Microsoft Defender for Identity maps these for you: chains of shared logins and permissions that would let an intruder holding an ordinary account work their way up to privileged ones.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Lateral movement paths in context, with comparison tables and the common traps.
Terms in this definition
- Defender for Identity
Microsoft Defender service that detects attacks on identities, using sensors on on-premises Active Directory servers plus signals from Microsoft Entra ID and other identity providers; it does no access reviews or identity governance.
- MAPS
Short for Microsoft Active Protection Service. It gives Microsoft Defender Antivirus cloud verdicts on suspect files in seconds, and features like file indicators stop working if it is turned off or blocked.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
Related terms
- Cloud security graph
Context engine in Defender for Cloud that links inventory, exposure, permissions, vulnerabilities and lateral movement paths; attack path analysis and cloud security explorer both build on it, and Defender CSPM is required.
- SAM
The account database in Windows. Older Windows clients log on with the SAM account name, and Defender for Identity once queried local admins over the SAM-R protocol to map lateral movement paths, stopping that in mid-May 2025.