We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Security
  2. Defender for Identity
Microsoft Defender for Identity

Somebody holding a working password is indistinguishable from a colleague until something is watching how they behave.

It reads signals from the directory on your own servers and from Entra, builds a picture of what normal looks like for each account, and raises the enumeration, credential abuse and sideways movement that always come before a domain falls. This is the layer that spots the person who is already through the door.

Book an identity threat reviewSee what it detects
Microsoft Defender for Identity deployment for US organizations
  • AD and EntraOn-premises and cloud identity
  • BehavioralNot signature matching
  • Lateral movement pathsShown before they are used
  • Service accountsNon-human identities included
What it actually does

Eight things this covers that nothing else in the stack is looking at.

Endpoint tooling watches machines and mail tooling watches messages. Neither of them has any view of what a perfectly valid credential does once the wrong person is using it, and that is exactly the stage where one compromised laptop turns into the whole domain.

Identity is the one thing nothing else you own is watching

It covers identity attacks whether they play out on your own servers, in the cloud or across both, taking signals from Active Directory, from Entra, and from other providers such as Okta. That reach matters because almost every American company past a certain size runs a directory alongside a cloud tenant, and an attacker moves between the two without either side raising anything on its own.

Reconnaissance, which is the earliest useful signal

There are detections for suspicious discovery work, meaning attempts to list out account names, who belongs to which group, addresses and available resources. It matters because looking around is the very first thing anybody does, well before anything is taken or encrypted, and none of it is visible to endpoint or mail tooling. Catching somebody at that stage is the difference between an incident report and a letter to your customers.

Credential abuse, including the quiet kind

Coverage includes password guessing at volume, repeated failures, and group membership changing in ways that look wrong. That third item is the interesting one, because putting an account into a privileged group is not an attack on the face of it, it is an ordinary Tuesday afternoon administrative task, and it only looks wrong once you know the context. Behavioral analysis is what supplies the context.

Lateral movement, and the paths before anybody uses them

It picks up attempts to move sideways and take control of more sensitive accounts across environments. Separately, and arguably worth more, it maps the routes by which somebody could travel through your estate. That second piece is preventive rather than detective: it names the perfectly ordinary account sitting two hops from a domain administrator, before anyone has walked that path.

Domain dominance, named specifically

The behaviors that come with losing the domain outright are named explicitly: code executed remotely on a domain controller, DCShadow, malicious replication between controllers, and Golden Ticket activity. These are the techniques that turn a foothold into ownership of everything, and catching them is the specific reason this exists as a product rather than as a checkbox inside something else.

Non-human identities, which nobody monitors

Coverage explicitly extends to service accounts, sync accounts and applications rather than stopping at people. In practice this is the gap that matters most, because service accounts hold real power, their passwords are almost never rotated, nobody has ever watched one, and somebody using one behaves in a way no tool built around human users would think to question. Abnormal service account behavior is among the strongest signals available anywhere.

Posture assessments feeding Secure Score

Alongside the detections sit posture assessments, surfaced through Secure Score, that call out risky configuration and exposure. That is the preventive half, and it is very often worth more straight away than the alerting is, because it tells you what is wrong this morning instead of waiting for somebody to make use of it.

How it deploys, which is lighter than people expect

Small sensors run on the identity infrastructure itself, reading and parsing the relevant traffic and Windows events locally, with API connectors where another provider is involved and analytics running in the cloud. Only what is needed leaves the machine, which keeps the performance cost down and avoids reworking the network. That is a far easier deployment than the appliance and port mirroring approach it replaced.

How this differs from an Active Directory audit

One maps the routes. The other spots somebody using them.

We do both, and they answer genuinely different questions, so it is worth establishing which of the two your situation calls for before any money is committed to either.

  • An audit examines the directory at one moment. It works out who really sits in the privileged groups, turns up delegations nobody can account for, finds the service accounts carrying permanent administrative rights, and traces how an ordinary account could end up a domain administrator. It tells you what is wrong today, and what comes out of it is a list of things to fix.
  • This runs continuously instead. It learns what normal looks like for each person, machine and account, then raises something when the deviation matches a known identity attack pattern. It tells you somebody is doing something right now that they should not be, and what comes out of it is an incident.
  • The order that works is audit first, detection second. Shutting the obvious privilege routes cuts the number of ways through, which lowers the risk and simultaneously cuts the noise the detection has to reason about. Putting detection on top of a directory nobody has examined produces alerts about a structure that should have been corrected first, which is a slower and more expensive road to the same destination.
  • There is one exception. Where you have genuine reason to think something is happening at this moment, detection goes first and the audit follows behind it. If somebody was phished, an account did something strange, or a competitor in your sector was just hit, the pressing question is whether anyone is moving through your environment right now, and that is precisely the question this answers.
Ask which of the two your situation actually needs
How we approach it

Four things that decide whether this is worth deploying.

Identity detection is genuinely worth having, and it is also the easiest thing in the Microsoft security range to drop into an empty room, where it generates alerts nobody responds to about a directory nobody has repaired.

We audit the directory before recommending detection

Put this on top of a directory nobody has examined and it will raise alerts about a structure that should have been fixed beforehand. Working out who is really in the privileged groups, stripping permanent rights from service accounts and shutting the obvious escalation routes lowers the genuine risk and the volume of material the detection has to reason about at the same time. The exception, as always, is where something appears to be happening at this moment, in which case detection goes first.

We start with the posture assessments, not the detections

The posture assessments and the lateral movement mapping tell you what is wrong this morning, and they are very often worth more straight away than the alerting is. A company that acts on those findings becomes measurably harder to move through, and it holds that benefit whether or not anybody ever attacks it, which cannot be said of detection on its own.

We inventory service accounts before the baseline is learned

Accounts that are not people are where this turns up things nothing else would, and its detections rest entirely on knowing what normal looks like. Walking in with a written list of the service accounts, what each one does and what it has any business touching, makes the first weeks of alerts readable rather than bewildering, and you end up with a document worth having either way.

We settle the response question before deployment

Alerts about sideways movement and domain takeover are urgent by their nature and have no habit of arriving between nine and five. So before anything is deployed we settle who gets told, how fast, who has authority to disable an account, and whether covering the hours outside the working day needs a managed arrangement. Detection with nobody to respond to it is an expensive way of documenting an incident you failed to stop.

Where this matters most

Six US situations where identity detection earns its place.

What links these is a directory old enough to have accumulated structure, alongside something an attacker would want. In two of the six the honest advice is to repair the directory before buying anything.

A long-lived Active Directory nobody has reviewed

A decade of groups, delegations and service accounts piling up, with privilege routes nobody has ever traced. This is where the lateral movement mapping produces its most arresting output, because it names the specific ordinary account sitting a short hop from control of the domain. The usual recommendation here is the audit first and the detection straight afterward, since each set of findings makes the other more useful.

A regulated firm expected to detect and investigate

When a SOC 2 auditor, an insurer, a HIPAA risk assessment or an examination under NYDFS Part 500 expects you to show detection covering identity and not merely endpoints, this is what answers the question, and the posture assessments generate the evidence as a side effect. What examiners expect around monitoring privileged access lines up almost exactly with what this watches.

Manufacturing, logistics or any long-lived estate

Older systems, machines that cannot be patched on any normal schedule, and shared or service accounts that exist for real operational reasons and cannot simply be deleted. Where the structural weakness cannot be repaired, detecting its abuse is the next best thing available, and this is one of very few situations where detection genuinely stands in for prevention.

A hybrid estate synchronizing to Microsoft Entra ID

Which describes nearly every American company past a certain size. The synchronization server is among the most privileged machines you own and the account driving it carries real power, so a compromise on your own hardware very often becomes a compromise of the cloud tenant. Watching identity signals on both sides is the entire point, and examining either half alone produces a misleading picture.

After a credential compromise or a near miss

Somebody got phished, an account did something strange, or a competitor in your sector was hit last week. The pressing question here is whether anyone is moving through your environment at this moment, which reverses the normal order: detection goes in first and the audit follows. It is also the point at which the budget conversation is easiest, because the risk has just stopped being hypothetical.

An organization with more service accounts than it can list

A situation most people will recognize. Applications, integrations, scheduled tasks and scripts, every one with an account behind it, most with passwords untouched for years, none of them watched by anything. Behavioral detection reaching accounts that are not people is aimed squarely at this, and the inventory work that comes before deployment is usually worth as much as the product itself.

Three positions

What visibility organizations actually have over identity attacks.

The middle column describes most American estates that have a sensible security budget, and it is also the position in which an identity attack travels furthest before anyone spots it, because everything deployed is watching a different part of the problem.
Malware on a device detected
Identity monitoredYes
Endpoint and email onlyYes
Nothing watching identityMaybe
Phishing email detected
Identity monitoredYes
Endpoint and email onlyYes
Nothing watching identityPartly
Account enumeration noticed
Identity monitoredYes
Endpoint and email onlyNo
Nothing watching identityNo
Suspicious privileged group change noticed
Identity monitoredYes
Endpoint and email onlyNo
Nothing watching identityNo
Lateral movement detected in progress
Identity monitoredYes
Endpoint and email onlyRarely
Nothing watching identityNo
Domain dominance techniques detected
Identity monitoredYes
Endpoint and email onlyNo
Nothing watching identityNo
Service account misuse detected
Identity monitoredYes
Endpoint and email onlyNo
Nothing watching identityNo
Lateral movement paths known in advance
Identity monitoredYes
Endpoint and email onlyNo
Nothing watching identityNo
Identity signals correlated with endpoint and email
Identity monitoredYes
Endpoint and email onlyPartly
Nothing watching identityNo
Could scope an identity incident for a disclosure decision
Identity monitoredYes
Endpoint and email onlyBarely
Nothing watching identityNo
Feature
Identity monitored
Endpoint and email only
Nothing watching identity
Malware on a device detected
YesYesMaybe
Phishing email detected
YesYesPartly
Account enumeration noticed
YesNoNo
Suspicious privileged group change noticed
YesNoNo
Lateral movement detected in progress
YesRarelyNo
Domain dominance techniques detected
YesNoNo
Service account misuse detected
YesNoNo
Lateral movement paths known in advance
YesNoNo
Identity signals correlated with endpoint and email
YesPartlyNo
Could scope an identity incident for a disclosure decision
YesBarelyNo
Detections by attack stage

What it watches for, laid against the way an attack genuinely unfolds.

Taken from the published mapping. Read it from the top down, because every stage is a chance to end the attack, and the ones nearest the top are by far the cheapest place to do it.

Attack stage

Reconnaissance

What is detected
Listing out account names, group memberships, addresses and available resources

Attack stage

Compromised credentials

What is detected
Brute force, repeated failed authentications, suspicious group membership changes

Attack stage

Lateral movement

What is detected
Attempts to expand control of sensitive identities across environments

Attack stage

Domain dominance

What is detected
Code run remotely on a controller, DCShadow, malicious replication, Golden Ticket

Attack stage

Posture, before any attack

What is detected
Risky configurations and exposures, surfaced in Secure Score

Attack stage

Posture, before any attack

What is detected
Lateral movement paths showing how an attacker could traverse

Attack stage

Non-human identities

What is detected
Abnormal behavior of service accounts, sync accounts and applications

Attack stage

Cross-environment

What is detected
Signals drawn from the local directory, from Entra, and from providers such as Okta
Attack stageWhat is detected
ReconnaissanceListing out account names, group memberships, addresses and available resources
Compromised credentialsBrute force, repeated failed authentications, suspicious group membership changes
Lateral movementAttempts to expand control of sensitive identities across environments
Domain dominanceCode run remotely on a controller, DCShadow, malicious replication, Golden Ticket
Posture, before any attackRisky configurations and exposures, surfaced in Secure Score
Posture, before any attackLateral movement paths showing how an attacker could traverse
Non-human identitiesAbnormal behavior of service accounts, sync accounts and applications
Cross-environmentSignals drawn from the local directory, from Entra, and from providers such as Okta
How a deployment runs

Five steps, and the sensors are the easy part.

Two to four weeks as a rule, and that includes the period it spends learning. The technical deployment itself is light. What matters is the preparation beforehand and what gets done with the output afterward.
  1. 1

    Confirm licensing and scope the identity infrastructure

    Whether your licensing already covers it, checked against the tenant rather than assumed, and what identity infrastructure falls in scope: the domain controllers, any Federation or Certificate Services, and whether an identity provider outside the Microsoft stack needs a connector.

  2. 2

    Audit and inventory before the baseline is set

    Privileged group membership worked out properly, service accounts written down with what each has legitimate business touching, and the obvious privilege routes closed wherever they can be. That narrows what the product has to reason about and makes the first findings readable instead of alarming.

  3. 3

    Deploy sensors and connectors

    Small sensors onto the identity infrastructure, reading and parsing traffic and Windows events on the machine itself, with only what is needed leaving for the cloud. Connectors where a second identity provider is involved. It is genuinely light, and it still touches domain controllers, so it goes through a proper change window like anything else that does.

  4. 4

    Work the posture findings while the baseline builds

    Behavioral detection needs time to work out what normal looks like, and the best use of that time is acting on the posture assessments and the lateral movement mapping, both of which are available on day one and depend on no learning at all. Most companies get their first real reduction in risk from this stage rather than from any alert.

  5. 5

    Tune, then agree the response rhythm

    The first alerts get worked through together, so that expected behavior is understood rather than silenced on sight, service account activity is explained rather than muted, and the response route is confirmed: who hears about it, how quickly, who has the authority to disable an account, and what happens at three in the morning.

Straight answers

What organizations ask about Defender for Identity.

An audit looks at one moment in time and finds the privilege routes, the over-permissioned service accounts and the delegations that are already there, producing a list of things to fix. This runs continuously and notices somebody actively moving through the place, producing incidents. Different questions, and we do both. The order that usually works is the audit first to close the obvious routes, then the detection, because putting detection over an unrepaired directory just generates alerts about a structure somebody should have corrected already.

Both. It watches identity signals coming from Active Directory on your own hardware, from Entra, and from other identity platforms, with Okta given as the worked example. That reach is exactly the point for American companies, most of which run a directory synchronized into a cloud tenant. An attacker moves between the two, and watching one side alone leaves you with half the picture.

The detections map onto four stages. Looking around, meaning somebody listing account names, group memberships, addresses and resources. Credentials in the wrong hands, covering password guessing at volume, repeated failures and group memberships changing suspiciously. Movement sideways across sensitive accounts and environments. And taking the domain outright, named specifically as code run remotely on a controller, DCShadow, malicious replication between controllers and Golden Ticket activity. Endpoint and mail tooling sees none of it, because not one of those involves a file or a message.

It maps how somebody could travel through your environment, which makes it preventive rather than detective. It answers a question most companies simply cannot: which perfectly ordinary account sits a short chain of steps from a domain administrator. The answer is usually uncomfortable, because the chain nearly always runs through somebody nobody had ever thought of as sensitive, and it can be acted on immediately without waiting for anyone to attack you.

Less than most people expect. Small sensors run on the identity infrastructure, reading and parsing the relevant traffic and Windows events on the machine itself, and only the signals actually needed leave for the cloud, which keeps the performance cost low and means the network does not have to be rebuilt around it. That is a great deal simpler than the port mirroring and appliance arrangement this class of product used to demand. It does still touch domain controllers, so it goes through a proper change window.

Usually yes, and for considerably longer than anybody plans for. Most American companies moving to Microsoft 365 keep the directory synchronized for years afterward, which means it is still authenticating people and still feeding cloud identity. A compromise on that side very often becomes a compromise of the tenant by way of the sync path. Once you are genuinely cloud only with no directory left at all, the case changes and deserves a fresh look rather than an assumption either way.

They are covered explicitly, and this is where the product turns up things nothing else would. Service accounts, sync accounts and applications are all named among the identities it watches that are not people. Those accounts carry real power, their passwords are almost never rotated, nobody has ever watched one, and somebody using one is invisible to any tool built around human behavior. We inventory them beforehand, partly because it sharpens the baseline and partly because the inventory turns out to be worth having in its own right.

That gets confirmed against your own tenant rather than claimed on a web page, because entitlement moves around by subscription and add-on and we would rather look than tell you something that turns out not to hold. What can be said generally is that a good number of companies already have this sitting inside an enterprise subscription bought for other reasons and never switched on, which makes establishing entitlement the first thing worth doing.

Fewer than people brace for, and the early ones deserve real attention. This works on behavior rather than signatures, so the opening weeks involve accounting for legitimate activity that happens to look strange, service accounts and administrative tooling above all. The discipline that matters is explaining rather than silencing. An alert muted without anybody working out why it fired is a detection you have switched off permanently for a reason nobody wrote down.

It detects, it gives you the context to investigate, and it supports acting against affected identities from the Defender portal, with alerts pulled together into single incidents alongside endpoint, mail and cloud signals. Whether an attack actually stops depends on a person doing something, which is exactly why the response question gets settled before deployment rather than after. Alerts about sideways movement and domain takeover do not arrive at convenient hours, and one that nobody answers at two in the morning is a record rather than a defense.

It watches signals from other identity platforms too, with Okta given as the worked example and connectors handling the integration. For American companies running a mixed identity estate, which is far more common than it sounds once acquisitions are counted, that means the picture can span both rather than leaving whichever provider arrived second entirely unwatched. That second one is almost always the less governed of the two.

It feeds identity signals into the Defender portal, where they are joined up with endpoint, mail, software as a service and cloud workload data into single incidents rather than scattered alerts. That joining up is the real argument for staying inside one family. An attack that begins with a phished message, lands on a laptop and then travels through identity arrives as one incident with a timeline attached, instead of three alerts in three consoles for somebody to assemble by hand at midnight.

It turns on the response question rather than on the deployment, which is light either way. Where nobody would act on a lateral movement alert outside office hours, the honest recommendation is to pair the detection with a managed response arrangement, or else to spend on the audit and the privilege reduction first, since those lower risk without requiring anybody to be awake for it. Commercially, each engagement is scoped on its own, driven by how much identity infrastructure is in play and whether the directory audit and the service account inventory are included. What you get for nothing in the first conversation is whether your existing licensing already covers it, and whether the audit or the detection is the more sensible next step in your particular case.
Before deploying

Fifteen questions worth answering first.

The first block asks whether this is the right thing to buy next. The second asks whether you are ready to deploy it. The third asks whether anybody would actually act on what it turns up, which is what decides whether the money is worth spending at all.

Is this the right next step

  • Have you audited the directory first?
    Closing the obvious privilege routes cuts the risk and the alert volume together.
  • Do you still run on-premises Active Directory?
    If you are cloud-only, the value proposition differs.
  • Do you synchronize identities to Microsoft Entra ID?
    The hybrid join is exactly what this monitors across.
  • Is there a real reason to suspect something is going on right now?
    If so, detection comes before audit rather than after.
  • Have you confirmed your licensing includes it?
    We check this rather than assuming, because it varies.

Deployment readiness

  • How many domain controllers would need sensors?
    Sensors run on identity infrastructure, not on every endpoint.
  • Are Certificate Services or Federation Services in the picture too?
    Additional identity infrastructure worth including in scope.
  • Is there a second identity provider outside the Microsoft stack?
    API connectors cover systems such as Okta.
  • Can you inventory your service accounts before you start?
    Their normal behavior is the baseline being learned.
  • Is there a change window for domain controller work?
    Light touch, and still domain controllers.

Would anybody act

  • Who receives an identity alert, and how quickly?
    Detection with no responder changes nothing.
  • If a lateral movement alert fired at two in the morning, would anybody act on it?
    These attacks do not respect office hours.
  • Is there an agreed way to shut down a compromised account quickly?
    Decided in advance, not during the incident.
  • Would the posture recommendations get actioned?
    They arrive in Secure Score and are frequently ignored.
  • Do you have or need a managed response arrangement?
    Worth deciding before buying detection.
Related reading

The pages around this one.

Active Directory

The on-premises directory this monitors, the hybrid identity model, and the attack paths that still run through it.

Learn more

Defender for Endpoint

The device half of the same family, and the plan comparison where Business Premium turns out, unexpectedly, to beat E3.

Learn more

Microsoft Entra

The cloud identity platform this watches alongside your own directory, plus the controls that shrink what an attacker can get to.

Learn more
Next step

Ask which of your everyday accounts is two moves from domain administrator.

That is precisely what the lateral movement mapping answers, and hardly any company can answer it today. If the directory has never been audited, that is the better opening move, and you will hear that from us rather than being sold detection to lay over a structure somebody should repair first.

Book an identity threat reviewSee the Microsoft security stack

Related Services

Explore more solutions that work great with this service

Microsoft Defender for Endpoint Services

EDR plan selection, onboarding and zero-gap AV migration

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

Microsoft Security Services

The Microsoft security stack deployed and managed end to end

Learn more

Microsoft Entra Conditional Access Design

Conditional Access design and review for US organizations:

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more

SOC-as-a-Service

24/7 security operations delivered as a service

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA