Integrating MDI with AD FS, AD CS, and Entra Connect
In this chapter, we will delve into the integration of Microsoft Defender for Identity (MDI) with key Active Directory services – specifically, Active Directory Federation Services (AD FS), Active Directory Certificate Services (AD CS), and Entra Connect. Integrating MDI with services such as AD FS, alongside data from our domain controllers, enhances our capability to correlate login data extensively. This allows for a deeper analysis of user behavior and authentication patterns, providing a more detailed and enriched security overview.
If you are thinking “Why the support of AD FS; shouldn’t we migrate our apps to Entra ID?”, the answer is yes, we should, but in some scenarios and some cases, we still need to have our AD FS infrastructure alive.
Additionally, we explore how to extend MDI’s coverage across multiple Active Directory forests, a step that is vital for organizations managing...