Turn your real-world experience into part of the show.
M365 FM Podcast
M365 FM Podcast
The M365 FM Podcast is your daily destination for everything happening across the Microsoft cloud. We cover the full spectrum of Microsoft 365, including Teams, SharePoint, Exchange, OneDrive, and the tools driving the modern workplace. Each episode delivers practical insights, expert interviews, and hands-on strategies for IT admins, cloud architects, developers, power users, and decision-makers in the Microsoft ecosystem. We explore the latest M365 updates, dive into Power Platform topics like Power Apps, Power Automate, Power BI, Power Pages, and share real-world guidance on automation, digital transformation, and low-code development. You’ll also get deep insights into Azure, including cloud infrastructure, Azure AD / Entra ID, identity, hybrid cloud, and Azure security. The show features focused discussions on Microsoft 365 Security, Defender, compliance, DLP, Zero Trust, and the best practices needed to protect and optimize your environment. We also highlight how AI and Copilot for Microsoft 365 are transforming productivity, collaboration, and automation across the cloud. Whether you want to improve Teams collaboration, strengthen security, enhance cloud architecture, or stay ahead of the latest Microsoft 365, Azure, Power Platform, and AI announcements, The M365 Podcast is your essential guide. M365 FM Podcast is Part of the M365.Show Network.
July 22, 2026

Microsoft Defender for Identity - Simply Explained

Microsoft Defender for Identity - Simply Explained

Quick answer: Microsoft Defender for Identity helps security teams detect suspicious identity activity and investigate attacks that target credentials, privileges, and lateral movement. This episode explains the signals it provides, how it supports investigations, and why identity protection must connect to endpoint and collaboration security.

In today's digital landscape, protecting your identity is crucial. Cyber threats continue to evolve, making it essential to understand how to safeguard your information. Microsoft Defender for Identity - Simply Explained, provides powerful tools to help you detect and respond to identity-related threats. By grasping its features, you can enhance your security measures and stay one step ahead of potential risks.

Key Takeaways

  • Microsoft Defender for Identity protects your organization from identity-related cyber threats.
  • Key features include identity threat detection, anomaly detection, and behavioral analytics.
  • Proactive security assessments help identify vulnerabilities before attackers exploit them.
  • Real-time monitoring allows immediate responses to suspicious activities during authentication.
  • Behavioral insights help detect unusual patterns that may indicate compromised credentials.
  • Automated responses streamline security operations and reduce the workload on your security team.
  • Risk scoring prioritizes incidents based on severity, ensuring critical threats are addressed first.
  • Microsoft Defender for Identity integrates seamlessly with existing security tools for a unified approach.

Microsoft Defender for Identity Overview

Microsoft Defender for Identity Overview

Microsoft Defender for Identity is a vital solution in the realm of cybersecurity. It helps organizations protect their identities from various threats. By understanding its features, you can better safeguard your sensitive information and enhance your overall security posture.

Key Components

Microsoft Defender for Identity consists of several core components that work together to provide comprehensive identity protection. Here’s a brief overview of these components:

Core Component Description
Identity Threat Detection Monitors and analyzes identity environments using behavioral analytics and Active Directory signals.
Anomaly Detection Identifies unusual behavior that may indicate security threats.
Behavioral Analytics Utilizes user behavior patterns to enhance threat detection capabilities.
Integration with Microsoft Defender XDR Provides a unified threat protection platform by integrating identity signals with other security solutions.

These components enable you to detect and respond to identity threats effectively. They leverage advanced technologies to ensure that you remain aware of potential risks.

Proactive Security Assessments

Proactive security assessments are crucial for reducing identity threats. They allow you to identify vulnerabilities before attackers exploit them. For instance, the PROID framework significantly reduces incident detection times and minimizes the impact on your organization. Traditional reactive measures often fall short against sophisticated cyber threats. Therefore, adopting proactive strategies like Threat Hunting and Continuous Monitoring is essential.

The effectiveness of proactive assessments is evident. The PROID framework successfully detected all thirty-one MITRE ATT&CK techniques in a simulated environment. This demonstrates its capability to address various tactics and layers of security. By implementing these assessments, you can enhance your security measures and stay ahead of potential threats.

Identity Threat Detection

Identity Threat Detection

Identity threat detection plays a crucial role in safeguarding your organization from cyber threats. It involves continuously monitoring user activities and analyzing behaviors to identify potential risks. By leveraging advanced technologies, Microsoft Defender for Identity enhances your ability to detect and respond to identity threats effectively.

Real-time Monitoring

Real-time monitoring is a key feature of Microsoft Defender for Identity. It allows you to assess risks during the authentication process. The system evaluates various factors, such as IP address, location, and user agent, to identify potential identity compromises. This proactive approach enables immediate remediation actions. For example, when the system detects anomalous sign-in behavior, it can enforce multifactor authentication to secure accounts.

The benefits of real-time monitoring are significant. Unlike traditional identity and access management (IAM) systems that rely on static rules, Microsoft Defender for Identity provides continuous oversight. This capability allows for immediate responses to potential threats, enhancing your security posture. Here’s a comparison of traditional IAM and identity threat detection and response (ITDR):

Feature Traditional IAM ITDR
Monitoring Static rules Continuous oversight
Response Reactive to issues Immediate response to potential threats
Behavior Analysis Limited to static rules Analyzes behavior patterns
Threat Prevention Mainly reactive Proactively prevents threats
Visibility Limited visibility post-authentication Real-time visibility into identity behaviors

This table illustrates how real-time monitoring improves the detection of identity threats compared to traditional methods. By focusing on ongoing monitoring, you can adapt security measures in real-time, making your organization more resilient against attacks.

Behavioral Insights

Behavioral insights are another critical aspect of identity threat detection. Microsoft Defender for Identity employs behavioral analytics to analyze user activities, group behavior, and network traffic patterns. This analysis helps identify potential security threats that may go unnoticed by traditional security measures.

For instance, the system can detect unusual login patterns that may indicate compromised credentials. These patterns include impossible travel, unusual devices, and abnormal access times. According to the Verizon 2025 Data Breach Investigations Report, 22% of breaches start with compromised credentials. By monitoring user behavior, you can spot deviations that suggest unauthorized access or privilege escalation.

Here are some key behavioral analytics techniques implemented in Microsoft Defender for Identity:

  • The system tracks changes in user group memberships to detect anomalies.
  • It identifies unusual user activity and risky behavior that may indicate insider threats.
  • The system looks for signs of compromised credentials being used to escalate privileges.

By leveraging these behavioral insights, you can enhance your identity threat detection and response capabilities. This proactive approach allows you to address suspicious activity before it escalates into a significant threat.

Anomaly Detection Features

Anomaly detection plays a vital role in identifying unusual patterns that may indicate security threats. Microsoft Defender for Identity employs advanced techniques to monitor user behavior and detect anomalies effectively. This proactive approach helps you stay ahead of potential identity-based attacks.

User Behavior Analytics

User behavior analytics (UBA) is a key feature of Microsoft Defender for Identity. It analyzes user activities to identify deviations from normal behavior. By understanding typical user patterns, the system can flag unusual actions that may suggest a security breach.

For example, if a user logs in from a new location or accesses sensitive data outside of regular hours, the system raises an alert. This capability is crucial because it allows you to respond quickly to potential threats. The anomaly detection system in Microsoft Defender for Identity has demonstrated a true positive rate of approximately 93.7% while maintaining a conservative false positive rate of 1%. This high precision indicates the effectiveness of the system in accurately identifying RDP brute force attacks.

Here’s a comparison of Microsoft Defender for Identity and another tool, Entra ID Protection, regarding their anomaly detection capabilities:

Feature/Tool Microsoft Defender for Identity Entra ID Protection
Primary Focus Detecting threats in Active Directory Access control and authentication risks
Type of Monitoring Network activity for post-authentication attacks Authentication risk assessment
Visibility into Authentication Traffic In-depth visibility Limited visibility

This table highlights how Microsoft Defender for Identity provides comprehensive monitoring, allowing you to detect threats more effectively.

Risk Scoring

Risk scoring is another essential feature that helps prioritize security incidents. Microsoft Defender for Identity uses AI-driven scoring to evaluate the severity of potential threats. This scoring system allows your security operations center (SOC) teams to quickly identify which incidents require immediate attention.

The risk scoring system offers several benefits:

  • Transparent prioritization: It reduces alert fatigue and improves analyst confidence.
  • Faster triage: This leads to quicker containment of high-impact threats across organizations.
  • Evaluation of high-impact signals: It considers factors like attack disruption, threat intelligence context, and alert severity.
  • Color-coded incident scores: Incidents are categorized as Red (high priority), Orange (medium priority), or Gray (low priority) for quick identification.

By implementing risk scoring, you can streamline your response to potential threats. This feature enhances your overall security posture by ensuring that you focus on the most critical incidents first.

Automated Response Capabilities

Microsoft Defender for Identity offers robust automated response capabilities that enhance your organization's ability to manage identity threats effectively. These features streamline security operations and ensure timely responses to potential risks.

Incident Response Automation

Incident response automation is a critical feature of Microsoft Defender for Identity. It helps you determine whether a threat requires action and what steps to take next. The system can:

  1. Assess the severity of the threat.
  2. Recommend necessary remediation actions.
  3. Decide if further investigations are needed.
  4. Repeat the process for other alerts as necessary.

By automating these processes, you reduce the workload on your security team. This efficiency allows analysts to focus on higher-priority tasks while the system handles low-impact responses. For example, when the system detects a potential threat, it can automatically disable compromised accounts and isolate affected systems. This quick action limits potential damage and enhances your overall security posture.

Playbooks and Workflows

Playbooks and workflows play a vital role in streamlining security operations within Microsoft Defender for Identity. These tools help ensure structured responses across various environments. Here are some key benefits:

  • Microsoft Sentinel automation rules facilitate incident handling processes.
  • Automated playbooks, built using Azure Logic Apps, trigger actions based on specific activities.
  • For instance, a playbook can isolate a compromised machine and block a compromised account, improving response times before human intervention.

The integration of playbooks and workflows allows you to respond to security alerts in real-time. This capability is crucial in today's fast-paced digital landscape, where threats can evolve rapidly. By leveraging these automated responses, you enhance your organization's ability to detect and mitigate identity threats effectively.

Automated Response Strategy Effectiveness in Mitigating Identity Threats
Automate Low-Impact Responses Reduces analyst fatigue and improves efficiency by handling low-severity alerts automatically.
Machine Learning Detection Identifies suspicious activity patterns that traditional tools might miss, enhancing detection capabilities.
Automated Incident Response Quickly disables compromised accounts and isolates impacted systems, limiting potential damage.

Automated responses through ITDR systems significantly improve security operations. They enhance detection capabilities and reduce the workload on analysts by automating low-severity alerts. Real-time actions from these automated responses ensure that your organization remains resilient against identity threats.

Practical Use Cases

Case Studies

Microsoft Defender for Identity has proven effective in various real-world scenarios. Here are a few case studies that highlight its capabilities:

  1. Financial Institution: A major bank implemented Microsoft Defender for Identity to protect sensitive customer data. The system detected unusual login attempts from foreign IP addresses. The bank quickly responded by enforcing multifactor authentication, preventing potential breaches.

  2. Healthcare Provider: A large hospital network used Microsoft Defender for Identity to monitor user behavior across its systems. The solution identified a spike in access requests to patient records outside normal hours. The security team investigated and found an insider threat, allowing them to take immediate action.

  3. Retail Company: A national retailer faced challenges with identity theft. By deploying Microsoft Defender for Identity, they gained insights into user behavior. The system flagged unusual transactions, enabling the company to block fraudulent activities before they escalated.

These case studies demonstrate how organizations across different sectors can leverage Microsoft Defender for Identity to enhance their security posture.

Hybrid Environment Applications

In today's digital landscape, many organizations operate in hybrid environments that combine on-premises and cloud solutions. Microsoft Defender for Identity excels in these settings. It integrates on-premises Active Directory signals with cloud capabilities, providing a comprehensive security solution.

This integration offers several advantages:

  • Real-time visibility: You gain insights into user and entity behavior across both environments.
  • Effective detection: The system identifies suspicious activities, allowing you to respond swiftly.
  • Prevention of attacks: By monitoring behaviors, you can stop attackers before they cause harm.

Unlike traditional on-premises solutions, Microsoft Defender for Identity leverages cloud-based technology. This approach makes it highly scalable and frequently updated. Organizations can benefit from enhanced security and visibility, ensuring that they remain protected in a hybrid landscape.

By understanding these practical use cases, you can see how Microsoft Defender for Identity can fit into your organization's security strategy. Whether you are in finance, healthcare, or retail, this solution can help you safeguard your identities effectively.

Benefits of Microsoft Defender for Identity

Microsoft Defender for Identity offers numerous benefits that enhance your organization's security and streamline operations. Understanding these advantages can help you make informed decisions about your identity management strategy.

Enhancing Security Posture

With Microsoft Defender for Identity, you can significantly improve your security posture. This solution provides advanced tools that help you detect and respond to identity threats effectively. Here are some key ways it enhances your security:

  • Proactive Threat Detection: The system continuously monitors user activities and analyzes behaviors. This proactive approach allows you to identify potential threats before they escalate.
  • Real-time Alerts: You receive immediate notifications about suspicious activities. This feature enables you to take swift action, reducing the risk of data breaches.
  • Comprehensive Visibility: Microsoft Defender for Identity integrates signals from both on-premises and cloud environments. This integration gives you a complete view of user behaviors, making it easier to spot anomalies.

By leveraging these features, you can create a robust security framework that protects your organization from identity-related threats.

Streamlining Operations

In addition to enhancing security, Microsoft Defender for Identity streamlines your operations. It automates many processes, allowing your security team to focus on high-priority tasks. Here’s how it helps:

  • Automated Incident Response: The system can automatically respond to low-impact threats. This automation reduces the workload on your security team, allowing them to concentrate on more critical issues.
  • Efficient Risk Management: With risk scoring, you can prioritize incidents based on their severity. This feature helps your team address the most pressing threats first, improving overall efficiency.
  • Integration with Existing Tools: Microsoft Defender for Identity works seamlessly with other security solutions. This integration allows you to create a unified security strategy that enhances your identity management efforts.

By streamlining operations, you can improve your team's efficiency and effectiveness in managing identity threats.


In summary, Microsoft Defender for Identity offers powerful features that enhance your organization's security against identity threats. By leveraging real-time monitoring, anomaly detection, and automated responses, you can effectively protect sensitive information.

Looking ahead, expect to see trends like:

  • AI-Driven Threat Hunting: Tools will analyze patterns to detect threats early.
  • Smarter Automation: Increased automation will handle incidents without human input.
  • Zero Trust Model: This approach will verify device health and user identity before granting access.
  • Integration with Cloud & XDR Platforms: Security will evolve to provide comprehensive protection across various sources.

By staying informed about these advancements, you can strengthen your identity protection strategy.

FAQ

What is Microsoft Defender for Identity?

Microsoft Defender for Identity is a security solution that helps you protect your organization's identities from cyber threats. It uses advanced detection techniques to monitor user behavior and identify potential risks.

How does identity threat detection work?

Identity threat detection continuously monitors user activities and analyzes behaviors. It identifies unusual patterns that may indicate security threats, allowing you to respond quickly to potential risks.

What are behavioral insights?

Behavioral insights refer to the analysis of user behavior patterns. Microsoft Defender for Identity uses these insights to detect anomalies, helping you identify potential identity-based threats before they escalate.

Can Microsoft Defender for Identity integrate with Azure Advanced Threat Protection?

Yes, Microsoft Defender for Identity integrates seamlessly with Azure Advanced Threat Protection. This integration enhances your security posture by providing comprehensive visibility and detection capabilities across your identity environment.

How does real-time monitoring benefit my organization?

Real-time monitoring allows you to assess risks during authentication processes. It enables immediate remediation actions, such as enforcing multifactor authentication, to secure accounts against potential identity compromises.

What is risk scoring in Microsoft Defender for Identity?

Risk scoring evaluates the severity of potential threats using AI-driven metrics. This feature helps you prioritize incidents, ensuring that your security team addresses the most critical threats first.

How can I automate incident responses?

You can automate incident responses through Microsoft Defender for Identity's built-in playbooks and workflows. These tools streamline security operations, allowing your team to focus on high-priority tasks while the system handles low-impact alerts.

Is Microsoft Defender for Identity suitable for hybrid environments?

Yes, Microsoft Defender for Identity is ideal for hybrid environments. It integrates on-premises Active Directory signals with cloud capabilities,


Last reviewed: July 2026.

What You’ll Learn

  • Which identity threats and suspicious behaviours security teams need to investigate.
  • How identity signals improve triage and incident context.
  • Why identity, endpoint, and email controls should be designed as one security operating model.

Who Should Listen

This episode is for Microsoft 365 administrators, security practitioners, IT leaders, and architects who need a practical understanding of Microsoft Defender for Identity before designing, configuring, or operating it.

🎧 You Should Also Listen To

🚀 Want to be part of m365.fm?

Then stop just listening… and start showing up.

👉 Connect with me on LinkedIn and let’s make something happen:

  • 🎙️ Be a podcast guest and share your story
  • 🎧 Host your own episode (yes, seriously)
  • 💡 Pitch topics the community actually wants to hear
  • 🌍 Build your personal brand in the Microsoft 365 space

This isn’t just a podcast — it’s a platform for people who take action.

🔥 Most people wait. The best ones don’t.

👉 Connect with me on LinkedIn and send me a message:
"I want in"

Let’s build something awesome 👊

1
00:00:00,000 --> 00:00:04,560
What happens when an attacker steals a legitimate password instead of breaking in through a firewall?

2
00:00:04,560 --> 00:00:08,880
I'm your host, Mirko Peters, and today we're talking about Microsoft Defender for Identity.

3
00:00:08,880 --> 00:00:11,440
Most security tools focus on the perimeter.

4
00:00:11,440 --> 00:00:14,640
They watch for malware, suspicious files, unusual network traffic,

5
00:00:14,640 --> 00:00:17,360
but identity attacks skip all of that entirely.

6
00:00:17,360 --> 00:00:20,080
An attacker with a stolen password doesn't need to break in.

7
00:00:20,080 --> 00:00:23,040
They just log in, and from the outside everything looks normal.

8
00:00:23,040 --> 00:00:27,520
By the end of this episode, you'll understand what Microsoft Defender for Identity actually is,

9
00:00:27,520 --> 00:00:32,320
why it exists, and how it watches for threats that traditional security tools completely miss.

10
00:00:32,320 --> 00:00:36,080
Let's start with why identity security has become the new battleground.

11
00:00:36,080 --> 00:00:37,760
The identity security problem.

12
00:00:37,760 --> 00:00:40,720
20 years ago, securing a network meant locking down the building,

13
00:00:40,720 --> 00:00:43,600
you set up a firewall, ran antivirus on every machine,

14
00:00:43,600 --> 00:00:45,760
and advised everyone to use strong passwords.

15
00:00:45,760 --> 00:00:49,600
That worked pretty well back then because attackers had to break through your defences to get in.

16
00:00:49,600 --> 00:00:54,080
They needed to find a vulnerability, exploit it, and then move around inside your network.

17
00:00:54,080 --> 00:00:57,040
The perimeter was the wall and the wall was strong, but here's the thing.

18
00:00:57,040 --> 00:00:58,480
That approach doesn't work anymore.

19
00:00:58,480 --> 00:01:00,320
Attackers don't break in, they just log in,

20
00:01:00,320 --> 00:01:02,640
they scoop up a legitimate password through phishing,

21
00:01:02,640 --> 00:01:06,560
a data breach, or a simple guess, and then stroll right through the front door.

22
00:01:06,560 --> 00:01:09,680
Compromised credentials are now behind 79% of ransomware attacks.

23
00:01:09,680 --> 00:01:10,720
That's not a niche problem.

24
00:01:10,720 --> 00:01:12,320
That's the main way attackers get in.

25
00:01:12,320 --> 00:01:13,440
And the numbers are serious.

26
00:01:13,440 --> 00:01:18,560
70% of organizations experienced at least one identity-related security breach in 2025.

27
00:01:18,560 --> 00:01:22,320
The average recovery cost, 1.64 million, that's not just the ransom payment.

28
00:01:22,320 --> 00:01:25,600
It's downtime, forensic investigation, legal fees, regulatory fines,

29
00:01:25,600 --> 00:01:26,960
and reputational damage.

30
00:01:26,960 --> 00:01:31,040
For mid-sized organizations, the median cost is still $750,000.

31
00:01:31,040 --> 00:01:33,440
So this isn't a theoretical risk. It's happening everywhere.

32
00:01:33,440 --> 00:01:35,200
Here's the core problem.

33
00:01:35,200 --> 00:01:40,000
Traditional security tools watch for malware, suspicious files, and unusual network connections.

34
00:01:40,000 --> 00:01:41,760
But they don't understand user behavior.

35
00:01:41,760 --> 00:01:43,840
They don't know if a login is normal or suspicious.

36
00:01:43,840 --> 00:01:47,200
An attacker with a stolen password looks exactly like a legitimate user.

37
00:01:47,200 --> 00:01:50,160
The same username, the same password, the same authentication process.

38
00:01:50,160 --> 00:01:51,680
The only difference is intent.

39
00:01:51,680 --> 00:01:54,480
And unless you're watching for abnormal patterns of behavior,

40
00:01:54,480 --> 00:01:56,160
you won't see it until it's too late.

41
00:01:56,160 --> 00:01:58,880
This is the gap that Defender for Identity was built to fill.

42
00:01:58,880 --> 00:02:00,240
It watches the watches.

43
00:02:00,240 --> 00:02:04,640
It monitors your identity infrastructure, learns what normal looks like for each user and device,

44
00:02:04,640 --> 00:02:06,240
and flags anything that doesn't fit.

45
00:02:06,240 --> 00:02:07,520
It's not looking for malware.

46
00:02:07,520 --> 00:02:09,760
It's looking for behavior that doesn't make sense.

47
00:02:09,760 --> 00:02:11,760
So what exactly is Defender for Identity?

48
00:02:11,760 --> 00:02:12,560
And how does it work?

49
00:02:12,560 --> 00:02:14,800
What is Defender for Identity?

50
00:02:14,800 --> 00:02:16,400
Here's the simplest definition.

51
00:02:16,400 --> 00:02:19,760
Microsoft Defender for Identity is a cloud-based security tool

52
00:02:19,760 --> 00:02:23,360
that watches your on-premises active directory for identity-based attacks.

53
00:02:23,360 --> 00:02:24,560
Notice I didn't say "entry"

54
00:02:24,560 --> 00:02:26,160
that's a common point of confusion.

55
00:02:26,160 --> 00:02:29,760
Defender for Identity focuses on your on-premises identity infrastructure,

56
00:02:29,760 --> 00:02:33,120
including domain controllers, active directory, and ADFS servers.

57
00:02:33,120 --> 00:02:36,240
This is the stuff that lives in your own data center or on your own servers.

58
00:02:36,240 --> 00:02:38,000
It's not a cloud-only solution.

59
00:02:38,000 --> 00:02:38,880
Now, how does it work?

60
00:02:38,880 --> 00:02:40,400
It uses behavioral analytics.

61
00:02:40,400 --> 00:02:43,120
It learns what's normal for each user and each device,

62
00:02:43,120 --> 00:02:44,880
and then it flags anything unusual.

63
00:02:44,880 --> 00:02:48,000
Think of it like a security guard who knows every employee's routine.

64
00:02:48,000 --> 00:02:50,800
They know who comes in at 8am, who works late,

65
00:02:50,800 --> 00:02:52,400
and who accesses the server room.

66
00:02:52,400 --> 00:02:55,280
When someone shows up at 3am trying to open the server room door,

67
00:02:55,280 --> 00:02:57,120
the guard notices immediately.

68
00:02:57,120 --> 00:02:58,960
That's exactly what Defender for Identity does,

69
00:02:58,960 --> 00:03:00,560
but for your digital environment.

70
00:03:00,560 --> 00:03:02,080
Let's clear up what this tool is not.

71
00:03:02,080 --> 00:03:03,200
It's not antivirus.

72
00:03:03,200 --> 00:03:04,160
It's not a firewall.

73
00:03:04,160 --> 00:03:05,760
It's not a patch management solution.

74
00:03:05,760 --> 00:03:09,040
It's identity-threat detection, a completely different category.

75
00:03:09,040 --> 00:03:10,960
It's not looking for malicious files.

76
00:03:10,960 --> 00:03:12,480
It's looking for malicious behavior.

77
00:03:12,480 --> 00:03:15,360
And that distinction matters because the most dangerous attacks today

78
00:03:15,360 --> 00:03:16,400
don't use malware at all.

79
00:03:16,400 --> 00:03:17,840
They use legitimate credentials.

80
00:03:17,840 --> 00:03:20,800
Defender for Identity sits inside Microsoft Defender XDR,

81
00:03:20,800 --> 00:03:23,520
which is Microsoft's extended detection and response platform.

82
00:03:23,520 --> 00:03:25,840
In practice, that means it shares signals

83
00:03:25,840 --> 00:03:28,720
with Defender for Endpoint, Defender for Office 365,

84
00:03:28,720 --> 00:03:29,920
and Microsoft Sentinel.

85
00:03:29,920 --> 00:03:32,720
So when Defender for Identity detects a suspicious login

86
00:03:32,720 --> 00:03:34,000
on a domain controller,

87
00:03:34,000 --> 00:03:38,960
it can cross-reference that with a phishing email detected by Defender for Office 365,

88
00:03:38,960 --> 00:03:42,800
or a suspicious process on a user's laptop detected by Defender for Endpoint.

89
00:03:42,800 --> 00:03:44,480
The real value isn't any single alert.

90
00:03:44,480 --> 00:03:47,840
It's how these tools work together to tell the full story of an attack.

91
00:03:47,840 --> 00:03:50,160
A single alert might look like a false positive,

92
00:03:50,160 --> 00:03:52,960
but when you see the whole picture, including the phishing email,

93
00:03:52,960 --> 00:03:55,360
the compromised credentials and the lateral movement,

94
00:03:55,360 --> 00:03:56,720
you know exactly what happened.

95
00:03:56,720 --> 00:03:59,280
Let's open the hood and look at how it actually detects threats.

96
00:03:59,280 --> 00:04:02,640
How it works, sensors and behavioral analytics.

97
00:04:02,640 --> 00:04:06,640
Defender for Identity uses lightweight sensors installed on your domain controllers.

98
00:04:06,640 --> 00:04:08,240
That's the key piece of the puzzle.

99
00:04:08,240 --> 00:04:09,760
Without the sensor, nothing happens.

100
00:04:09,760 --> 00:04:13,600
The sensor captures the data and is designed to be as unobtrusive as possible,

101
00:04:13,600 --> 00:04:15,120
running quietly in the background,

102
00:04:15,120 --> 00:04:17,120
reading network traffic and Windows events

103
00:04:17,120 --> 00:04:19,120
without slowing down your domain controller.

104
00:04:19,760 --> 00:04:22,800
Think of these sensors as the eyes and ears of the system.

105
00:04:22,800 --> 00:04:24,720
They capture three main types of information,

106
00:04:24,720 --> 00:04:26,720
network traffic to see authentication requests,

107
00:04:26,720 --> 00:04:27,760
flowing between machines,

108
00:04:27,760 --> 00:04:30,400
Windows events to see what's happening at the operating system level,

109
00:04:30,400 --> 00:04:33,760
and authentication activity to see who's logging in from where and when.

110
00:04:33,760 --> 00:04:38,320
All of that data gets sent to the Defender for Identity Cloud Service for Analysis.

111
00:04:38,320 --> 00:04:40,160
The sensor doesn't do the heavy lifting itself,

112
00:04:40,160 --> 00:04:41,440
it just collects and forwards.

113
00:04:41,440 --> 00:04:44,320
Once the data reaches the cloud, the real work begins.

114
00:04:44,320 --> 00:04:48,880
The Cloud Service builds a baseline profile for every single user in your environment.

115
00:04:48,880 --> 00:04:50,800
It learns their typical login times,

116
00:04:50,800 --> 00:04:52,720
which workstations they usually use,

117
00:04:52,720 --> 00:04:54,480
and what resources they normally access.

118
00:04:54,480 --> 00:04:56,160
This is the behavioral analytics part.

119
00:04:56,160 --> 00:04:59,200
The system doesn't come with pre-configured rules about what's normal.

120
00:04:59,200 --> 00:05:00,640
It learns from your actual environment,

121
00:05:00,640 --> 00:05:03,600
and that's important because normal looks different for every organization,

122
00:05:03,600 --> 00:05:05,520
when something deviates from that baseline,

123
00:05:05,520 --> 00:05:06,720
and alert fires.

124
00:05:06,720 --> 00:05:10,160
For example, a user who always logs in from 9 a.m. to 5 p.m.

125
00:05:10,160 --> 00:05:11,760
suddenly authenticates at 3 a.m.

126
00:05:11,760 --> 00:05:13,520
from a workstation they've never used before.

127
00:05:13,520 --> 00:05:14,240
That's a deviation.

128
00:05:14,240 --> 00:05:15,120
The system flags it.

129
00:05:15,120 --> 00:05:16,880
It doesn't assume it's malicious right away,

130
00:05:16,880 --> 00:05:19,840
but it raises the alert so your security team can investigate.

131
00:05:19,840 --> 00:05:21,680
What kinds of attacks does it actually detect?

132
00:05:21,680 --> 00:05:23,520
The list is long, but here are the big ones.

133
00:05:23,520 --> 00:05:24,800
Pass the hash attacks,

134
00:05:24,800 --> 00:05:28,080
where an attacker steals a password hash and uses it to authenticate.

135
00:05:28,080 --> 00:05:29,120
Kerberoasting,

136
00:05:29,120 --> 00:05:31,760
where an attacker requests service tickets for privileged accounts

137
00:05:31,760 --> 00:05:32,960
and cracks them offline.

138
00:05:32,960 --> 00:05:34,160
Golden ticket usage,

139
00:05:34,160 --> 00:05:35,920
where an attacker forges a Kerberoast ticket

140
00:05:35,920 --> 00:05:37,680
to gain domain-wide access.

141
00:05:37,680 --> 00:05:38,880
DC sync attacks,

142
00:05:38,880 --> 00:05:41,280
where an attacker pretends to be a domain controller

143
00:05:41,280 --> 00:05:43,040
and requests password hashes.

144
00:05:43,040 --> 00:05:44,000
And lateral movement,

145
00:05:44,000 --> 00:05:46,320
where an attacker uses one compromised account

146
00:05:46,320 --> 00:05:48,080
to hop from machine to machine.

147
00:05:48,080 --> 00:05:50,560
Each detection is mapped to the Miter attack framework,

148
00:05:50,560 --> 00:05:53,280
which is the industry standard for describing attack techniques.

149
00:05:53,280 --> 00:05:55,520
So when defender for identity flags something,

150
00:05:55,520 --> 00:05:57,760
it doesn't just say suspicious activity.

151
00:05:57,760 --> 00:05:59,920
It says, "This is a pass the hash attack,

152
00:05:59,920 --> 00:06:03,120
mapped to technique T-Fun Feen 50 on 0.0.2."

153
00:06:03,120 --> 00:06:05,280
That gives your security team immediate context

154
00:06:05,280 --> 00:06:07,520
about what they're dealing with and how to respond.

155
00:06:07,520 --> 00:06:08,720
Here's the real difference.

156
00:06:08,720 --> 00:06:10,400
It doesn't just tell you something happened,

157
00:06:10,400 --> 00:06:11,760
it shows you the attack timeline.

158
00:06:11,760 --> 00:06:14,880
It traces how the attacker moved from point A to point B.

159
00:06:14,880 --> 00:06:17,600
So instead of a single alert that says, "Suspicious login,"

160
00:06:17,600 --> 00:06:18,800
you get a full story.

161
00:06:18,800 --> 00:06:20,560
The initial compromise, the lateral movement,

162
00:06:20,560 --> 00:06:22,000
the privilege escalation

163
00:06:22,000 --> 00:06:23,360
and the domain dominance

164
00:06:23,360 --> 00:06:25,520
all connected in a single timeline.

165
00:06:25,520 --> 00:06:27,680
That's the difference between a tool that alerts you

166
00:06:27,680 --> 00:06:29,760
and a tool that helps you understand.

167
00:06:29,760 --> 00:06:31,520
Let's walk through the stages of an attack

168
00:06:31,520 --> 00:06:34,320
and see where defender for identity catches each one.

169
00:06:34,320 --> 00:06:36,240
The attack lifecycle it catches.

170
00:06:36,240 --> 00:06:38,320
So attackers follow a predictable pattern.

171
00:06:38,320 --> 00:06:39,520
It's not random at all.

172
00:06:39,520 --> 00:06:40,560
They go through stages,

173
00:06:40,560 --> 00:06:42,400
and each stage has a specific goal.

174
00:06:42,400 --> 00:06:44,000
The stages are reconnaissance,

175
00:06:44,000 --> 00:06:46,160
compromised credentials, lateral movement,

176
00:06:46,160 --> 00:06:47,360
and domain dominance.

177
00:06:47,360 --> 00:06:48,560
Once you understand these stages,

178
00:06:48,560 --> 00:06:51,280
you'll see exactly where defender for identity fits in.

179
00:06:51,280 --> 00:06:52,880
But what does that actually look like?

180
00:06:52,880 --> 00:06:54,240
Let's start with reconnaissance.

181
00:06:54,240 --> 00:06:55,920
The attacker has no access yet.

182
00:06:55,920 --> 00:06:58,000
They're just looking around, scanning your network,

183
00:06:58,000 --> 00:07:00,560
searching for accounts, groups, and trust relationships.

184
00:07:00,560 --> 00:07:02,640
They're trying to figure out who the administrators are,

185
00:07:02,640 --> 00:07:04,480
which accounts have elevated privileges

186
00:07:04,480 --> 00:07:06,000
and how the domain is structured.

187
00:07:06,000 --> 00:07:07,600
They often use tools like Bloodhound

188
00:07:07,600 --> 00:07:09,120
to map out the environment.

189
00:07:09,120 --> 00:07:10,720
Defender for identity spots this

190
00:07:10,720 --> 00:07:12,960
by watching for suspicious LDP queries

191
00:07:12,960 --> 00:07:14,400
or enumeration attempts.

192
00:07:14,400 --> 00:07:16,320
An alert fires when someone starts querying

193
00:07:16,320 --> 00:07:17,680
for all domain admin accounts

194
00:07:17,680 --> 00:07:19,600
from a workstation that's never done that before.

195
00:07:19,600 --> 00:07:21,280
The attacker hasn't done anything harmful yet,

196
00:07:21,280 --> 00:07:22,480
but you know they're looking.

197
00:07:22,480 --> 00:07:24,080
Next up is compromised credentials.

198
00:07:24,080 --> 00:07:26,320
The attacker has found a way to get a password

199
00:07:26,320 --> 00:07:27,760
through phishing, a data breach,

200
00:07:27,760 --> 00:07:29,440
or buying it on the dark web.

201
00:07:29,440 --> 00:07:32,000
Now they have a legitimate username and password.

202
00:07:32,000 --> 00:07:35,040
Defender for identity flags, unusual logins at this stage.

203
00:07:35,040 --> 00:07:37,280
Unusual logins include a user signing in

204
00:07:37,280 --> 00:07:39,600
from a new location at 3am,

205
00:07:39,600 --> 00:07:41,840
or suddenly accessing hundreds of files

206
00:07:41,840 --> 00:07:43,280
instead of their usual five.

207
00:07:43,280 --> 00:07:44,960
These are behavioral deviations

208
00:07:44,960 --> 00:07:46,960
that don't require malware detection.

209
00:07:46,960 --> 00:07:49,440
They just require understanding what normal looks like.

210
00:07:49,440 --> 00:07:50,640
Then comes lateral movement.

211
00:07:50,640 --> 00:07:51,840
The attacker has a foothold,

212
00:07:51,840 --> 00:07:54,000
but it's probably not a privileged account yet.

213
00:07:54,000 --> 00:07:55,440
They need to move across your network

214
00:07:55,440 --> 00:07:57,040
to reach high-value targets.

215
00:07:57,040 --> 00:07:58,720
They use techniques like Pass the hash,

216
00:07:58,720 --> 00:07:59,440
Pass the ticket,

217
00:07:59,440 --> 00:08:02,080
and overpass the hash to hop from machine to machine.

218
00:08:02,080 --> 00:08:04,000
Each hop looks like a legitimate authentication,

219
00:08:04,000 --> 00:08:05,440
but the pattern is suspicious.

220
00:08:05,440 --> 00:08:06,880
Defender for identity detects this

221
00:08:06,880 --> 00:08:09,040
by watching for authentication anomalies.

222
00:08:09,040 --> 00:08:10,400
If a user account authenticates

223
00:08:10,400 --> 00:08:12,560
from three different workstations in five minutes,

224
00:08:12,560 --> 00:08:14,160
that's not normal human behavior.

225
00:08:14,160 --> 00:08:15,840
That's an attacker moving laterally.

226
00:08:15,840 --> 00:08:17,280
Finally, domain dominance.

227
00:08:17,280 --> 00:08:20,160
What you see, alerts, incidents, and taking action,

228
00:08:20,160 --> 00:08:22,400
open the Microsoft Defender Portal at Security,

229
00:08:22,400 --> 00:08:24,240
Microsoft.com and navigate to identities.

230
00:08:24,240 --> 00:08:25,440
That's your command center.

231
00:08:25,440 --> 00:08:27,520
The first thing you'll see is the dashboard,

232
00:08:27,520 --> 00:08:29,040
which gives you a quick overview

233
00:08:29,040 --> 00:08:31,360
of everything happening in your identity environment.

234
00:08:31,360 --> 00:08:33,040
How many users are being monitored,

235
00:08:33,040 --> 00:08:34,720
how many active alerts are open,

236
00:08:34,720 --> 00:08:37,280
and the health status of your sensors.

237
00:08:37,280 --> 00:08:38,720
It's designed to give you a snapshot

238
00:08:38,720 --> 00:08:40,320
in seconds, not minutes.

239
00:08:40,320 --> 00:08:41,920
There's also a score on that dashboard

240
00:08:41,920 --> 00:08:44,000
called the Identity Security Score.

241
00:08:44,000 --> 00:08:45,520
It's a zero to 100 number that shows

242
00:08:45,520 --> 00:08:47,760
how well you're protecting your identity infrastructure.

243
00:08:47,760 --> 00:08:49,120
This isn't a theoretical metric.

244
00:08:49,120 --> 00:08:51,520
It's based on actual configurations and recommendations.

245
00:08:51,520 --> 00:08:53,360
If you have domain controllers without sensors,

246
00:08:53,360 --> 00:08:54,400
your score drops.

247
00:08:54,400 --> 00:08:56,720
If you have users without multi-factor authentication,

248
00:08:56,720 --> 00:08:57,840
your score drops.

249
00:08:57,840 --> 00:08:58,880
Fix those issues,

250
00:08:58,880 --> 00:09:00,240
and your score goes up.

251
00:09:00,240 --> 00:09:03,200
It's a concrete way to track your security posture over time.

252
00:09:03,200 --> 00:09:04,560
Now, let's talk about alerts.

253
00:09:04,560 --> 00:09:06,880
Alerts are generated by detection rules.

254
00:09:06,880 --> 00:09:07,920
Pre-configured conditions

255
00:09:07,920 --> 00:09:10,240
that define what suspicious behavior looks like.

256
00:09:10,240 --> 00:09:11,680
Based on years of threat research,

257
00:09:11,680 --> 00:09:13,840
Microsoft has built hundreds of these rules.

258
00:09:13,840 --> 00:09:16,240
When a user logs in from an unusual location,

259
00:09:16,240 --> 00:09:17,280
that's a detection rule.

260
00:09:17,280 --> 00:09:18,720
When someone tries a DC sync attack,

261
00:09:18,720 --> 00:09:20,000
that's a detection rule.

262
00:09:20,000 --> 00:09:21,680
When an attacker uses a golden ticket,

263
00:09:21,680 --> 00:09:23,040
that's a detection rule.

264
00:09:23,040 --> 00:09:24,400
The system is constantly comparing

265
00:09:24,400 --> 00:09:26,800
what's happening in your environment against these rules.

266
00:09:26,800 --> 00:09:27,840
But here's the thing,

267
00:09:27,840 --> 00:09:30,720
multiple alerts can combine into a single incident.

268
00:09:30,720 --> 00:09:33,600
That's important because attackers don't do one suspicious thing.

269
00:09:33,600 --> 00:09:35,120
They do many things in sequence.

270
00:09:35,120 --> 00:09:37,200
A single alert might look like a false positive,

271
00:09:37,200 --> 00:09:38,800
but when you see the full incident,

272
00:09:38,800 --> 00:09:40,880
the reconnaissance, the credential compromise,

273
00:09:40,880 --> 00:09:42,880
the lateral movement, the domain dominance,

274
00:09:42,880 --> 00:09:44,240
you know exactly what happened.

275
00:09:44,240 --> 00:09:45,600
The incident is the story.

276
00:09:45,600 --> 00:09:47,520
The alerts are just individual sentences.

277
00:09:47,520 --> 00:09:49,440
Each incident includes an attack graph.

278
00:09:49,440 --> 00:09:51,200
This is a visual map of how the attacker

279
00:09:51,200 --> 00:09:52,640
moved through your environment.

280
00:09:52,640 --> 00:09:54,000
It shows you the starting point,

281
00:09:54,000 --> 00:09:55,120
every hop along the way,

282
00:09:55,120 --> 00:09:56,560
and the final destination.

283
00:09:56,560 --> 00:09:58,240
You can see which accounts were compromised,

284
00:09:58,240 --> 00:09:59,440
which machines were accessed,

285
00:09:59,440 --> 00:10:00,640
and which techniques were used.

286
00:10:00,640 --> 00:10:02,480
It's like watching a security camera replay

287
00:10:02,480 --> 00:10:03,680
of the entire attack,

288
00:10:03,680 --> 00:10:04,880
but in diagram form,

289
00:10:04,880 --> 00:10:07,200
and you can take action directly from the portal.

290
00:10:07,200 --> 00:10:09,440
If you identify a compromised user account,

291
00:10:09,440 --> 00:10:12,080
you don't need to log into your domain controller to disable it.

292
00:10:12,080 --> 00:10:14,080
You can do it right from the Defender portal,

293
00:10:14,080 --> 00:10:15,120
disable the account,

294
00:10:15,120 --> 00:10:16,320
force a password reset,

295
00:10:16,320 --> 00:10:17,760
request a sign in attempt,

296
00:10:17,760 --> 00:10:20,960
the sensor communicates back to your on-premises active directory,

297
00:10:20,960 --> 00:10:22,720
and makes the change instantly.

298
00:10:22,720 --> 00:10:25,360
That's the power of having the sensor on your domain controller.

299
00:10:25,360 --> 00:10:27,040
It's not just listening, it can act.

300
00:10:27,040 --> 00:10:29,280
You can also configure email notifications.

301
00:10:29,280 --> 00:10:30,560
When a critical alert fires,

302
00:10:30,560 --> 00:10:32,720
your security team gets an email instantly.

303
00:10:32,720 --> 00:10:35,200
They don't have to monitor the dashboard 24/7,

304
00:10:35,200 --> 00:10:36,320
the system alerts them.

305
00:10:36,320 --> 00:10:39,440
And because the alerts are mapped to the Miter ATTANK framework,

306
00:10:39,440 --> 00:10:41,680
they know exactly what kind of attack they're dealing with

307
00:10:41,680 --> 00:10:43,680
before they even open the portal.

308
00:10:43,680 --> 00:10:44,640
Beyond the basics,

309
00:10:44,640 --> 00:10:47,360
there are a few advanced features worth knowing about.

310
00:10:47,360 --> 00:10:49,440
Honeypots, tagging, and exclusions.

311
00:10:49,440 --> 00:10:50,800
Let's talk about Honeypots accounts.

312
00:10:50,800 --> 00:10:52,480
These are also called Honey tokens,

313
00:10:52,480 --> 00:10:54,320
and they're exactly what they sound like.

314
00:10:54,320 --> 00:10:55,280
Fake user accounts,

315
00:10:55,280 --> 00:10:57,760
you create specifically to lure attackers.

316
00:10:57,760 --> 00:10:58,880
You give them a tempting name,

317
00:10:58,880 --> 00:11:01,760
like Exchange Admin or Domain Backup Service.

318
00:11:01,760 --> 00:11:04,160
You give them a high-privileged sounding group membership.

319
00:11:04,160 --> 00:11:05,280
But here's the catch.

320
00:11:05,280 --> 00:11:07,040
These accounts have no real use.

321
00:11:07,040 --> 00:11:08,480
Nobody should ever log into them.

322
00:11:08,480 --> 00:11:10,240
They're not used for any legitimate purpose.

323
00:11:10,240 --> 00:11:11,840
They just sit there waiting.

324
00:11:11,840 --> 00:11:13,840
If someone does log into a Honeypot account,

325
00:11:13,840 --> 00:11:15,040
you know immediately.

326
00:11:15,040 --> 00:11:16,720
Not because you set up custom monitoring,

327
00:11:16,720 --> 00:11:18,800
not because you wrote a complex detection rule,

328
00:11:18,800 --> 00:11:21,040
because Defender for Identity knows that account

329
00:11:21,040 --> 00:11:22,240
should never be used.

330
00:11:22,240 --> 00:11:23,840
The moment someone authenticates with it,

331
00:11:23,840 --> 00:11:24,880
an alert fires.

332
00:11:24,880 --> 00:11:26,240
And you know exactly what happened.

333
00:11:26,240 --> 00:11:28,880
An attacker found your decoy account and tried to use it.

334
00:11:28,880 --> 00:11:30,400
That's not a false positive.

335
00:11:30,400 --> 00:11:32,160
That's a confirmed intrusion attempt.

336
00:11:32,160 --> 00:11:33,760
You can set these up in the Defender portal

337
00:11:33,760 --> 00:11:36,000
under settings identities honey tokens.

338
00:11:36,000 --> 00:11:37,680
It takes about 30 seconds.

339
00:11:37,680 --> 00:11:39,360
Entity tagging is another feature.

340
00:11:39,360 --> 00:11:40,960
You can mark specific users,

341
00:11:40,960 --> 00:11:44,160
devices or groups as sensitive for extra monitoring.

342
00:11:44,160 --> 00:11:45,200
Think about what that means.

343
00:11:45,200 --> 00:11:47,520
If you tag a Domain Admin account as sensitive,

344
00:11:47,520 --> 00:11:49,840
Defender for Identity watches every single action

345
00:11:49,840 --> 00:11:51,600
that account takes more closely.

346
00:11:51,600 --> 00:11:53,520
Any deviation from normal behavior

347
00:11:53,520 --> 00:11:55,280
gets flagged with higher priority.

348
00:11:55,280 --> 00:11:57,200
Any lateral movement involving that account

349
00:11:57,200 --> 00:11:58,160
gets escalated,

350
00:11:58,160 --> 00:12:00,960
it's like putting a GPS tracker on your most valuable assets.

351
00:12:00,960 --> 00:12:02,320
And then there are exclusion rules,

352
00:12:02,320 --> 00:12:03,920
sometimes legitimate security tools

353
00:12:03,920 --> 00:12:06,080
or admin processes trigger false alarms.

354
00:12:06,080 --> 00:12:07,920
Your vulnerability scanner might authenticate

355
00:12:07,920 --> 00:12:09,760
against every machine in the network.

356
00:12:09,760 --> 00:12:10,720
That looks suspicious.

357
00:12:10,720 --> 00:12:13,040
Your backup software might access domain controllers

358
00:12:13,040 --> 00:12:14,080
at unusual hours.

359
00:12:14,080 --> 00:12:15,440
That also looks suspicious.

360
00:12:15,440 --> 00:12:17,520
You can exclude specific IP addresses,

361
00:12:17,520 --> 00:12:19,760
devices or users from certain detection rules

362
00:12:19,760 --> 00:12:23,120
so those false positives don't clutter your alert queue.

363
00:12:23,120 --> 00:12:25,760
Global exclusion apply to all detection rules.

364
00:12:25,760 --> 00:12:27,920
Per-rule exclusions are more targeted.

365
00:12:27,920 --> 00:12:28,960
The goal is the same.

366
00:12:28,960 --> 00:12:32,000
Reduce noise so your security team focuses on real threats.

367
00:12:32,320 --> 00:12:34,240
Defender for Identity doesn't work alone.

368
00:12:34,240 --> 00:12:36,480
Let's see how it fits into the bigger picture.

369
00:12:36,480 --> 00:12:39,200
How it fits in Microsoft's security ecosystem.

370
00:12:39,200 --> 00:12:42,160
So how does Defender for Identity fit into Microsoft's

371
00:12:42,160 --> 00:12:43,520
bigger security picture?

372
00:12:43,520 --> 00:12:45,920
Think of it as one piece of the Defender XDR puzzle.

373
00:12:45,920 --> 00:12:47,840
On its own, each tool is useful,

374
00:12:47,840 --> 00:12:50,240
but the real power comes when they work together.

375
00:12:50,240 --> 00:12:52,560
Defender for endpoint guards your devices.

376
00:12:52,560 --> 00:12:54,080
It checks every laptop and server

377
00:12:54,080 --> 00:12:56,320
for malware and suspicious network activity.

378
00:12:56,320 --> 00:12:58,800
Defender for Office 365 protects your email

379
00:12:58,800 --> 00:12:59,840
and collaboration tools,

380
00:12:59,840 --> 00:13:02,080
catching phishing attempts and malicious attachments.

381
00:13:02,080 --> 00:13:05,040
And Defender for Identity, it watches over your user accounts,

382
00:13:05,040 --> 00:13:06,480
looking for stolen credentials,

383
00:13:06,480 --> 00:13:08,240
lateral movement and domain dominance.

384
00:13:08,240 --> 00:13:10,080
On their own, each tool is useful,

385
00:13:10,080 --> 00:13:11,040
but here's the thing.

386
00:13:11,040 --> 00:13:13,920
Together, they share signals and connect the dots.

387
00:13:13,920 --> 00:13:16,720
Imagine a suspicious login on a domain controller.

388
00:13:16,720 --> 00:13:18,880
That same login could be linked to a phishing email

389
00:13:18,880 --> 00:13:21,520
that Defender for Office 365 already caught.

390
00:13:21,520 --> 00:13:23,120
The attacker compromises the mailbox

391
00:13:23,120 --> 00:13:25,040
and is now trying to move laterally.

392
00:13:25,040 --> 00:13:26,720
Defender for Identity sees the login,

393
00:13:26,720 --> 00:13:29,120
Defender for Office 365 sees the email

394
00:13:29,120 --> 00:13:31,520
and the Microsoft Defender XDR platform

395
00:13:31,520 --> 00:13:32,880
creates a single incident.

396
00:13:32,880 --> 00:13:34,720
That's the difference between isolated alerts

397
00:13:34,720 --> 00:13:36,160
and a complete attack story.

398
00:13:36,160 --> 00:13:38,000
It also integrates with Microsoft Sentinel,

399
00:13:38,000 --> 00:13:40,160
which is Microsoft's cloud native CM.

400
00:13:40,160 --> 00:13:41,760
That's where you go for advanced hunting

401
00:13:41,760 --> 00:13:42,960
and custom detections.

402
00:13:42,960 --> 00:13:46,000
You can write custocheries that search across all your defender data,

403
00:13:46,000 --> 00:13:48,640
Identity, endpoint, email, cloud apps,

404
00:13:48,640 --> 00:13:52,000
and find patterns that automated rules don't always catch.

405
00:13:52,000 --> 00:13:54,400
And it works alongside Microsoft EntraID Protection.

406
00:13:54,400 --> 00:13:55,600
Here's the distinction.

407
00:13:55,600 --> 00:13:58,400
EntraID Protection handles cloud-based sign-in risks

408
00:13:58,400 --> 00:14:00,640
like risky sign-ins from anonymous IP addresses

409
00:14:00,640 --> 00:14:01,920
or a typical travel.

410
00:14:01,920 --> 00:14:04,560
Defender for Identity handles on-premises threats

411
00:14:04,560 --> 00:14:06,160
like watching your domain controllers,

412
00:14:06,160 --> 00:14:08,240
active directory and ADFS servers.

413
00:14:08,240 --> 00:14:10,880
Microsoft recommends using both for defense and depth

414
00:14:10,880 --> 00:14:12,240
in hybrid environments.

415
00:14:12,240 --> 00:14:13,920
The magic isn't any single product.

416
00:14:13,920 --> 00:14:16,000
It's how they all talk to each other.

417
00:14:16,000 --> 00:14:18,560
Let's wrap up with what you should do next.

418
00:14:18,560 --> 00:14:19,600
Here's the takeaway.

419
00:14:19,600 --> 00:14:21,600
Defender for Identity fills a gap

420
00:14:21,600 --> 00:14:23,840
that traditional security tools leave open.

421
00:14:23,840 --> 00:14:25,600
It watches for Identity-based attacks

422
00:14:25,600 --> 00:14:26,960
using stolen credentials.

423
00:14:26,960 --> 00:14:28,640
It catches attackers who don't break in.

424
00:14:28,640 --> 00:14:29,520
They log in.

425
00:14:29,520 --> 00:14:31,040
And it's not complicated.

426
00:14:31,040 --> 00:14:32,480
Sensors on your domain controllers

427
00:14:32,480 --> 00:14:34,640
plus behavioral analytics in the cloud

428
00:14:34,640 --> 00:14:36,640
equals real-time threat detection.

429
00:14:36,640 --> 00:14:37,920
The simplest next step?

430
00:14:37,920 --> 00:14:41,600
Check if your domain controllers are running Windows Server 2019 or above.

431
00:14:41,600 --> 00:14:43,520
If they are, you can activate the new sensor

432
00:14:43,520 --> 00:14:44,880
from the Defender portal today.

433
00:14:44,880 --> 00:14:47,040
There's no download, no installation,

434
00:14:47,040 --> 00:14:48,000
just a few clicks.

435
00:14:48,000 --> 00:14:50,000
Subscribe on your favorite podcast platform

436
00:14:50,000 --> 00:14:50,960
and share this with someone

437
00:14:50,960 --> 00:14:53,200
who's starting their Identity Security journey.

438
00:14:53,200 --> 00:14:55,280
And click here for our next episode

439
00:14:55,280 --> 00:14:57,680
on Microsoft, Enter ID Protection,

440
00:14:57,680 --> 00:15:00,480
the Cloud Side Companion to Defender for Identity.

Mirko Peters Profile Photo

Founder of m365.fm, m365.show and m365con.net

Mirko Peters is a Microsoft 365 expert, content creator, and founder of m365.fm, a platform dedicated to sharing practical insights on modern workplace technologies. His work focuses on Microsoft 365 governance, security, collaboration, and real-world implementation strategies.

Through his podcast and written content, Mirko provides hands-on guidance for IT professionals, architects, and business leaders navigating the complexities of Microsoft 365. He is known for translating complex topics into clear, actionable advice, often highlighting common mistakes and overlooked risks in real-world environments.

With a strong emphasis on community contribution and knowledge sharing, Mirko is actively building a platform that connects experts, shares experiences, and helps organizations get the most out of their Microsoft 365 investments.

Related to this Episode

Traditional IAM vs. ITDR: Why Static Rules No Longer Cut It

Welcome back to the blog! If you have been following our podcast journey, you know we spend a lot of time breaking down complex security frameworks and helping administrators make sense of their cloud and on-premises environments. Today, we are expa…