Cloud security solution that uses Active Directory signals to detect advanced threats and compromised identities.
Microsoft Defender for Identity monitors Active Directory signals to detect advanced attacks—credential theft, lateral movement, and domain dominance attempts. It identifies suspicious activities like pass-the-hash attacks, reconnaissance, and privilege escalation. Defender for Identity provides security alerts, user investigation priorities, and integration with the broader Microsoft XDR platform. It's particularly valuable for hybrid environments with on-premises Active Directory.
Why It Matters
The DSC Perspective:
Active Directory is a prime target for attackers. Defender for Identity detects attack techniques specifically targeting identity infrastructure—essential for organisations with on-premises AD or hybrid identity.
