Attackers target identities. Microsoft Defender for Identity detects suspicious activities and protects your Active Directory infrastructure.
What is Defender for Identity?
Defender for Identity (formerly Azure ATP) monitors:
- On-Premise Active Directory – Domain Controllers
- Microsoft Entra ID – Cloud identities
- AD FS – Federated authentication
Detection Capabilities
- Compromised credentials
- Lateral movement in the network
- Privilege escalation
- Reconnaissance activities
- Malicious activities
Typical Attack Scenarios
Pass-the-Hash
Attackers use stolen password hashes:
- Defender detects unusual hash usage
- Alerts on suspicious authentications
- Correlates with other signals
Kerberoasting
Extraction of service account credentials:
- Detection of excessive ticket requests
- Analysis of encryption downgrades
- Warning of brute-force attempts
Golden Ticket
Forgery of Kerberos tickets:
- Detection of manipulated ticket lifetimes
- Analysis of unusual ticket properties
- Correlation with other compromise indicators
DCSync
Replication of domain controller data:
- Monitoring of replication requests
- Detection of unauthorized sources
- Immediate alerting
Integration
Microsoft 365 Defender
Defender for Identity is part of Microsoft 365 Defender:
- Correlated Alerts – Across all Defender products
- Unified Investigation – A console for all incidents
- Automated Response – Playbooks for response
SIEM Integration
Export to Security Information and Event Management:
- Syslog export
- Microsoft Sentinel integration
- Third-party SIEM connectivity
Deployment
Sensor Installation
- On domain controllers
- Resource-efficient
- Automatic updates
Configuration
- Sensitivity settings
- Exceptions for known activities
- Notification rules
Incident Response
In case of detected threats:
- 1Alert – Immediate notification
- 2Investigation – Detailed timeline
- 3Remediation – Recommended actions
- 4Prevention – Hardening recommendations
Conclusion
Defender for Identity is essential for on-premise AD environments. Integration with the Microsoft ecosystem provides comprehensive protection. CNEXT supports deployment and operation.

