search
Get Started
search
Microsoft Defender for Identity - Security Software
zoom_in Click to enlarge

Microsoft Defender for Identity

language

description Microsoft Defender for Identity Overview

Microsoft Defender for Identity continuously monitors and analyzes user and device sign-in events across your organization to detect and respond to suspicious activity attempting to impersonate legitimate users or compromise accounts.

help Microsoft Defender for Identity FAQ

Does Microsoft Defender for Identity require on-premises sensors?

Yes, it typically requires installing Defender for Identity sensors on your on-premises domain controllers. These sensors monitor the traffic directly to detect attacks like Pass-the-Hash or Pass-the-Ticket.

Can Microsoft Defender for Identity detect anomalous lateral movements?

Yes, the platform uses machine learning to build behavioral profiles for users, detecting unusual lateral movements across the network. It maps these suspicious activities to the MITRE ATT&CK framework.

How does Microsoft Defender for Identity handle honeytoken accounts?

Administrators can configure honeytoken accounts within Defender for Identity to act as decoys. Any authentication attempt using these accounts triggers an immediate high-priority alert, as they should never be actively used.

Is Microsoft Defender for Identity included in the E5 license?

Yes, Microsoft Defender for Identity is included as part of the Microsoft 365 E5 security suite or under the Microsoft 365 Defender portal. It integrates natively with Defender for Cloud Apps and Microsoft Sentinel.

Reviews & Comments

Write a Review

rate_review

Be the first to review

Share your thoughts with the community and help others make better decisions.

Save to your list

Save your favorites and follow how their scores change over time.

Save favorites
Track changes
Compare scores

Already have an account? Sign in

Compare Items

See how they stack up against each other

Comparing
VS
Select 1 more item to compare