Microsoft Defender service that detects attacks on identities, using sensors on on-premises Active Directory servers plus signals from Microsoft Entra ID and other identity providers; it does no access reviews or identity governance.
Also called Microsoft Defender for Identity, Azure ATP.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Defender for Identity in context, with comparison tables and the common traps.
Terms in this definition
- AD
Short for Active Directory, the directory service built into Windows Server (AD DS). Entra Connect synchronises on-premises forests to Microsoft Entra ID.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
- Access reviews
Microsoft Entra ID Governance capability that periodically asks reviewers or users themselves to confirm membership for guests, app users or groups, removing anyone who does not respond. PIM, by contrast, handles privileged roles.
- Governance
Keeping cloud deployments in line with an organisation's rules on technology, security and compliance, helped by Azure Policy, tags and resource locks.
Related terms
- Enterprise exposure graph
Exposure Management's map of assets, identities, findings and how they connect, fed by Entra ID, Defender for Cloud, Defender for Endpoint, Defender for Identity and connectors. Attack paths are built from it, and advanced hunting can query it.
- IdentityLogonEvents
A table in advanced hunting holding authentication events from Microsoft online services (via Defender for Cloud Apps) and on-premises AD (via Defender for Identity). It only covers sign-ins that have already happened.
- ITDR
Identity threat detection and response: security tools that spot and react to attacks aimed at accounts and the systems that manage them. Microsoft offers Defender for Identity in this role.
- Lateral movement path
In Defender for Identity, a posture assessment showing routes by which stolen credentials could take an attacker from ordinary accounts to sensitive ones. Since mid-May 2025 the SAM-R gathering of local administrators that fed these maps has been switched off, so they no longer refresh that way.
- Lateral movement paths
Microsoft Defender for Identity maps these for you: chains of shared logins and permissions that would let an intruder holding an ordinary account work their way up to privileged ones.
- Pass-the-ticket
Also written PtT: a lateral movement method in which a stolen Kerberos ticket from one machine is replayed on a different one. Microsoft Defender for Identity has dedicated alerts for it.
- SAM
The account database in Windows. Older Windows clients log on with the SAM account name, and Defender for Identity once queried local admins over the SAM-R protocol to map lateral movement paths, stopping that in mid-May 2025.