Microsoft Defender for Identity (MDI) watches on-premises Active Directory (AD) for attacks such as reconnaissance, credential theft, lateral movement and domain dominance. It needs to see authentication and directory traffic, so it relies on sensors installed on the servers that handle identity: every domain controller, plus Active Directory Federation Services (AD FS) servers, Active Directory Certificate Services (AD CS) servers and Microsoft Entra Connect servers. Missing even one domain controller creates a blind spot, because an attacker's Kerberos requests may go to the unmonitored one.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.