Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
 Microsoft Defender for Identity in Depth

You're reading from   Microsoft Defender for Identity in Depth An exhaustive guide to ITDR, breach prevention, and cyberattack response

Arrow left icon
Product type Paperback
Published in Dec 2024
Publisher Packt
ISBN-13 9781835884485
Length 380 pages
Edition 1st Edition
Arrow right icon
Author (1):
Arrow left icon
Pierre Thoor Pierre Thoor
Author Profile Icon Pierre Thoor
Pierre Thoor
Arrow right icon
View More author details
Toc

Table of Contents (16) Chapters Close

Preface 1. Part 1:Mastering the Fundamentals of Microsoft Defender for Identity FREE CHAPTER
2. Chapter 1: Introduction to Microsoft Defender for Identity 3. Chapter 2: Setting up Microsoft Defender for Identity 4. Chapter 3: Leveraging MDI PowerShell for Automation and Management 5. Part 2: Advanced Configuration, Integration, and Threat Detection
6. Chapter 4: Integrating MDI with AD FS, AD CS, and Entra Connect 7. Chapter 5: Extending MDI Capabilities Through APIs 8. Chapter 6: Mastering KQL for Advanced Threat Detection in MDI 9. Part 3: Operational Excellence with Microsoft Defender for Identity
10. Chapter 7: Investigating and Responding to Security Alerts 11. Chapter 8: Utilizing MDI Action Accounts Effectively 12. Chapter 9: Building a Resilient Identity Threat Detection and Response Framework 13. Chapter 10: Navigating Challenges: MDI Troubleshooting and Optimization 14. Index 15. Other Books You May Enjoy

Summary

In this chapter, we have focused on the essential processes of managing alerts and incidents within MDI. We explored how the MDI alert system functions, providing insights into the different types of alerts and their classifications. We delved into the initial triage process, highlighting the steps to assess and categorize incidents effectively.

Furthermore, we examined the automation capabilities available within the Microsoft Cloud, including Power Automate, Logic Apps, Azure Automation, and Azure Functions. These tools enable streamlined and efficient incident response workflows.

Finally, we discussed the importance of having a structured IRP and building a capable IRT. Emphasizing the need for regular reviews and updates, we underscored the significance of being prepared and proactive in the ever-evolving cybersecurity landscape.

Next, we will delve into the strategic use of MDI action accounts, focusing on the configuration, security best practices, and the critical...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime
Banner background image