Understanding the MDI architecture
MDI is a combination of services and components that work together to provide your Microsoft 365 hybrid deployment with comprehensive protection from modern threats and attacks. You can view the MDI architecture at https://learn.microsoft.com/en-us/defender-for-identity/architecture. Here, sensors are installed on AD FS servers and domain controllers. These sensors send signals to Microsoft 365 Defender about Active Directory entities, parsed traffic, and Windows events and traces.
MDI can function to protect your hybrid identity by leveraging the following three key components:
- The Microsoft 365 Defender portal, in which you create your MDI instance, as well as monitor and address any threats that have been reported.
- The MDI sensor, which is installed on your on-premises domain controllers and is used to monitor domain controller traffic. It can also be installed on your AD FS servers to directly monitor network traffic and authentication...