Somebody holding a working password is indistinguishable from a colleague until something is watching how they behave.
It reads signals from the directory on your own servers and from Entra, builds a picture of what normal looks like for each account, and raises the enumeration, credential abuse and sideways movement that always come before a domain falls. This is the layer that spots the person who is already through the door.

- AD and EntraOn-premises and cloud identity
- BehavioralNot signature matching
- Lateral movement pathsShown before they are used
- Service accountsNon-human identities included
Eight things this covers that nothing else in the stack is looking at.
Identity is the one thing nothing else you own is watching
It covers identity attacks whether they play out on your own servers, in the cloud or across both, taking signals from Active Directory, from Entra, and from other providers such as Okta. That reach matters because almost every American company past a certain size runs a directory alongside a cloud tenant, and an attacker moves between the two without either side raising anything on its own.
Reconnaissance, which is the earliest useful signal
There are detections for suspicious discovery work, meaning attempts to list out account names, who belongs to which group, addresses and available resources. It matters because looking around is the very first thing anybody does, well before anything is taken or encrypted, and none of it is visible to endpoint or mail tooling. Catching somebody at that stage is the difference between an incident report and a letter to your customers.
Credential abuse, including the quiet kind
Coverage includes password guessing at volume, repeated failures, and group membership changing in ways that look wrong. That third item is the interesting one, because putting an account into a privileged group is not an attack on the face of it, it is an ordinary Tuesday afternoon administrative task, and it only looks wrong once you know the context. Behavioral analysis is what supplies the context.
Lateral movement, and the paths before anybody uses them
It picks up attempts to move sideways and take control of more sensitive accounts across environments. Separately, and arguably worth more, it maps the routes by which somebody could travel through your estate. That second piece is preventive rather than detective: it names the perfectly ordinary account sitting two hops from a domain administrator, before anyone has walked that path.
Domain dominance, named specifically
The behaviors that come with losing the domain outright are named explicitly: code executed remotely on a domain controller, DCShadow, malicious replication between controllers, and Golden Ticket activity. These are the techniques that turn a foothold into ownership of everything, and catching them is the specific reason this exists as a product rather than as a checkbox inside something else.
Non-human identities, which nobody monitors
Coverage explicitly extends to service accounts, sync accounts and applications rather than stopping at people. In practice this is the gap that matters most, because service accounts hold real power, their passwords are almost never rotated, nobody has ever watched one, and somebody using one behaves in a way no tool built around human users would think to question. Abnormal service account behavior is among the strongest signals available anywhere.
Posture assessments feeding Secure Score
Alongside the detections sit posture assessments, surfaced through Secure Score, that call out risky configuration and exposure. That is the preventive half, and it is very often worth more straight away than the alerting is, because it tells you what is wrong this morning instead of waiting for somebody to make use of it.
How it deploys, which is lighter than people expect
Small sensors run on the identity infrastructure itself, reading and parsing the relevant traffic and Windows events locally, with API connectors where another provider is involved and analytics running in the cloud. Only what is needed leaves the machine, which keeps the performance cost down and avoids reworking the network. That is a far easier deployment than the appliance and port mirroring approach it replaced.
One maps the routes. The other spots somebody using them.
We do both, and they answer genuinely different questions, so it is worth establishing which of the two your situation calls for before any money is committed to either.
- An audit examines the directory at one moment. It works out who really sits in the privileged groups, turns up delegations nobody can account for, finds the service accounts carrying permanent administrative rights, and traces how an ordinary account could end up a domain administrator. It tells you what is wrong today, and what comes out of it is a list of things to fix.
- This runs continuously instead. It learns what normal looks like for each person, machine and account, then raises something when the deviation matches a known identity attack pattern. It tells you somebody is doing something right now that they should not be, and what comes out of it is an incident.
- The order that works is audit first, detection second. Shutting the obvious privilege routes cuts the number of ways through, which lowers the risk and simultaneously cuts the noise the detection has to reason about. Putting detection on top of a directory nobody has examined produces alerts about a structure that should have been corrected first, which is a slower and more expensive road to the same destination.
- There is one exception. Where you have genuine reason to think something is happening at this moment, detection goes first and the audit follows behind it. If somebody was phished, an account did something strange, or a competitor in your sector was just hit, the pressing question is whether anyone is moving through your environment right now, and that is precisely the question this answers.
Four things that decide whether this is worth deploying.
We audit the directory before recommending detection
Put this on top of a directory nobody has examined and it will raise alerts about a structure that should have been fixed beforehand. Working out who is really in the privileged groups, stripping permanent rights from service accounts and shutting the obvious escalation routes lowers the genuine risk and the volume of material the detection has to reason about at the same time. The exception, as always, is where something appears to be happening at this moment, in which case detection goes first.
We start with the posture assessments, not the detections
The posture assessments and the lateral movement mapping tell you what is wrong this morning, and they are very often worth more straight away than the alerting is. A company that acts on those findings becomes measurably harder to move through, and it holds that benefit whether or not anybody ever attacks it, which cannot be said of detection on its own.
We inventory service accounts before the baseline is learned
Accounts that are not people are where this turns up things nothing else would, and its detections rest entirely on knowing what normal looks like. Walking in with a written list of the service accounts, what each one does and what it has any business touching, makes the first weeks of alerts readable rather than bewildering, and you end up with a document worth having either way.
We settle the response question before deployment
Alerts about sideways movement and domain takeover are urgent by their nature and have no habit of arriving between nine and five. So before anything is deployed we settle who gets told, how fast, who has authority to disable an account, and whether covering the hours outside the working day needs a managed arrangement. Detection with nobody to respond to it is an expensive way of documenting an incident you failed to stop.
Six US situations where identity detection earns its place.
A long-lived Active Directory nobody has reviewed
A decade of groups, delegations and service accounts piling up, with privilege routes nobody has ever traced. This is where the lateral movement mapping produces its most arresting output, because it names the specific ordinary account sitting a short hop from control of the domain. The usual recommendation here is the audit first and the detection straight afterward, since each set of findings makes the other more useful.
A regulated firm expected to detect and investigate
When a SOC 2 auditor, an insurer, a HIPAA risk assessment or an examination under NYDFS Part 500 expects you to show detection covering identity and not merely endpoints, this is what answers the question, and the posture assessments generate the evidence as a side effect. What examiners expect around monitoring privileged access lines up almost exactly with what this watches.
Manufacturing, logistics or any long-lived estate
Older systems, machines that cannot be patched on any normal schedule, and shared or service accounts that exist for real operational reasons and cannot simply be deleted. Where the structural weakness cannot be repaired, detecting its abuse is the next best thing available, and this is one of very few situations where detection genuinely stands in for prevention.
A hybrid estate synchronizing to Microsoft Entra ID
Which describes nearly every American company past a certain size. The synchronization server is among the most privileged machines you own and the account driving it carries real power, so a compromise on your own hardware very often becomes a compromise of the cloud tenant. Watching identity signals on both sides is the entire point, and examining either half alone produces a misleading picture.
After a credential compromise or a near miss
Somebody got phished, an account did something strange, or a competitor in your sector was hit last week. The pressing question here is whether anyone is moving through your environment at this moment, which reverses the normal order: detection goes in first and the audit follows. It is also the point at which the budget conversation is easiest, because the risk has just stopped being hypothetical.
An organization with more service accounts than it can list
A situation most people will recognize. Applications, integrations, scheduled tasks and scripts, every one with an account behind it, most with passwords untouched for years, none of them watched by anything. Behavioral detection reaching accounts that are not people is aimed squarely at this, and the inventory work that comes before deployment is usually worth as much as the product itself.
What visibility organizations actually have over identity attacks.
| Feature | Identity monitored | Endpoint and email only | Nothing watching identity |
|---|---|---|---|
Malware on a device detected | Yes | Yes | Maybe |
Phishing email detected | Yes | Yes | Partly |
Account enumeration noticed | Yes | No | No |
Suspicious privileged group change noticed | Yes | No | No |
Lateral movement detected in progress | Yes | Rarely | No |
Domain dominance techniques detected | Yes | No | No |
Service account misuse detected | Yes | No | No |
Lateral movement paths known in advance | Yes | No | No |
Identity signals correlated with endpoint and email | Yes | Partly | No |
Could scope an identity incident for a disclosure decision | Yes | Barely | No |
What it watches for, laid against the way an attack genuinely unfolds.
Attack stage
Reconnaissance
- What is detected
- Listing out account names, group memberships, addresses and available resources
Attack stage
Compromised credentials
- What is detected
- Brute force, repeated failed authentications, suspicious group membership changes
Attack stage
Lateral movement
- What is detected
- Attempts to expand control of sensitive identities across environments
Attack stage
Domain dominance
- What is detected
- Code run remotely on a controller, DCShadow, malicious replication, Golden Ticket
Attack stage
Posture, before any attack
- What is detected
- Risky configurations and exposures, surfaced in Secure Score
Attack stage
Posture, before any attack
- What is detected
- Lateral movement paths showing how an attacker could traverse
Attack stage
Non-human identities
- What is detected
- Abnormal behavior of service accounts, sync accounts and applications
Attack stage
Cross-environment
- What is detected
- Signals drawn from the local directory, from Entra, and from providers such as Okta
Five steps, and the sensors are the easy part.
- 1
Confirm licensing and scope the identity infrastructure
Whether your licensing already covers it, checked against the tenant rather than assumed, and what identity infrastructure falls in scope: the domain controllers, any Federation or Certificate Services, and whether an identity provider outside the Microsoft stack needs a connector.
- 2
Audit and inventory before the baseline is set
Privileged group membership worked out properly, service accounts written down with what each has legitimate business touching, and the obvious privilege routes closed wherever they can be. That narrows what the product has to reason about and makes the first findings readable instead of alarming.
- 3
Deploy sensors and connectors
Small sensors onto the identity infrastructure, reading and parsing traffic and Windows events on the machine itself, with only what is needed leaving for the cloud. Connectors where a second identity provider is involved. It is genuinely light, and it still touches domain controllers, so it goes through a proper change window like anything else that does.
- 4
Work the posture findings while the baseline builds
Behavioral detection needs time to work out what normal looks like, and the best use of that time is acting on the posture assessments and the lateral movement mapping, both of which are available on day one and depend on no learning at all. Most companies get their first real reduction in risk from this stage rather than from any alert.
- 5
Tune, then agree the response rhythm
The first alerts get worked through together, so that expected behavior is understood rather than silenced on sight, service account activity is explained rather than muted, and the response route is confirmed: who hears about it, how quickly, who has the authority to disable an account, and what happens at three in the morning.
What organizations ask about Defender for Identity.
Fifteen questions worth answering first.
Is this the right next step
- Have you audited the directory first?Closing the obvious privilege routes cuts the risk and the alert volume together.
- Do you still run on-premises Active Directory?If you are cloud-only, the value proposition differs.
- Do you synchronize identities to Microsoft Entra ID?The hybrid join is exactly what this monitors across.
- Is there a real reason to suspect something is going on right now?If so, detection comes before audit rather than after.
- Have you confirmed your licensing includes it?We check this rather than assuming, because it varies.
Deployment readiness
- How many domain controllers would need sensors?Sensors run on identity infrastructure, not on every endpoint.
- Are Certificate Services or Federation Services in the picture too?Additional identity infrastructure worth including in scope.
- Is there a second identity provider outside the Microsoft stack?API connectors cover systems such as Okta.
- Can you inventory your service accounts before you start?Their normal behavior is the baseline being learned.
- Is there a change window for domain controller work?Light touch, and still domain controllers.
Would anybody act
- Who receives an identity alert, and how quickly?Detection with no responder changes nothing.
- If a lateral movement alert fired at two in the morning, would anybody act on it?These attacks do not respect office hours.
- Is there an agreed way to shut down a compromised account quickly?Decided in advance, not during the incident.
- Would the posture recommendations get actioned?They arrive in Secure Score and are frequently ignored.
- Do you have or need a managed response arrangement?Worth deciding before buying detection.
The pages around this one.
Active Directory
The on-premises directory this monitors, the hybrid identity model, and the attack paths that still run through it.
Defender for Endpoint
The device half of the same family, and the plan comparison where Business Premium turns out, unexpectedly, to beat E3.
Microsoft Entra
The cloud identity platform this watches alongside your own directory, plus the controls that shrink what an attacker can get to.
Ask which of your everyday accounts is two moves from domain administrator.
That is precisely what the lateral movement mapping answers, and hardly any company can answer it today. If the directory has never been audited, that is the better opening move, and you will hear that from us rather than being sold detection to lay over a structure somebody should repair first.
Related Services
Explore more solutions that work great with this service
Microsoft Defender for Endpoint Services
EDR plan selection, onboarding and zero-gap AV migration
Learn moreMicrosoft Entra
Identity and access management solutions
Learn moreMicrosoft Security Services
The Microsoft security stack deployed and managed end to end
Learn moreMicrosoft Entra Conditional Access Design
Conditional Access design and review for US organizations:
Learn moreMicrosoft Defender
Advanced endpoint and email threat protection
Learn moreSOC-as-a-Service
24/7 security operations delivered as a service
Learn more