Updated: May 31, 2023 (August 22, 2021)

  Analyst Report

Secure Active Directory with Microsoft Defender for Identity

My Atlas / Analyst Reports

1,150 wordsTime to read: 6 min
Wes Miller by
Wes Miller

Wes Miller analyzes and writes about Microsoft’s security, identity management, and systems management technologies. Before joining Directions on Microsoft, Wes... more

  • Microsoft Defender for Identity is a hosted service designed to help organizations discover malicious activities within their network.
  • It has a considerable deployment impact and requires extensive user subscription licensing.
  • Microsoft Defender for Identity replaces Advanced Threat Analytics on-premises software and provides improved analysis.

Microsoft Defender for Identity (previously Azure Advanced Threat Protection) captures, parses, and analyzes traffic of key unencrypted network protocols. It examines authentication, authorization, and other activities for indicators of potentially suspicious behavior by a user or on a device. These functions put Microsoft Defender for Identity in the category of a user behavioral analytics solutions, which Microsoft sometimes simply refers to as behavioral analytics.

Microsoft Defender for Identity looks for several distinct types of user behavior to help find and highlight potential intruders—ideally, before they have a chance to establish themselves within the organization’s systems. In particular, Microsoft Defender for Identity watches for:

Atlas Members have full access

Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.

Membership Options

Already have an account? Login Now