Microsoft Defender for Identity Learning Path

Learn how Microsoft Defender for Identity detects identity-based threats in hybrid environments and supports identity investigations.

What you will learn

Sensor deployment, identity signals, lateral movement detection, investigation, and response.

Implementation and governance

Treat identity as a cross-domain security dependency: align Defender for Identity, Entra controls, privileged access, and incident processes.

Recommended podcast episodes

Continue learning

Return to the Microsoft Defender Learning Hub for the complete path, or use the M365.fm Learning Hub to explore another domain.

Last reviewed: July 2026.

Learning objectives

  • Recognize identity-based signals that indicate credential misuse or lateral movement.
  • Connect identity detections to endpoint and email investigations.
  • Define response ownership across security and identity teams.

FAQ

Why is identity central to XDR?

Identity connects people, access, devices, and cloud services. It often provides the context that turns separate alerts into one incident story.

Continue learning: Defender for Cloud Apps and Defender XDR.