From the course: Configuring Windows Server Hybrid Advanced Services (AZ-801) Cert Prep by Microsoft Press

Unlock this course with a free trial

Join today to access over 25,600 courses taught by industry experts.

Implement and manage Microsoft Defender for Identity

Implement and manage Microsoft Defender for Identity

Active Directory is ground zero. If attackers own AD, they own your whole estate. Defender for Identity gives you visibility and control. So we're continuing our journey. The whole front part of this certification is squarely focused on Windows Server hybrid cloud security, and this is a good example of where Azure can be brought to bear to protect your local Active Directory domain services environment. What MDI or Microsoft Defender for Identity is, it's a cloud-based security system that works over the internet to protect your domain controllers. The sensors, as they're called, run locally on your DCs, capturing Kerberos, NTLM, LDAP, DNS traffic with a lightweight install and no reboot. Because MDI is a cloud service, it uses AI and machine learning in particular to detect suspicious account behavior. It builds a 30-day baseline, then flags anomalies like Pass the Hash, DC Sync, and Golden Ticket. An exam tip, by the way, for AZ-801, know that impossible travel and abnormal…

Contents