

52
00:02:19,760 --> 00:02:23,360
that watches your on-premises active directory for identity-based attacks.

53
00:02:23,360 --> 00:02:24,560
Notice I didn't say "entry"

54
00:02:24,560 --> 00:02:26,160
that's a common point of confusion.

55
00:02:26,160 --> 00:02:29,760
Defender for Identity focuses on your on-premises identity infrastructure,

56
00:02:29,760 --> 00:02:33,120
including domain controllers, active directory, and ADFS servers.

57
00:02:33,120 --> 00:02:36,240
This is the stuff that lives in your own data center or on your own servers.

58
00:02:36,240 --> 00:02:38,000
It's not a cloud-only solution.

59
00:02:38,000 --> 00:02:38,880
Now, how does it work?

60
00:02:38,880 --> 00:02:40,400
It uses behavioral analytics.

61
00:02:40,400 --> 00:02:43,120
It learns what's normal for each user and each device,

62
00:02:43,120 --> 00:02:44,880
and then it flags anything unusual.

63
00:02:44,880 --> 00:02:48,000
Think of it like a security guard who knows every employee's routine.

64
00:02:48,000 --> 00:02:50,800
They know who comes in at 8am, who works late,

65
00:02:50,800 --> 00:02:52,400
and who accesses the server room.

66
00:02:52,400 --> 00:02:55,280
When someone shows up at 3am trying to open the server room door,

67
00:02:55,280 --> 00:02:57,120
the guard notices immediately.

68
00:02:57,120 --> 00:02:58,960
That's exactly what Defender for Identity does,

69
00:02:58,960 --> 00:03:00,560
but for your digital environment.

70
00:03:00,560 --> 00:03:02,080
Let's clear up what this tool is not.

71
00:03:02,080 --> 00:03:03,200
It's not antivirus.

72
00:03:03,200 --> 00:03:04,160
It's not a firewall.

73
00:03:04,160 --> 00:03:05,760
It's not a patch management solution.

74
00:03:05,760 --> 00:03:09,040
It's identity-threat detection, a completely different category.

75
00:03:09,040 --> 00:03:10,960
It's not looking for malicious files.

76
00:03:10,960 --> 00:03:12,480
It's looking for malicious behavior.

77
00:03:12,480 --> 00:03:15,360
And that distinction matters because the most dangerous attacks today

78
00:03:15,360 --> 00:03:16,400
don't use malware at all.

79
00:03:16,400 --> 00:03:17,840
They use legitimate credentials.

80
00:03:17,840 --> 00:03:20,800
Defender for Identity sits inside Microsoft Defender XDR,

81
00:03:20,800 --> 00:03:23,520
which is Microsoft's extended detection and response platform.

82
00:03:23,520 --> 00:03:25,840
In practice, that means it shares signals

83
00:03:25,840 --> 00:03:28,720
with Defender for Endpoint, Defender for Office 365,

84
00:03:28,720 --> 00:03:29,920
and Microsoft Sentinel.

85
00:03:29,920 --> 00:03:32,720
So when Defender for Identity detects a suspicious login

86
00:03:32,720 --> 00:03:34,000
on a domain controller,

87
00:03:34,000 --> 00:03:38,960
it can cross-reference that with a phishing email detected by Defender for Office 365,

88
00:03:38,960 --> 00:03:42,800
or a suspicious process on a user's laptop detected by Defender for Endpoint.

89
00:03:42,800 --> 00:03:44,480
The real value isn't any single alert.

90
00:03:44,480 --> 00:03:47,840
It's how these tools work together to tell the full story of an attack.

91
00:03:47,840 --> 00:03:50,160
A single alert might look like a false positive,

92
00:03:50,160 --> 00:03:52,960
but when you see the whole picture, including the phishing email,

93
00:03:52,960 --> 00:03:55,360
the compromised credentials and the lateral movement,

94
00:03:55,360 --> 00:03:56,720
you know exactly what happened.

95
00:03:56,720 --> 00:03:59,280
Let's open the hood and look at how it actually detects threats.

96
00:03:59,280 --> 00:04:02,640
How it works, sensors and behavioral analytics.

97
00:04:02,640 --> 00:04:06,640
Defender for Identity uses lightweight sensors installed on your domain controllers.

98
00:04:06,640 --> 00:04:08,240
That's the key piece of the puzzle.

99
00:04:08,240 --> 00:04:09,760
Without the sensor, nothing happens.

100
00:04:09,760 --> 00:04:13,600
The sensor captures the data and is designed to be as unobtrusive as possible,

101
00:04:13,600 --> 00:04:15,120
running quietly in the background,

102
00:04:15,120 --> 00:04:17,120
reading network traffic and Windows events

103
00:04:17,120 --> 00:04:19,120
without slowing down your domain controller.

104
00:04:19,760 --> 00:04:22,800
Think of these sensors as the eyes and ears of the system.

105
00:04:22,800 --> 00:04:24,720
They capture three main types of information,

106
00:04:24,720 --> 00:04:26,720
network traffic to see authentication requests,

107
00:04:26,720 --> 00:04:27,760
flowing between machines,

108
00:04:27,760 --> 00:04:30,400
Windows events to see what's happening at the operating system level,

109
00:04:30,400 --> 00:04:33,760
and authentication activity to see who's logging in from where and when.

110
00:04:33,760 --> 00:04:38,320
All of that data gets sent to the Defender for Identity Cloud Service for Analysis.

111
00:04:38,320 --> 00:04:40,160
The sensor doesn't do the heavy lifting itself,

112
00:04:40,160 --> 00:04:41,440
it just collects and forwards.

113
00:04:41,440 --> 00:04:44,320
Once the data reaches the cloud, the real work begins.

114
00:04:44,320 --> 00:04:48,880
The Cloud Service builds a baseline profile for every single user in your environment.

115
00:04:48,880 --> 00:04:50,800
It learns their typical login times,

116
00:04:50,800 --> 00:04:52,720
which workstations they usually use,

117
00:04:52,720 --> 00:04:54,480
and what resources they normally access.

118
00:04:54,480 --> 00:04:56,160
This is the behavioral analytics part.

119
00:04:56,160 --> 00:04:59,200
The system doesn't come with pre-configured rules about what's normal.

120
00:04:59,200 --> 00:05:00,640
It learns from your actual environment,

121
00:05:00,640 --> 00:05:03,600
and that's important because normal looks different for every organization,

122
00:05:03,600 --> 00:05:05,520
when something deviates from that baseline,

123
00:05:05,520 --> 00:05:06,720
and alert fires.

124
00:05:06,720 --> 00:05:10,160
For example, a user who always logs in from 9 a.m. to 5 p.m.

125
00:05:10,160 --> 00:05:11,760
suddenly authenticates at 3 a.m.

126
00:05:11,760 --> 00:05:13,520
from a workstation they've never used before.

127
00:05:13,520 --> 00:05:14,240
That's a deviation.

128
00:05:14,240 --> 00:05:15,120
The system flags it.

129
00:05:15,120 --> 00:05:16,880
It doesn't assume it's malicious right away,

130
00:05:16,880 --> 00:05:19,840
but it raises the alert so your security team can investigate.

131
00:05:19,840 --> 00:05:21,680
What kinds of attacks does it actually detect?

132
00:05:21,680 --> 00:05:23,520
The list is long, but here are the big ones.

133
00:05:23,520 --> 00:05:24,800
Pass the hash attacks,

134
00:05:24,800 --> 00:05:28,080
where an attacker steals a password hash and uses it to authenticate.

135
00:05:28,080 --> 00:05:29,120
Kerberoasting,

136
00:05:29,120 --> 00:05:31,760
where an attacker requests service tickets for privileged accounts

137
00:05:31,760 --> 00:05:32,960
and cracks them offline.

138
00:05:32,960 --> 00:05:34,160
Golden ticket usage,

139
00:05:34,160 --> 00:05:35,920
where an attacker forges a Kerberoast ticket

140
00:05:35,920 --> 00:05:37,680
to gain domain-wide access.

141
00:05:37,680 --> 00:05:38,880
DC sync attacks,

142
00:05:38,880 --> 00:05:41,280
where an attacker pretends to be a domain controller

143
00:05:41,280 --> 00:05:43,040
and requests password hashes.

144
00:05:43,040 --> 00:05:44,000
And lateral movement,

145
00:05:44,000 --> 00:05:46,320
where an attacker uses one compromised account

146
00:05:46,320 --> 00:05:48,080
to hop from machine to machine.

147
00:05:48,080 --> 00:05:50,560
Each detection is mapped to the Miter attack framework,

148
00:05:50,560 --> 00:05:53,280
which is the industry standard for describing attack techniques.

149
00:05:53,280 --> 00:05:55,520
So when defender for identity flags something,

150
00:05:55,520 --> 00:05:57,760
it doesn't just say suspicious activity.

151
00:05:57,760 --> 00:05:59,920
It says, "This is a pass the hash attack,

152
00:05:59,920 --> 00:06:03,120
mapped to technique T-Fun Feen 50 on 0.0.2."

153
00:06:03,120 --> 00:06:05,280
That gives your security team immediate context

154
00:06:05,280 --> 00:06:07,520
about what they're dealing with and how to respond.

155
00:06:07,520 --> 00:06:08,720
Here's the real difference.

156
00:06:08,720 --> 00:06:10,400
It doesn't just tell you something happened,

157
00:06:10,400 --> 00:06:11,760
it shows you the attack timeline.

158
00:06:11,760 --> 00:06:14,880
It traces how the attacker moved from point A to point B.

159
00:06:14,880 --> 00:06:17,600
So instead of a single alert that says, "Suspicious login,"

160
00:06:17,600 --> 00:06:18,800
you get a full story.

161
00:06:18,800 --> 00:06:20,560
The initial compromise, the lateral movement,

162
00:06:20,560 --> 00:06:22,000
the privilege escalation

163
00:06:22,000 --> 00:06:23,360
and the domain dominance

164
00:06:23,360 --> 00:06:25,520
all connected in a single timeline.

165
00:06:25,520 --> 00:06:27,680
That's the difference between a tool that alerts you

166
00:06:27,680 --> 00:06:29,760
and a tool that helps you understand.

167
00:06:29,760 --> 00:06:31,520
Let's walk through the stages of an attack

168
00:06:31,520 --> 00:06:34,320
and see where defender for identity catches each one.

169
00:06:34,320 --> 00:06:36,240
The attack lifecycle it catches.

170
00:06:36,240 --> 00:06:38,320
So attackers follow a predictable pattern.

171
00:06:38,320 --> 00:06:39,520
It's not random at all.

172
00:06:39,520 --> 00:06:40,560
They go through stages,

173
00:06:40,560 --> 00:06:42,400
and each stage has a specific goal.

174
00:06:42,400 --> 00:06:44,000
The stages are reconnaissance,

175
00:06:44,000 --> 00:06:46,160
compromised credentials, lateral movement,

176
00:06:46,160 --> 00:06:47,360
and domain dominance.

177
00:06:47,360 --> 00:06:48,560
Once you understand these stages,

178
00:06:48,560 --> 00:06:51,280
you'll see exactly where defender for identity fits in.

179
00:06:51,280 --> 00:06:52,880
But what does that actually look like?

180
00:06:52,880 --> 00:06:54,240
Let's start with reconnaissance.

181
00:06:54,240 --> 00:06:55,920
The attacker has no access yet.

182
00:06:55,920 --> 00:06:58,000
They're just looking around, scanning your network,

183
00:06:58,000 --> 00:07:00,560
searching for accounts, groups, and trust relationships.

184
00:07:00,560 --> 00:07:02,640
They're trying to figure out who the administrators are,

185
00:07:02,640 --> 00:07:04,480
which accounts have elevated privileges

186
00:07:04,480 --> 00:07:06,000
and how the domain is structured.

187
00:07:06,000 --> 00:07:07,600
They often use tools like Bloodhound

188
00:07:07,600 --> 00:07:09,120
to map out the environment.

189
00:07:09,120 --> 00:07:10,720
Defender for identity spots this

190
00:07:10,720 --> 00:07:12,960
by watching for suspicious LDP queries

191
00:07:12,960 --> 00:07:14,400
or enumeration attempts.

192
00:07:14,400 --> 00:07:16,320
An alert fires when someone starts querying

193
00:07:16,320 --> 00:07:17,680
for all domain admin accounts

194
00:07:17,680 --> 00:07:19,600
from a workstation that's never done that before.

195
00:07:19,600 --> 00:07:21,280
The attacker hasn't done anything harmful yet,

196
00:07:21,280 --> 00:07:22,480
but you know they're looking.

197
00:07:22,480 --> 00:07:24,080
Next up is compromised credentials.

198
00:07:24,080 --> 00:07:26,320
The attacker has found a way to get a password

199
00:07:26,320 --> 00:07:27,760
through phishing, a data breach,

200
00:07:27,760 --> 00:07:29,440
or buying it on the dark web.

201
00:07:29,440 --> 00:07:32,000
Now they have a legitimate username and password.

202
00:07:32,000 --> 00:07:35,040
Defender for identity flags, unusual logins at this stage.

203
00:07:35,040 --> 00:07:37,280
Unusual logins include a user signing in

204
00:07:37,280 --> 00:07:39,600
from a new location at 3am,

205
00:07:39,600 --> 00:07:41,840
or suddenly accessing hundreds of files

206
00:07:41,840 --> 00:07:43,280
instead of their usual five.

207
00:07:43,280 --> 00:07:44,960
These are behavioral deviations

208
00:07:44,960 --> 00:07:46,960
that don't require malware detection.

209
00:07:46,960 --> 00:07:49,440
They just require understanding what normal looks like.

210
00:07:49,440 --> 00:07:50,640
Then comes lateral movement.

211
00:07:50,640 --> 00:07:51,840
The attacker has a foothold,

212
00:07:51,840 --> 00:07:54,000
but it's probably not a privileged account yet.

213
00:07:54,000 --> 00:07:55,440
They need to move across your network

214
00:07:55,440 --> 00:07:57,040
to reach high-value targets.

215
00:07:57,040 --> 00:07:58,720
They use techniques like Pass the hash,

216
00:07:58,720 --> 00:07:59,440
Pass the ticket,

217
00:07:59,440 --> 00:08:02,080
and overpass the hash to hop from machine to machine.

218
00:08:02,080 --> 00:08:04,000
Each hop looks like a legitimate authentication,

219
00:08:04,000 --> 00:08:05,440
but the pattern is suspicious.

220
00:08:05,440 --> 00:08:06,880
Defender for identity detects this

221
00:08:06,880 --> 00:08:09,040
by watching for authentication anomalies.

222
00:08:09,040 --> 00:08:10,400
If a user account authenticates

223
00:08:10,400 --> 00:08:12,560
from three different workstations in five minutes,

224
00:08:12,560 --> 00:08:14,160
that's not normal human behavior.

225
00:08:14,160 --> 00:08:15,840
That's an attacker moving laterally.

226
00:08:15,840 --> 00:08:17,280
Finally, domain dominance.

227
00:08:17,280 --> 00:08:20,160
What you see, alerts, incidents, and taking action,

228
00:08:20,160 --> 00:08:22,400
open the Microsoft Defender Portal at Security,

229
00:08:22,400 --> 00:08:24,240
Microsoft.com and navigate to identities.

230
00:08:24,240 --> 00:08:25,440
That's your command center.

231
00:08:25,440 --> 00:08:27,520
The first thing you'll see is the dashboard,

232
00:08:27,520 --> 00:08:29,040
which gives you a quick overview

233
00:08:29,040 --> 00:08:31,360
of everything happening in your identity environment.

234
00:08:31,360 --> 00:08:33,040
How many users are being monitored,

235
00:08:33,040 --> 00:08:34,720
how many active alerts are open,

236
00:08:34,720 --> 00:08:37,280
and the health status of your sensors.

237
00:08:37,280 --> 00:08:38,720
It's designed to give you a snapshot

238
00:08:38,720 --> 00:08:40,320
in seconds, not minutes.

239
00:08:40,320 --> 00:08:41,920
There's also a score on that dashboard

240
00:08:41,920 --> 00:08:44,000
called the Identity Security Score.

241
00:08:44,000 --> 00:08:45,520
It's a zero to 100 number that shows

242
00:08:45,520 --> 00:08:47,760
how well you're protecting your identity infrastructure.

243
00:08:47,760 --> 00:08:49,120
This isn't a theoretical metric.

244
00:08:49,120 --> 00:08:51,520
It's based on actual configurations and recommendations.

245
00:08:51,520 --> 00:08:53,360
If you have domain controllers without sensors,

246
00:08:53,360 --> 00:08:54,400
your score drops.

247
00:08:54,400 --> 00:08:56,720
If you have users without multi-factor authentication,

248
00:08:56,720 --> 00:08:57,840
your score drops.

249
00:08:57,840 --> 00:08:58,880
Fix those issues,

250
00:08:58,880 --> 00:09:00,240
and your score goes up.

251
00:09:00,240 --> 00:09:03,200
It's a concrete way to track your security posture over time.

252
00:09:03,200 --> 00:09:04,560
Now, let's talk about alerts.

253
00:09:04,560 --> 00:09:06,880
Alerts are generated by detection rules.

254
00:09:06,880 --> 00:09:07,920
Pre-configured conditions

255
00:09:07,920 --> 00:09:10,240
that define what suspicious behavior looks like.

256
00:09:10,240 --> 00:09:11,680
Based on years of threat research,

257
00:09:11,680 --> 00:09:13,840
Microsoft has built hundreds of these rules.

258
00:09:13,840 --> 00:09:16,240
When a user logs in from an unusual location,

259
00:09:16,240 --> 00:09:17,280
that's a detection rule.

260
00:09:17,280 --> 00:09:18,720
When someone tries a DC sync attack,

261
00:09:18,720 --> 00:09:20,000
that's a detection rule.

262
00:09:20,000 --> 00:09:21,680
When an attacker uses a golden ticket,

263
00:09:21,680 --> 00:09:23,040
that's a detection rule.

264
00:09:23,040 --> 00:09:24,400
The system is constantly comparing

265
00:09:24,400 --> 00:09:26,800
what's happening in your environment against these rules.

266
00:09:26,800 --> 00:09:27,840
But here's the thing,

267
00:09:27,840 --> 00:09:30,720
multiple alerts can combine into a single incident.

268
00:09:30,720 --> 00:09:33,600
That's important because attackers don't do one suspicious thing.

269
00:09:33,600 --> 00:09:35,120
They do many things in sequence.

270
00:09:35,120 --> 00:09:37,200
A single alert might look like a false positive,

271
00:09:37,200 --> 00:09:38,800
but when you see the full incident,

272
00:09:38,800 --> 00:09:40,880
the reconnaissance, the credential compromise,

273
00:09:40,880 --> 00:09:42,880
the lateral movement, the domain dominance,

274
00:09:42,880 --> 00:09:44,240
you know exactly what happened.

275
00:09:44,240 --> 00:09:45,600
The incident is the story.

276
00:09:45,600 --> 00:09:47,520
The alerts are just individual sentences.

277
00:09:47,520 --> 00:09:49,440
Each incident includes an attack graph.

278
00:09:49,440 --> 00:09:51,200
This is a visual map of how the attacker

279
00:09:51,200 --> 00:09:52,640
moved through your environment.

280
00:09:52,640 --> 00:09:54,000
It shows you the starting point,

281
00:09:54,000 --> 00:09:55,120
every hop along the way,

282
00:09:55,120 --> 00:09:56,560
and the final destination.

283
00:09:56,560 --> 00:09:58,240
You can see which accounts were compromised,

284
00:09:58,240 --> 00:09:59,440
which machines were accessed,

285
00:09:59,440 --> 00:10:00,640
and which techniques were used.

286
00:10:00,640 --> 00:10:02,480
It's like watching a security camera replay

287
00:10:02,480 --> 00:10:03,680
of the entire attack,

288
00:10:03,680 --> 00:10:04,880
but in diagram form,

289
00:10:04,880 --> 00:10:07,200
and you can take action directly from the portal.

290
00:10:07,200 --> 00:10:09,440
If you identify a compromised user account,

291
00:10:09,440 --> 00:10:12,080
you don't need to log into your domain controller to disable it.

292
00:10:12,080 --> 00:10:14,080
You can do it right from the Defender portal,

293
00:10:14,080 --> 00:10:15,120
disable the account,

294
00:10:15,120 --> 00:10:16,320
force a password reset,

295
00:10:16,320 --> 00:10:17,760
request a sign in attempt,

296
00:10:17,760 --> 00:10:20,960
the sensor communicates back to your on-premises active directory,

297
00:10:20,960 --> 00:10:22,720
and makes the change instantly.

298
00:10:22,720 --> 00:10:25,360
That's the power of having the sensor on your domain controller.

299
00:10:25,360 --> 00:10:27,040
It's not just listening, it can act.

300
00:10:27,040 --> 00:10:29,280
You can also configure email notifications.

301
00:10:29,280 --> 00:10:30,560
When a critical alert fires,

302
00:10:30,560 --> 00:10:32,720
your security team gets an email instantly.

303
00:10:32,720 --> 00:10:35,200
They don't have to monitor the dashboard 24/7,

304
00:10:35,200 --> 00:10:36,320
the system alerts them.

305
00:10:36,320 --> 00:10:39,440
And because the alerts are mapped to the Miter ATTANK framework,

306
00:10:39,440 --> 00:10:41,680
they know exactly what kind of attack they're dealing with

307
00:10:41,680 --> 00:10:43,680
before they even open the portal.

308
00:10:43,680 --> 00:10:44,640
Beyond the basics,

309
00:10:44,640 --> 00:10:47,360
there are a few advanced features worth knowing about.

310
00:10:47,360 --> 00:10:49,440
Honeypots, tagging, and exclusions.

311
00:10:49,440 --> 00:10:50,800
Let's talk about Honeypots accounts.

312
00:10:50,800 --> 00:10:52,480
These are also called Honey tokens,

313
00:10:52,480 --> 00:10:54,320
and they're exactly what they sound like.

314
00:10:54,320 --> 00:10:55,280
Fake user accounts,

315
00:10:55,280 --> 00:10:57,760
you create specifically to lure attackers.

316
00:10:57,760 --> 00:10:58,880
You give them a tempting name,

317
00:10:58,880 --> 00:11:01,760
like Exchange Admin or Domain Backup Service.

318
00:11:01,760 --> 00:11:04,160
You give them a high-privileged sounding group membership.

319
00:11:04,160 --> 00:11:05,280
But here's the catch.

320
00:11:05,280 --> 00:11:07,040
These accounts have no real use.

321
00:11:07,040 --> 00:11:08,480
Nobody should ever log into them.

322
00:11:08,480 --> 00:11:10,240
They're not used for any legitimate purpose.

323
00:11:10,240 --> 00:11:11,840
They just sit there waiting.

324
00:11:11,840 --> 00:11:13,840
If someone does log into a Honeypot account,

325
00:11:13,840 --> 00:11:15,040
you know immediately.

326
00:11:15,040 --> 00:11:16,720
Not because you set up custom monitoring,

327
00:11:16,720 --> 00:11:18,800
not because you wrote a complex detection rule,

328
00:11:18,800 --> 00:11:21,040
because Defender for Identity knows that account

329
00:11:21,040 --> 00:11:22,240
should never be used.

330
00:11:22,240 --> 00:11:23,840
The moment someone authenticates with it,

331
00:11:23,840 --> 00:11:24,880
an alert fires.

332
00:11:24,880 --> 00:11:26,240
And you know exactly what happened.

333
00:11:26,240 --> 00:11:28,880
An attacker found your decoy account and tried to use it.

334
00:11:28,880 --> 00:11:30,400
That's not a false positive.

335
00:11:30,400 --> 00:11:32,160
That's a confirmed intrusion attempt.

336
00:11:32,160 --> 00:11:33,760
You can set these up in the Defender portal

337
00:11:33,760 --> 00:11:36,000
under settings identities honey tokens.

338
00:11:36,000 --> 00:11:37,680
It takes about 30 seconds.

339
00:11:37,680 --> 00:11:39,360
Entity tagging is another feature.

340
00:11:39,360 --> 00:11:40,960
You can mark specific users,

341
00:11:40,960 --> 00:11:44,160
devices or groups as sensitive for extra monitoring.

342
00:11:44,160 --> 00:11:45,200
Think about what that means.

343
00:11:45,200 --> 00:11:47,520
If you tag a Domain Admin account as sensitive,

344
00:11:47,520 --> 00:11:49,840
Defender for Identity watches every single action

345
00:11:49,840 --> 00:11:51,600
that account takes more closely.

346
00:11:51,600 --> 00:11:53,520
Any deviation from normal behavior

347
00:11:53,520 --> 00:11:55,280
gets flagged with higher priority.

348
00:11:55,280 --> 00:11:57,200
Any lateral movement involving that account

349
00:11:57,200 --> 00:11:58,160
gets escalated,

350
00:11:58,160 --> 00:12:00,960
it's like putting a GPS tracker on your most valuable assets.

351
00:12:00,960 --> 00:12:02,320
And then there are exclusion rules,

352
00:12:02,320 --> 00:12:03,920
sometimes legitimate security tools

353
00:12:03,920 --> 00:12:06,080
or admin processes trigger false alarms.

354
00:12:06,080 --> 00:12:07,920
Your vulnerability scanner might authenticate

355
00:12:07,920 --> 00:12:09,760
against every machine in the network.

356
00:12:09,760 --> 00:12:10,720
That looks suspicious.

357
00:12:10,720 --> 00:12:13,040
Your backup software might access domain controllers

358
00:12:13,040 --> 00:12:14,080
at unusual hours.

359
00:12:14,080 --> 00:12:15,440
That also looks suspicious.

360
00:12:15,440 --> 00:12:17,520
You can exclude specific IP addresses,

361
00:12:17,520 --> 00:12:19,760
devices or users from certain detection rules

362
00:12:19,760 --> 00:12:23,120
so those false positives don't clutter your alert queue.

363
00:12:23,120 --> 00:12:25,760
Global exclusion apply to all detection rules.

364
00:12:25,760 --> 00:12:27,920
Per-rule exclusions are more targeted.

365
00:12:27,920 --> 00:12:28,960
The goal is the same.

366
00:12:28,960 --> 00:12:32,000
Reduce noise so your security team focuses on real threats.

367
00:12:32,320 --> 00:12:34,240
Defender for Identity doesn't work alone.

368
00:12:34,240 --> 00:12:36,480
Let's see how it fits into the bigger picture.

369
00:12:36,480 --> 00:12:39,200
How it fits in Microsoft's security ecosystem.

370
00:12:39,200 --> 00:12:42,160
So how does Defender for Identity fit into Microsoft's

371
00:12:42,160 --> 00:12:43,520
bigger security picture?

372
00:12:43,520 --> 00:12:45,920
Think of it as one piece of the Defender XDR puzzle.

373
00:12:45,920 --> 00:12:47,840
On its own, each tool is useful,

374
00:12:47,840 --> 00:12:50,240
but the real power comes when they work together.

375
00:12:50,240 --> 00:12:52,560
Defender for endpoint guards your devices.

376
00:12:52,560 --> 00:12:54,080
It checks every laptop and server

377
00:12:54,080 --> 00:12:56,320
for malware and suspicious network activity.

378
00:12:56,320 --> 00:12:58,800
Defender for Office 365 protects your email

379
00:12:58,800 --> 00:12:59,840
and collaboration tools,

380
00:12:59,840 --> 00:13:02,080
catching phishing attempts and malicious attachments.

381
00:13:02,080 --> 00:13:05,040
And Defender for Identity, it watches over your user accounts,

382
00:13:05,040 --> 00:13:06,480
looking for stolen credentials,

383
00:13:06,480 --> 00:13:08,240
lateral movement and domain dominance.

384
00:13:08,240 --> 00:13:10,080
On their own, each tool is useful,

385
00:13:10,080 --> 00:13:11,040
but here's the thing.

386
00:13:11,040 --> 00:13:13,920
Together, they share signals and connect the dots.

387
00:13:13,920 --> 00:13:16,720
Imagine a suspicious login on a domain controller.

388
00:13:16,720 --> 00:13:18,880
That same login could be linked to a phishing email

389
00:13:18,880 --> 00:13:21,520
that Defender for Office 365 already caught.

390
00:13:21,520 --> 00:13:23,120
The attacker compromises the mailbox

391
00:13:23,120 --> 00:13:25,040
and is now trying to move laterally.

392
00:13:25,040 --> 00:13:26,720
Defender for Identity sees the login,

393
00:13:26,720 --> 00:13:29,120
Defender for Office 365 sees the email

394
00:13:29,120 --> 00:13:31,520
and the Microsoft Defender XDR platform

395
00:13:31,520 --> 00:13:32,880
creates a single incident.

396
00:13:32,880 --> 00:13:34,720
That's the difference between isolated alerts

397
00:13:34,720 --> 00:13:36,160
and a complete attack story.

398
00:13:36,160 --> 00:13:38,000
It also integrates with Microsoft Sentinel,

399
00:13:38,000 --> 00:13:40,160
which is Microsoft's cloud native CM.

400
00:13:40,160 --> 00:13:41,760
That's where you go for advanced hunting

401
00:13:41,760 --> 00:13:42,960
and custom detections.

402
00:13:42,960 --> 00:13:46,000
You can write custocheries that search across all your defender data,

403
00:13:46,000 --> 00:13:48,640
Identity, endpoint, email, cloud apps,

404
00:13:48,640 --> 00:13:52,000
and find patterns that automated rules don't always catch.

405
00:13:52,000 --> 00:13:54,400
And it works alongside Microsoft EntraID Protection.

406
00:13:54,400 --> 00:13:55,600
Here's the distinction.

407
00:13:55,600 --> 00:13:58,400
EntraID Protection handles cloud-based sign-in risks

408
00:13:58,400 --> 00:14:00,640
like risky sign-ins from anonymous IP addresses

409
00:14:00,640 --> 00:14:01,920
or a typical travel.

410
00:14:01,920 --> 00:14:04,560
Defender for Identity handles on-premises threats

411
00:14:04,560 --> 00:14:06,160
like watching your domain controllers,

412
00:14:06,160 --> 00:14:08,240
active directory and ADFS servers.

413
00:14:08,240 --> 00:14:10,880
Microsoft recommends using both for defense and depth

414
00:14:10,880 --> 00:14:12,240
in hybrid environments.

415
00:14:12,240 --> 00:14:13,920
The magic isn't any single product.

416
00:14:13,920 --> 00:14:16,000
It's how they all talk to each other.

417
00:14:16,000 --> 00:14:18,560
Let's wrap up with what you should do next.

418
00:14:18,560 --> 00:14:19,600
Here's the takeaway.

419
00:14:19,600 --> 00:14:21,600
Defender for Identity fills a gap

420
00:14:21,600 --> 00:14:23,840
that traditional security tools leave open.

421
00:14:23,840 --> 00:14:25,600
It watches for Identity-based attacks

422
00:14:25,600 --> 00:14:26,960
using stolen credentials.

423
00:14:26,960 --> 00:14:28,640
It catches attackers who don't break in.

424
00:14:28,640 --> 00:14:29,520
They log in.

425
00:14:29,520 --> 00:14:31,040
And it's not complicated.

426
00:14:31,040 --> 00:14:32,480
Sensors on your domain controllers

427
00:14:32,480 --> 00:14:34,640
plus behavioral analytics in the cloud

428
00:14:34,640 --> 00:14:36,640
equals real-time threat detection.

429
00:14:36,640 --> 00:14:37,920
The simplest next step?

430
00:14:37,920 --> 00:14:41,600
Check if your domain controllers are running Windows Server 2019 or above.

431
00:14:41,600 --> 00:14:43,520
If they are, you can activate the new sensor

432
00:14:43,520 --> 00:14:44,880
from the Defender portal today.

433
00:14:44,880 --> 00:14:47,040
There's no download, no installation,

434
00:14:47,040 --> 00:14:48,000
just a few clicks.

435
00:14:48,000 --> 00:14:50,000
Subscribe on your favorite podcast platform

436
00:14:50,000 --> 00:14:50,960
and share this with someone

437
00:14:50,960 --> 00:14:53,200
who's starting their Identity Security journey.

438
00:14:53,200 --> 00:14:55,280
And click here for our next episode

439
00:14:55,280 --> 00:14:57,680
on Microsoft, Enter ID Protection,

440
00:14:57,680 --> 00:15:00,480
the Cloud Side Companion to Defender for Identity.