defender-for-identity
Microsoft Defender for Identity
Microsoft Defender for Identity (MDI) is a cloud-based identity threat detection and response (ITDR) solution. Lightweight sensors on domain controllers and other identity infrastructure parse network traffic, ETW events, and AD object reads to detect reconnaissance, credential theft, lateral movement, and domain dominance. Signals correlate into Defender XDR incidents.
When to use
Detecting identity-based attacks against on-premises Active Directory, AD CS, AD FS, and Entra Connect — and surfacing identity posture issues (legacy protocols, unsecure accounts, risky delegations) that lead to those attacks.
Do not use this skill for cloud-only Entra ID risk detection — that is Entra ID
Protection (entra-id-protection). MDI sees on-prem and hybrid identity infrastructure.
Map the attack to a detection source
Pick the row that matches the attacker behaviour to confirm MDI is the right control and which sensor surface produces the signal.