In my opinion, one of the coolest security features to come out of Microsoft over the past few years is Advanced Threat Analytics (ATA), and yet I hardly hear anyone talking about it. It's not a feature or function built into the Windows Server OS, not yet anyway, but is an on-premises software that rides on top of Windows to produce some amazing functionality. Essentially, what ATA does is monitor all of your Active Directory traffic, and warns you of dangerous or unusual behavior in real time, immediately as it is happening.
The idea of ATA is pretty simple to understand and makes so much common sense that it's something we are all going to wonder why it took so long to put into place. The reason for that, though, is because under the hood the processing and learning that ATA is doing is very advanced. Yes, I said learning. This is the coolest...