1
00:00:00,000 --> 00:00:04,560
What happens when an attacker steals a legitimate password instead of breaking in through a firewall?

2
00:00:04,560 --> 00:00:08,880
I'm your host, Mirko Peters, and today we're talking about Microsoft Defender for Identity.

3
00:00:08,880 --> 00:00:11,440
Most security tools focus on the perimeter.

4
00:00:11,440 --> 00:00:14,640
They watch for malware, suspicious files, unusual network traffic,

5
00:00:14,640 --> 00:00:17,360
but identity attacks skip all of that entirely.

6
00:00:17,360 --> 00:00:20,080
An attacker with a stolen password doesn't need to break in.

7
00:00:20,080 --> 00:00:23,040
They just log in, and from the outside everything looks normal.

8
00:00:23,040 --> 00:00:27,520
By the end of this episode, you'll understand what Microsoft Defender for Identity actually is,

9
00:00:27,520 --> 00:00:32,320
why it exists, and how it watches for threats that traditional security tools completely miss.

10
00:00:32,320 --> 00:00:36,080
Let's start with why identity security has become the new battleground.

11
00:00:36,080 --> 00:00:37,760
The identity security problem.

12
00:00:37,760 --> 00:00:40,720
20 years ago, securing a network meant locking down the building,

13
00:00:40,720 --> 00:00:43,600
you set up a firewall, ran antivirus on every machine,

14
00:00:43,600 --> 00:00:45,760
and advised everyone to use strong passwords.

15
00:00:45,760 --> 00:00:49,600
That worked pretty well back then because attackers had to break through your defences to get in.

16
00:00:49,600 --> 00:00:54,080
They needed to find a vulnerability, exploit it, and then move around inside your network.

17
00:00:54,080 --> 00:00:57,040
The perimeter was the wall and the wall was strong, but here's the thing.

18
00:00:57,040 --> 00:00:58,480
That approach doesn't work anymore.

19
00:00:58,480 --> 00:01:00,320
Attackers don't break in, they just log in,

20
00:01:00,320 --> 00:01:02,640
they scoop up a legitimate password through phishing,

21
00:01:02,640 --> 00:01:06,560
a data breach, or a simple guess, and then stroll right through the front door.

22
00:01:06,560 --> 00:01:09,680
Compromised credentials are now behind 79% of ransomware attacks.

23
00:01:09,680 --> 00:01:10,720
That's not a niche problem.

24
00:01:10,720 --> 00:01:12,320
That's the main way attackers get in.

25
00:01:12,320 --> 00:01:13,440
And the numbers are serious.

26
00:01:13,440 --> 00:01:18,560
70% of organizations experienced at least one identity-related security breach in 2025.

27
00:01:18,560 --> 00:01:22,320
The average recovery cost, 1.64 million, that's not just the ransom payment.

28
00:01:22,320 --> 00:01:25,600
It's downtime, forensic investigation, legal fees, regulatory fines,

29
00:01:25,600 --> 00:01:26,960
and reputational damage.

30
00:01:26,960 --> 00:01:31,040
For mid-sized organizations, the median cost is still $750,000.

31
00:01:31,040 --> 00:01:33,440
So this isn't a theoretical risk. It's happening everywhere.

32
00:01:33,440 --> 00:01:35,200
Here's the core problem.

33
00:01:35,200 --> 00:01:40,000
Traditional security tools watch for malware, suspicious files, and unusual network connections.

34
00:01:40,000 --> 00:01:41,760
But they don't understand user behavior.

35
00:01:41,760 --> 00:01:43,840
They don't know if a login is normal or suspicious.

36
00:01:43,840 --> 00:01:47,200
An attacker with a stolen password looks exactly like a legitimate user.

37
00:01:47,200 --> 00:01:50,160
The same username, the same password, the same authentication process.

38
00:01:50,160 --> 00:01:51,680
The only difference is intent.

39
00:01:51,680 --> 00:01:54,480
And unless you're watching for abnormal patterns of behavior,

40
00:01:54,480 --> 00:01:56,160
you won't see it until it's too late.

41
00:01:56,160 --> 00:01:58,880
This is the gap that Defender for Identity was built to fill.

42
00:01:58,880 --> 00:02:00,240
It watches the watches.

43
00:02:00,240 --> 00:02:04,640
It monitors your identity infrastructure, learns what normal looks like for each user and device,

44
00:02:04,640 --> 00:02:06,240
and flags anything that doesn't fit.

45
00:02:06,240 --> 00:02:07,520
It's not looking for malware.

46
00:02:07,520 --> 00:02:09,760
It's looking for behavior that doesn't make sense.

47
00:02:09,760 --> 00:02:11,760
So what exactly is Defender for Identity?

48
00:02:11,760 --> 00:02:12,560
And how does it work?

49
00:02:12,560 --> 00:02:14,800
What is Defender for Identity?

50
00:02:14,800 --> 00:02:16,400
Here's the simplest definition.

51
00:02:16,400 --> 00:02:19,760
Microsoft Defender for Identity is a cloud-based security tool

52
00:02:19,760 --> 00:02:23,360
that watches your on-premises active directory for identity-based attacks.

53
00:02:23,360 --> 00:02:24,560
Notice I didn't say "entry"

54
00:02:24,560 --> 00:02:26,160
that's a common point of confusion.

55
00:02:26,160 --> 00:02:29,760
Defender for Identity focuses on your on-premises identity infrastructure,

56
00:02:29,760 --> 00:02:33,120
including domain controllers, active directory, and ADFS servers.

57
00:02:33,120 --> 00:02:36,240
This is the stuff that lives in your own data center or on your own servers.

58
00:02:36,240 --> 00:02:38,000
It's not a cloud-only solution.

59
00:02:38,000 --> 00:02:38,880
Now, how does it work?

60
00:02:38,880 --> 00:02:40,400
It uses behavioral analytics.

61
00:02:40,400 --> 00:02:43,120
It learns what's normal for each user and each device,

62
00:02:43,120 --> 00:02:44,880
and then it flags anything unusual.

63
00:02:44,880 --> 00:02:48,000
Think of it like a security guard who knows every employee's routine.

64
00:02:48,000 --> 00:02:50,800
They know who comes in at 8am, who works late,

65
00:02:50,800 --> 00:02:52,400
and who accesses the server room.

66
00:02:52,400 --> 00:02:55,280
When someone shows up at 3am trying to open the server room door,

67
00:02:55,280 --> 00:02:57,120
the guard notices immediately.

68
00:02:57,120 --> 00:02:58,960
That's exactly what Defender for Identity does,

69
00:02:58,960 --> 00:03:00,560
but for your digital environment.

70
00:03:00,560 --> 00:03:02,080
Let's clear up what this tool is not.

71
00:03:02,080 --> 00:03:03,200
It's not antivirus.

72
00:03:03,200 --> 00:03:04,160
It's not a firewall.

73
00:03:04,160 --> 00:03:05,760
It's not a patch management solution.

74
00:03:05,760 --> 00:03:09,040
It's identity-threat detection, a completely different category.

75
00:03:09,040 --> 00:03:10,960
It's not looking for malicious files.

76
00:03:10,960 --> 00:03:12,480
It's looking for malicious behavior.

77
00:03:12,480 --> 00:03:15,360
And that distinction matters because the most dangerous attacks today

78
00:03:15,360 --> 00:03:16,400
don't use malware at all.

79
00:03:16,400 --> 00:03:17,840
They use legitimate credentials.

80
00:03:17,840 --> 00:03:20,800
Defender for Identity sits inside Microsoft Defender XDR,

81
00:03:20,800 --> 00:03:23,520
which is Microsoft's extended detection and response platform.

82
00:03:23,520 --> 00:03:25,840
In practice, that means it shares signals

83
00:03:25,840 --> 00:03:28,720
with Defender for Endpoint, Defender for Office 365,

84
00:03:28,720 --> 00:03:29,920
and Microsoft Sentinel.

85
00:03:29,920 --> 00:03:32,720
So when Defender for Identity detects a suspicious login

86
00:03:32,720 --> 00:03:34,000
on a domain controller,

87
00:03:34,000 --> 00:03:38,960
it can cross-reference that with a phishing email detected by Defender for Office 365,

88
00:03:38,960 --> 00:03:42,800
or a suspicious process on a user's laptop detected by Defender for Endpoint.

89
00:03:42,800 --> 00:03:44,480
The real value isn't any single alert.

90
00:03:44,480 --> 00:03:47,840
It's how these tools work together to tell the full story of an attack.

91
00:03:47,840 --> 00:03:50,160
A single alert might look like a false positive,

92
00:03:50,160 --> 00:03:52,960
but when you see the whole picture, including the phishing email,

93
00:03:52,960 --> 00:03:55,360
the compromised credentials and the lateral movement,

94
00:03:55,360 --> 00:03:56,720
you know exactly what happened.

95
00:03:56,720 --> 00:03:59,280
Let's open the hood and look at how it actually detects threats.

96
00:03:59,280 --> 00:04:02,640
How it works, sensors and behavioral analytics.

97
00:04:02,640 --> 00:04:06,640
Defender for Identity uses lightweight sensors installed on your domain controllers.

98
00:04:06,640 --> 00:04:08,240
That's the key piece of the puzzle.

99
00:04:08,240 --> 00:04:09,760
Without the sensor, nothing happens.

100
00:04:09,760 --> 00:04:13,600
The sensor captures the data and is designed to be as unobtrusive as possible,

101
00:04:13,600 --> 00:04:15,120
running quietly in the background,

102
00:04:15,120 --> 00:04:17,120
reading network traffic and Windows events

103
00:04:17,120 --> 00:04:19,120
without slowing down your domain controller.

104
00:04:19,760 --> 00:04:22,800
Think of these sensors as the eyes and ears of the system.

105
00:04:22,800 --> 00:04:24,720
They capture three main types of information,

106
00:04:24,720 --> 00:04:26,720
network traffic to see authentication requests,

107
00:04:26,720 --> 00:04:27,760
flowing between machines,

108
00:04:27,760 --> 00:04:30,400
Windows events to see what's happening at the operating system level,

109
00:04:30,400 --> 00:04:33,760
and authentication activity to see who's logging in from where and when.

110
00:04:33,760 --> 00:04:38,320
All of that data gets sent to the Defender for Identity Cloud Service for Analysis.

111
00:04:38,320 --> 00:04:40,160
The sensor doesn't do the heavy lifting itself,

112
00:04:40,160 --> 00:04:41,440
it just collects and forwards.

113
00:04:41,440 --> 00:04:44,320
Once the data reaches the cloud, the real work begins.

114
00:04:44,320 --> 00:04:48,880
The Cloud Service builds a baseline profile for every single user in your environment.

115
00:04:48,880 --> 00:04:50,800
It learns their typical login times,

116
00:04:50,800 --> 00:04:52,720
which workstations they usually use,

117
00:04:52,720 --> 00:04:54,480
and what resources they normally access.

118
00:04:54,480 --> 00:04:56,160
This is the behavioral analytics part.

119
00:04:56,160 --> 00:04:59,200
The system doesn't come with pre-configured rules about what's normal.

120
00:04:59,200 --> 00:05:00,640
It learns from your actual environment,

121
00:05:00,640 --> 00:05:03,600
and that's important because normal looks different for every organization,

122
00:05:03,600 --> 00:05:05,520
when something deviates from that baseline,

123
00:05:05,520 --> 00:05:06,720
and alert fires.

124
00:05:06,720 --> 00:05:10,160
For example, a user who always logs in from 9 a.m. to 5 p.m.

125
00:05:10,160 --> 00:05:11,760
suddenly authenticates at 3 a.m.

126
00:05:11,760 --> 00:05:13,520
from a workstation they've never used before.

127
00:05:13,520 --> 00:05:14,240
That's a deviation.

128
00:05:14,240 --> 00:05:15,120
The system flags it.

129
00:05:15,120 --> 00:05:16,880
It doesn't assume it's malicious right away,

130
00:05:16,880 --> 00:05:19,840
but it raises the alert so your security team can investigate.

131
00:05:19,840 --> 00:05:21,680
What kinds of attacks does it actually detect?

132
00:05:21,680 --> 00:05:23,520
The list is long, but here are the big ones.

133
00:05:23,520 --> 00:05:24,800
Pass the hash attacks,

134
00:05:24,800 --> 00:05:28,080
where an attacker steals a password hash and uses it to authenticate.

135
00:05:28,080 --> 00:05:29,120
Kerberoasting,

136
00:05:29,120 --> 00:05:31,760
where an attacker requests service tickets for privileged accounts

137
00:05:31,760 --> 00:05:32,960
and cracks them offline.

138
00:05:32,960 --> 00:05:34,160
Golden ticket usage,

139
00:05:34,160 --> 00:05:35,920
where an attacker forges a Kerberoast ticket

140
00:05:35,920 --> 00:05:37,680
to gain domain-wide access.

141
00:05:37,680 --> 00:05:38,880
DC sync attacks,

142
00:05:38,880 --> 00:05:41,280
where an attacker pretends to be a domain controller

143
00:05:41,280 --> 00:05:43,040
and requests password hashes.

144
00:05:43,040 --> 00:05:44,000
And lateral movement,

145
00:05:44,000 --> 00:05:46,320
where an attacker uses one compromised account

146
00:05:46,320 --> 00:05:48,080
to hop from machine to machine.

147
00:05:48,080 --> 00:05:50,560
Each detection is mapped to the Miter attack framework,

148
00:05:50,560 --> 00:05:53,280
which is the industry standard for describing attack techniques.

149
00:05:53,280 --> 00:05:55,520
So when defender for identity flags something,

150
00:05:55,520 --> 00:05:57,760
it doesn't just say suspicious activity.

151
00:05:57,760 --> 00:05:59,920
It says, "This is a pass the hash attack,

152
00:05:59,920 --> 00:06:03,120
mapped to technique T-Fun Feen 50 on 0.0.2."

153
00:06:03,120 --> 00:06:05,280
That gives your security team immediate context

154
00:06:05,280 --> 00:06:07,520
about what they're dealing with and how to respond.

155
00:06:07,520 --> 00:06:08,720
Here's the real difference.

156
00:06:08,720 --> 00:06:10,400
It doesn't just tell you something happened,

157
00:06:10,400 --> 00:06:11,760
it shows you the attack timeline.

158
00:06:11,760 --> 00:06:14,880
It traces how the attacker moved from point A to point B.

159
00:06:14,880 --> 00:06:17,600
So instead of a single alert that says, "Suspicious login,"

160
00:06:17,600 --> 00:06:18,800
you get a full story.

161
00:06:18,800 --> 00:06:20,560
The initial compromise, the lateral movement,

162
00:06:20,560 --> 00:06:22,000
the privilege escalation

163
00:06:22,000 --> 00:06:23,360
and the domain dominance

164
00:06:23,360 --> 00:06:25,520
all connected in a single timeline.

165
00:06:25,520 --> 00:06:27,680
That's the difference between a tool that alerts you

166
00:06:27,680 --> 00:06:29,760
and a tool that helps you understand.

167
00:06:29,760 --> 00:06:31,520
Let's walk through the stages of an attack

168
00:06:31,520 --> 00:06:34,320
and see where defender for identity catches each one.

169
00:06:34,320 --> 00:06:36,240
The attack lifecycle it catches.

170
00:06:36,240 --> 00:06:38,320
So attackers follow a predictable pattern.

171
00:06:38,320 --> 00:06:39,520
It's not random at all.

172
00:06:39,520 --> 00:06:40,560
They go through stages,

173
00:06:40,560 --> 00:06:42,400
and each stage has a specific goal.

174
00:06:42,400 --> 00:06:44,000
The stages are reconnaissance,

175
00:06:44,000 --> 00:06:46,160
compromised credentials, lateral movement,

176
00:06:46,160 --> 00:06:47,360
and domain dominance.

177
00:06:47,360 --> 00:06:48,560
Once you understand these stages,

178
00:06:48,560 --> 00:06:51,280
you'll see exactly where defender for identity fits in.

179
00:06:51,280 --> 00:06:52,880
But what does that actually look like?

180
00:06:52,880 --> 00:06:54,240
Let's start with reconnaissance.

181
00:06:54,240 --> 00:06:55,920
The attacker has no access yet.

182
00:06:55,920 --> 00:06:58,000
They're just looking around, scanning your network,

183
00:06:58,000 --> 00:07:00,560
searching for accounts, groups, and trust relationships.

184
00:07:00,560 --> 00:07:02,640
They're trying to figure out who the administrators are,

185
00:07:02,640 --> 00:07:04,480
which accounts have elevated privileges

186
00:07:04,480 --> 00:07:06,000
and how the domain is structured.

187
00:07:06,000 --> 00:07:07,600
They often use tools like Bloodhound

188
00:07:07,600 --> 00:07:09,120
to map out the environment.

189
00:07:09,120 --> 00:07:10,720
Defender for identity spots this

190
00:07:10,720 --> 00:07:12,960
by watching for suspicious LDP queries

191
00:07:12,960 --> 00:07:14,400
or enumeration attempts.

192
00:07:14,400 --> 00:07:16,320
An alert fires when someone starts querying

193
00:07:16,320 --> 00:07:17,680
for all domain admin accounts

194
00:07:17,680 --> 00:07:19,600
from a workstation that's never done that before.

195
00:07:19,600 --> 00:07:21,280
The attacker hasn't done anything harmful yet,

196
00:07:21,280 --> 00:07:22,480
but you know they're looking.

197
00:07:22,480 --> 00:07:24,080
Next up is compromised credentials.

198
00:07:24,080 --> 00:07:26,320
The attacker has found a way to get a password

199
00:07:26,320 --> 00:07:27,760
through phishing, a data breach,

200
00:07:27,760 --> 00:07:29,440
or buying it on the dark web.

201
00:07:29,440 --> 00:07:32,000
Now they have a legitimate username and password.

202
00:07:32,000 --> 00:07:35,040
Defender for identity flags, unusual logins at this stage.

203
00:07:35,040 --> 00:07:37,280
Unusual logins include a user signing in

204
00:07:37,280 --> 00:07:39,600
from a new location at 3am,

205
00:07:39,600 --> 00:07:41,840
or suddenly accessing hundreds of files

206
00:07:41,840 --> 00:07:43,280
instead of their usual five.

207
00:07:43,280 --> 00:07:44,960
These are behavioral deviations

208
00:07:44,960 --> 00:07:46,960
that don't require malware detection.

209
00:07:46,960 --> 00:07:49,440
They just require understanding what normal looks like.

210
00:07:49,440 --> 00:07:50,640
Then comes lateral movement.

211
00:07:50,640 --> 00:07:51,840
The attacker has a foothold,

212
00:07:51,840 --> 00:07:54,000
but it's probably not a privileged account yet.

213
00:07:54,000 --> 00:07:55,440
They need to move across your network

214
00:07:55,440 --> 00:07:57,040
to reach high-value targets.

215
00:07:57,040 --> 00:07:58,720
They use techniques like Pass the hash,

216
00:07:58,720 --> 00:07:59,440
Pass the ticket,

217
00:07:59,440 --> 00:08:02,080
and overpass the hash to hop from machine to machine.

218
00:08:02,080 --> 00:08:04,000
Each hop looks like a legitimate authentication,

219
00:08:04,000 --> 00:08:05,440
but the pattern is suspicious.

220
00:08:05,440 --> 00:08:06,880
Defender for identity detects this

221
00:08:06,880 --> 00:08:09,040
by watching for authentication anomalies.

222
00:08:09,040 --> 00:08:10,400
If a user account authenticates

223
00:08:10,400 --> 00:08:12,560
from three different workstations in five minutes,

224
00:08:12,560 --> 00:08:14,160
that's not normal human behavior.

225
00:08:14,160 --> 00:08:15,840
That's an attacker moving laterally.

226
00:08:15,840 --> 00:08:17,280
Finally, domain dominance.

227
00:08:17,280 --> 00:08:20,160
What you see, alerts, incidents, and taking action,

228
00:08:20,160 --> 00:08:22,400
open the Microsoft Defender Portal at Security,

229
00:08:22,400 --> 00:08:24,240
Microsoft.com and navigate to identities.

230
00:08:24,240 --> 00:08:25,440
That's your command center.

231
00:08:25,440 --> 00:08:27,520
The first thing you'll see is the dashboard,

232
00:08:27,520 --> 00:08:29,040
which gives you a quick overview

233
00:08:29,040 --> 00:08:31,360
of everything happening in your identity environment.

234
00:08:31,360 --> 00:08:33,040
How many users are being monitored,

235
00:08:33,040 --> 00:08:34,720
how many active alerts are open,

236
00:08:34,720 --> 00:08:37,280
and the health status of your sensors.

237
00:08:37,280 --> 00:08:38,720
It's designed to give you a snapshot

238
00:08:38,720 --> 00:08:40,320
in seconds, not minutes.

239
00:08:40,320 --> 00:08:41,920
There's also a score on that dashboard

240
00:08:41,920 --> 00:08:44,000
called the Identity Security Score.

241
00:08:44,000 --> 00:08:45,520
It's a zero to 100 number that shows

242
00:08:45,520 --> 00:08:47,760
how well you're protecting your identity infrastructure.

243
00:08:47,760 --> 00:08:49,120
This isn't a theoretical metric.

244
00:08:49,120 --> 00:08:51,520
It's based on actual configurations and recommendations.

245
00:08:51,520 --> 00:08:53,360
If you have domain controllers without sensors,

246
00:08:53,360 --> 00:08:54,400
your score drops.

247
00:08:54,400 --> 00:08:56,720
If you have users without multi-factor authentication,

248
00:08:56,720 --> 00:08:57,840
your score drops.

249
00:08:57,840 --> 00:08:58,880
Fix those issues,

250
00:08:58,880 --> 00:09:00,240
and your score goes up.

251
00:09:00,240 --> 00:09:03,200
It's a concrete way to track your security posture over time.

252
00:09:03,200 --> 00:09:04,560
Now, let's talk about alerts.

253
00:09:04,560 --> 00:09:06,880
Alerts are generated by detection rules.

254
00:09:06,880 --> 00:09:07,920
Pre-configured conditions

255
00:09:07,920 --> 00:09:10,240
that define what suspicious behavior looks like.

256
00:09:10,240 --> 00:09:11,680
Based on years of threat research,

257
00:09:11,680 --> 00:09:13,840
Microsoft has built hundreds of these rules.

258
00:09:13,840 --> 00:09:16,240
When a user logs in from an unusual location,

259
00:09:16,240 --> 00:09:17,280
that's a detection rule.

260
00:09:17,280 --> 00:09:18,720
When someone tries a DC sync attack,

261
00:09:18,720 --> 00:09:20,000
that's a detection rule.

262
00:09:20,000 --> 00:09:21,680
When an attacker uses a golden ticket,

263
00:09:21,680 --> 00:09:23,040
that's a detection rule.

264
00:09:23,040 --> 00:09:24,400
The system is constantly comparing

265
00:09:24,400 --> 00:09:26,800
what's happening in your environment against these rules.

266
00:09:26,800 --> 00:09:27,840
But here's the thing,

267
00:09:27,840 --> 00:09:30,720
multiple alerts can combine into a single incident.

268
00:09:30,720 --> 00:09:33,600
That's important because attackers don't do one suspicious thing.

269
00:09:33,600 --> 00:09:35,120
They do many things in sequence.

270
00:09:35,120 --> 00:09:37,200
A single alert might look like a false positive,

271
00:09:37,200 --> 00:09:38,800
but when you see the full incident,

272
00:09:38,800 --> 00:09:40,880
the reconnaissance, the credential compromise,

273
00:09:40,880 --> 00:09:42,880
the lateral movement, the domain dominance,

274
00:09:42,880 --> 00:09:44,240
you know exactly what happened.

275
00:09:44,240 --> 00:09:45,600
The incident is the story.

276
00:09:45,600 --> 00:09:47,520
The alerts are just individual sentences.

277
00:09:47,520 --> 00:09:49,440
Each incident includes an attack graph.

278
00:09:49,440 --> 00:09:51,200
This is a visual map of how the attacker

279
00:09:51,200 --> 00:09:52,640
moved through your environment.

280
00:09:52,640 --> 00:09:54,000
It shows you the starting point,

281
00:09:54,000 --> 00:09:55,120
every hop along the way,

282
00:09:55,120 --> 00:09:56,560
and the final destination.

283
00:09:56,560 --> 00:09:58,240
You can see which accounts were compromised,

284
00:09:58,240 --> 00:09:59,440
which machines were accessed,

285
00:09:59,440 --> 00:10:00,640
and which techniques were used.

286
00:10:00,640 --> 00:10:02,480
It's like watching a security camera replay

287
00:10:02,480 --> 00:10:03,680
of the entire attack,

288
00:10:03,680 --> 00:10:04,880
but in diagram form,

289
00:10:04,880 --> 00:10:07,200
and you can take action directly from the portal.

290
00:10:07,200 --> 00:10:09,440
If you identify a compromised user account,

291
00:10:09,440 --> 00:10:12,080
you don't need to log into your domain controller to disable it.

292
00:10:12,080 --> 00:10:14,080
You can do it right from the Defender portal,

293
00:10:14,080 --> 00:10:15,120
disable the account,

294
00:10:15,120 --> 00:10:16,320
force a password reset,

295
00:10:16,320 --> 00:10:17,760
request a sign in attempt,

296
00:10:17,760 --> 00:10:20,960
the sensor communicates back to your on-premises active directory,

297
00:10:20,960 --> 00:10:22,720
and makes the change instantly.

298
00:10:22,720 --> 00:10:25,360
That's the power of having the sensor on your domain controller.

299
00:10:25,360 --> 00:10:27,040
It's not just listening, it can act.

300
00:10:27,040 --> 00:10:29,280
You can also configure email notifications.

301
00:10:29,280 --> 00:10:30,560
When a critical alert fires,

302
00:10:30,560 --> 00:10:32,720
your security team gets an email instantly.

303
00:10:32,720 --> 00:10:35,200
They don't have to monitor the dashboard 24/7,

304
00:10:35,200 --> 00:10:36,320
the system alerts them.

305
00:10:36,320 --> 00:10:39,440
And because the alerts are mapped to the Miter ATTANK framework,

306
00:10:39,440 --> 00:10:41,680
they know exactly what kind of attack they're dealing with

307
00:10:41,680 --> 00:10:43,680
before they even open the portal.

308
00:10:43,680 --> 00:10:44,640
Beyond the basics,

309
00:10:44,640 --> 00:10:47,360
there are a few advanced features worth knowing about.

310
00:10:47,360 --> 00:10:49,440
Honeypots, tagging, and exclusions.

311
00:10:49,440 --> 00:10:50,800
Let's talk about Honeypots accounts.

312
00:10:50,800 --> 00:10:52,480
These are also called Honey tokens,

313
00:10:52,480 --> 00:10:54,320
and they're exactly what they sound like.

314
00:10:54,320 --> 00:10:55,280
Fake user accounts,

315
00:10:55,280 --> 00:10:57,760
you create specifically to lure attackers.

316
00:10:57,760 --> 00:10:58,880
You give them a tempting name,

317
00:10:58,880 --> 00:11:01,760
like Exchange Admin or Domain Backup Service.

318
00:11:01,760 --> 00:11:04,160
You give them a high-privileged sounding group membership.

319
00:11:04,160 --> 00:11:05,280
But here's the catch.

320
00:11:05,280 --> 00:11:07,040
These accounts have no real use.

321
00:11:07,040 --> 00:11:08,480
Nobody should ever log into them.

322
00:11:08,480 --> 00:11:10,240
They're not used for any legitimate purpose.

323
00:11:10,240 --> 00:11:11,840
They just sit there waiting.

324
00:11:11,840 --> 00:11:13,840
If someone does log into a Honeypot account,

325
00:11:13,840 --> 00:11:15,040
you know immediately.

326
00:11:15,040 --> 00:11:16,720
Not because you set up custom monitoring,

327
00:11:16,720 --> 00:11:18,800
not because you wrote a complex detection rule,

328
00:11:18,800 --> 00:11:21,040
because Defender for Identity knows that account

329
00:11:21,040 --> 00:11:22,240
should never be used.

330
00:11:22,240 --> 00:11:23,840
The moment someone authenticates with it,

331
00:11:23,840 --> 00:11:24,880
an alert fires.

332
00:11:24,880 --> 00:11:26,240
And you know exactly what happened.

333
00:11:26,240 --> 00:11:28,880
An attacker found your decoy account and tried to use it.

334
00:11:28,880 --> 00:11:30,400
That's not a false positive.

335
00:11:30,400 --> 00:11:32,160
That's a confirmed intrusion attempt.

336
00:11:32,160 --> 00:11:33,760
You can set these up in the Defender portal

337
00:11:33,760 --> 00:11:36,000
under settings identities honey tokens.

338
00:11:36,000 --> 00:11:37,680
It takes about 30 seconds.

339
00:11:37,680 --> 00:11:39,360
Entity tagging is another feature.

340
00:11:39,360 --> 00:11:40,960
You can mark specific users,

341
00:11:40,960 --> 00:11:44,160
devices or groups as sensitive for extra monitoring.

342
00:11:44,160 --> 00:11:45,200
Think about what that means.

343
00:11:45,200 --> 00:11:47,520
If you tag a Domain Admin account as sensitive,

344
00:11:47,520 --> 00:11:49,840
Defender for Identity watches every single action

345
00:11:49,840 --> 00:11:51,600
that account takes more closely.

346
00:11:51,600 --> 00:11:53,520
Any deviation from normal behavior

347
00:11:53,520 --> 00:11:55,280
gets flagged with higher priority.

348
00:11:55,280 --> 00:11:57,200
Any lateral movement involving that account

349
00:11:57,200 --> 00:11:58,160
gets escalated,

350
00:11:58,160 --> 00:12:00,960
it's like putting a GPS tracker on your most valuable assets.

351
00:12:00,960 --> 00:12:02,320
And then there are exclusion rules,

352
00:12:02,320 --> 00:12:03,920
sometimes legitimate security tools

353
00:12:03,920 --> 00:12:06,080
or admin processes trigger false alarms.

354
00:12:06,080 --> 00:12:07,920
Your vulnerability scanner might authenticate

355
00:12:07,920 --> 00:12:09,760
against every machine in the network.

356
00:12:09,760 --> 00:12:10,720
That looks suspicious.

357
00:12:10,720 --> 00:12:13,040
Your backup software might access domain controllers

358
00:12:13,040 --> 00:12:14,080
at unusual hours.

359
00:12:14,080 --> 00:12:15,440
That also looks suspicious.

360
00:12:15,440 --> 00:12:17,520
You can exclude specific IP addresses,

361
00:12:17,520 --> 00:12:19,760
devices or users from certain detection rules

362
00:12:19,760 --> 00:12:23,120
so those false positives don't clutter your alert queue.

363
00:12:23,120 --> 00:12:25,760
Global exclusion apply to all detection rules.

364
00:12:25,760 --> 00:12:27,920
Per-rule exclusions are more targeted.

365
00:12:27,920 --> 00:12:28,960
The goal is the same.

366
00:12:28,960 --> 00:12:32,000
Reduce noise so your security team focuses on real threats.

367
00:12:32,320 --> 00:12:34,240
Defender for Identity doesn't work alone.

368
00:12:34,240 --> 00:12:36,480
Let's see how it fits into the bigger picture.

369
00:12:36,480 --> 00:12:39,200
How it fits in Microsoft's security ecosystem.

370
00:12:39,200 --> 00:12:42,160
So how does Defender for Identity fit into Microsoft's

371
00:12:42,160 --> 00:12:43,520
bigger security picture?

372
00:12:43,520 --> 00:12:45,920
Think of it as one piece of the Defender XDR puzzle.

373
00:12:45,920 --> 00:12:47,840
On its own, each tool is useful,

374
00:12:47,840 --> 00:12:50,240
but the real power comes when they work together.

375
00:12:50,240 --> 00:12:52,560
Defender for endpoint guards your devices.

376
00:12:52,560 --> 00:12:54,080
It checks every laptop and server

377
00:12:54,080 --> 00:12:56,320
for malware and suspicious network activity.

378
00:12:56,320 --> 00:12:58,800
Defender for Office 365 protects your email

379
00:12:58,800 --> 00:12:59,840
and collaboration tools,

380
00:12:59,840 --> 00:13:02,080
catching phishing attempts and malicious attachments.

381
00:13:02,080 --> 00:13:05,040
And Defender for Identity, it watches over your user accounts,

382
00:13:05,040 --> 00:13:06,480
looking for stolen credentials,

383
00:13:06,480 --> 00:13:08,240
lateral movement and domain dominance.

384
00:13:08,240 --> 00:13:10,080
On their own, each tool is useful,

385
00:13:10,080 --> 00:13:11,040
but here's the thing.

386
00:13:11,040 --> 00:13:13,920
Together, they share signals and connect the dots.

387
00:13:13,920 --> 00:13:16,720
Imagine a suspicious login on a domain controller.

388
00:13:16,720 --> 00:13:18,880
That same login could be linked to a phishing email

389
00:13:18,880 --> 00:13:21,520
that Defender for Office 365 already caught.

390
00:13:21,520 --> 00:13:23,120
The attacker compromises the mailbox

391
00:13:23,120 --> 00:13:25,040
and is now trying to move laterally.

392
00:13:25,040 --> 00:13:26,720
Defender for Identity sees the login,

393
00:13:26,720 --> 00:13:29,120
Defender for Office 365 sees the email

394
00:13:29,120 --> 00:13:31,520
and the Microsoft Defender XDR platform

395
00:13:31,520 --> 00:13:32,880
creates a single incident.

396
00:13:32,880 --> 00:13:34,720
That's the difference between isolated alerts

397
00:13:34,720 --> 00:13:36,160
and a complete attack story.

398
00:13:36,160 --> 00:13:38,000
It also integrates with Microsoft Sentinel,

399
00:13:38,000 --> 00:13:40,160
which is Microsoft's cloud native CM.

400
00:13:40,160 --> 00:13:41,760
That's where you go for advanced hunting

401
00:13:41,760 --> 00:13:42,960
and custom detections.

402
00:13:42,960 --> 00:13:46,000
You can write custocheries that search across all your defender data,

403
00:13:46,000 --> 00:13:48,640
Identity, endpoint, email, cloud apps,

404
00:13:48,640 --> 00:13:52,000
and find patterns that automated rules don't always catch.

405
00:13:52,000 --> 00:13:54,400
And it works alongside Microsoft EntraID Protection.

406
00:13:54,400 --> 00:13:55,600
Here's the distinction.

407
00:13:55,600 --> 00:13:58,400
EntraID Protection handles cloud-based sign-in risks

408
00:13:58,400 --> 00:14:00,640
like risky sign-ins from anonymous IP addresses

409
00:14:00,640 --> 00:14:01,920
or a typical travel.

410
00:14:01,920 --> 00:14:04,560
Defender for Identity handles on-premises threats

411
00:14:04,560 --> 00:14:06,160
like watching your domain controllers,

412
00:14:06,160 --> 00:14:08,240
active directory and ADFS servers.

413
00:14:08,240 --> 00:14:10,880
Microsoft recommends using both for defense and depth

414
00:14:10,880 --> 00:14:12,240
in hybrid environments.

415
00:14:12,240 --> 00:14:13,920
The magic isn't any single product.

416
00:14:13,920 --> 00:14:16,000
It's how they all talk to each other.

417
00:14:16,000 --> 00:14:18,560
Let's wrap up with what you should do next.

418
00:14:18,560 --> 00:14:19,600
Here's the takeaway.

419
00:14:19,600 --> 00:14:21,600
Defender for Identity fills a gap

420
00:14:21,600 --> 00:14:23,840
that traditional security tools leave open.

421
00:14:23,840 --> 00:14:25,600
It watches for Identity-based attacks

422
00:14:25,600 --> 00:14:26,960
using stolen credentials.

423
00:14:26,960 --> 00:14:28,640
It catches attackers who don't break in.

424
00:14:28,640 --> 00:14:29,520
They log in.

425
00:14:29,520 --> 00:14:31,040
And it's not complicated.

426
00:14:31,040 --> 00:14:32,480
Sensors on your domain controllers

427
00:14:32,480 --> 00:14:34,640
plus behavioral analytics in the cloud

428
00:14:34,640 --> 00:14:36,640
equals real-time threat detection.

429
00:14:36,640 --> 00:14:37,920
The simplest next step?

430
00:14:37,920 --> 00:14:41,600
Check if your domain controllers are running Windows Server 2019 or above.

431
00:14:41,600 --> 00:14:43,520
If they are, you can activate the new sensor

432
00:14:43,520 --> 00:14:44,880
from the Defender portal today.

433
00:14:44,880 --> 00:14:47,040
There's no download, no installation,

434
00:14:47,040 --> 00:14:48,000
just a few clicks.

435
00:14:48,000 --> 00:14:50,000
Subscribe on your favorite podcast platform

436
00:14:50,000 --> 00:14:50,960
and share this with someone

437
00:14:50,960 --> 00:14:53,200
who's starting their Identity Security journey.

438
00:14:53,200 --> 00:14:55,280
And click here for our next episode

439
00:14:55,280 --> 00:14:57,680
on Microsoft, Enter ID Protection,

440
00:14:57,680 --> 00:15:00,480
the Cloud Side Companion to Defender for Identity.

