Active Directory Members Only

Microsoft Defender for Identity

Microsoft Defender for Identity (MDI) is the cloud-powered behavioral detection platform for Active Directory. Its sensors sit on every DC, capture network traffic and Windows event logs, and feed a cloud ML backend that detects Kerberoasting, Pass-the-Hash, DCSync, Golden Tickets, and lateral movement. This covers sensor deployment, what alerts look like, detection quality, and how attackers attempt to evade it.

Related Articles