Microsoft Defender for Identity: Real-time threat detection

    Back to Blog
    Security

    Microsoft Defender for Identity: Real-time threat detection

    Detect compromised identities and lateral movements of attackers. Defender for Identity protects your on-premises and cloud environment.

    September 23, 202510 min read
    Luis Castillo

    Luis Castillo

    Solution Engineer

    luis.castillo@cnext.ch
    6+ Jahreexperience·5×Microsoft Applied Skills·Security & Intune
    CNEXT Microsoft Partner

    Quick Answer

    Detect compromised identities and lateral movements of attackers. Defender for Identity protects your on-premises and cloud environment.

    Attackers target identities. Microsoft Defender for Identity detects suspicious activities and protects your Active Directory infrastructure.

    What is Defender for Identity?

    Defender for Identity (formerly Azure ATP) monitors:

    • On-Premise Active Directory – Domain Controllers
    • Microsoft Entra ID – Cloud identities
    • AD FS – Federated authentication

    Detection Capabilities

    • Compromised credentials
    • Lateral movement in the network
    • Privilege escalation
    • Reconnaissance activities
    • Malicious activities

    Typical Attack Scenarios

    Pass-the-Hash

    Attackers use stolen password hashes:

    • Defender detects unusual hash usage
    • Alerts on suspicious authentications
    • Correlates with other signals

    Kerberoasting

    Extraction of service account credentials:

    • Detection of excessive ticket requests
    • Analysis of encryption downgrades
    • Warning of brute-force attempts

    Golden Ticket

    Forgery of Kerberos tickets:

    • Detection of manipulated ticket lifetimes
    • Analysis of unusual ticket properties
    • Correlation with other compromise indicators

    DCSync

    Replication of domain controller data:

    • Monitoring of replication requests
    • Detection of unauthorized sources
    • Immediate alerting

    Integration

    Microsoft 365 Defender

    Defender for Identity is part of Microsoft 365 Defender:

    • Correlated Alerts – Across all Defender products
    • Unified Investigation – A console for all incidents
    • Automated Response – Playbooks for response

    SIEM Integration

    Export to Security Information and Event Management:

    • Syslog export
    • Microsoft Sentinel integration
    • Third-party SIEM connectivity

    Deployment

    Sensor Installation

    • On domain controllers
    • Resource-efficient
    • Automatic updates

    Configuration

    • Sensitivity settings
    • Exceptions for known activities
    • Notification rules

    Incident Response

    In case of detected threats:

    1. 1Alert – Immediate notification
    2. 2Investigation – Detailed timeline
    3. 3Remediation – Recommended actions
    4. 4Prevention – Hardening recommendations

    Conclusion

    Defender for Identity is essential for on-premise AD environments. Integration with the Microsoft ecosystem provides comprehensive protection. CNEXT supports deployment and operation.

    SecuritySchweiz
    Teilen:

    This article was created with the support of AI and reviewed by our team. We use AI tools to produce high-quality content efficiently — the editorial responsibility always lies with our experts.

    Luis Castillo

    Luis Castillo

    Solution Engineer

    Have questions about this topic?

    Our experts are happy to advise you – free and without obligation.