September 28, 2025

  Analyst Report

Defender for Endpoint Helps Discover Unsecured AD Servers

My Atlas / Analyst Reports

1,095 wordsTime to read: 6 min
Wes Miller by
Wes Miller

Wes Miller analyzes and writes about Microsoft’s security, identity management, and systems management technologies. Before joining Directions on Microsoft, Wes... more

  • Active Directory servers not protected by Defender for Identity are high-value targets for attack because of their role.
  • Defender for Endpoint can now help discover unprotected Active Directory identity servers, but Microsoft 365 E5 licenses are usually required.
  • Discovery includes Active Directory servers in the following roles: Federation Services, Certificate Services, and Entra Connect servers.

Identity management servers running Active Directory (AD) Federation Services and Certificate Services play a critical role in on-premises infrastructure. Their legacy nature leads many organizations to neglect them, leaving them vulnerable to attacks and a common vector for successful breaches. A new feature included in Defender for Endpoint should help organizations discover key identity servers that are not yet protected by Microsoft’s AD-defense service, Defender for Identity. Although finding unprotected servers requires Defender for Endpoint, remediating requires Defender for Identity as well, making the solution relevant only for organizations licensed for Microsoft 365 E5. 

Atlas Members have full access

Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.

Membership Options

Already have an account? Login Now