Describing Microsoft Defender for Identity
Microsoft Defender for Identity is used within a hybrid identity infrastructure. Microsoft Defender for Identity connects to the on-premises Active Directory Domain Services (AD DS) servers and Active Directory Federated Services (AD FS) servers to gather signals and events from the on-premises infrastructure and protect against threats to identity. Microsoft Defender for Identity provides similar reporting regarding the risky users and sign-ins that are provided within Azure AD Identity Protection in Azure Active Directory. We discussed Azure AD Identity Protection in Chapter 7, Describing the Identity Protection and Governance Capabilities of Azure AD.
The features of Microsoft Defender for Identity are listed as follows:
- It monitors and profiles user behavior and activities.
- It protects user identities and reduces the attack surface.
- It identifies suspicious activities across the cyber-attack kill chain.
- It investigates...