description Microsoft Defender for Identity Overview
Microsoft Defender for Identity continuously monitors and analyzes user and device sign-in events across your organization to detect and respond to suspicious activity attempting to impersonate legitimate users or compromise accounts.
help Microsoft Defender for Identity FAQ
Does Microsoft Defender for Identity require on-premises sensors?
Yes, it typically requires installing Defender for Identity sensors on your on-premises domain controllers. These sensors monitor the traffic directly to detect attacks like Pass-the-Hash or Pass-the-Ticket.
Can Microsoft Defender for Identity detect anomalous lateral movements?
Yes, the platform uses machine learning to build behavioral profiles for users, detecting unusual lateral movements across the network. It maps these suspicious activities to the MITRE ATT&CK framework.
How does Microsoft Defender for Identity handle honeytoken accounts?
Administrators can configure honeytoken accounts within Defender for Identity to act as decoys. Any authentication attempt using these accounts triggers an immediate high-priority alert, as they should never be actively used.
Is Microsoft Defender for Identity included in the E5 license?
Yes, Microsoft Defender for Identity is included as part of the Microsoft 365 E5 security suite or under the Microsoft 365 Defender portal. It integrates natively with Defender for Cloud Apps and Microsoft Sentinel.
explore Explore More
Similar to Microsoft Defender for Identity
See all arrow_forwardReviews & Comments
Write a Review
Be the first to review
Share your thoughts with the community and help others make better decisions.