Microsoft Defender
for Identity
Microsoft Defender for Identity is a cloud-based security solution from Microsoft that is used in conjunction with an organisation’s on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions.
Microsoft Defender for Identity (renamed from Azure Advanced Threat Protection or Azure ATP) is a cloud-based security solution from Microsoft that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organisation.
Monitor and profile user behaviour and activities
Defender for Identity monitors and analyses user activity and information across an organisation’s network, such as group membership and permissions which allows for the creation of a behavioural baseline for each user. Defender for Identity then identifies anomalies with adaptive built-in intelligence, giving you insights into suspicious activities and events, revealing the advanced threats, compromised users, and insider threats facing your organisation. Defender for Identity’s proprietary sensors monitor organizational domain controllers, providing a comprehensive view of all user activities from every device.
Reduce the attack surface and protect user identities
Through insights into user identities, Defender for Identity provides insights and configuration security best-practices and with the use of security reports, user profile analytics Defender for Identity helps reduce the attack surface of your organisation, making it harder for user credentials to be compromised and for advanced attacks to occur.
Identify suspicious activities and advanced cyber attacks
Most commonly, attacks are aimed at any accessible entity, in most cases a low-privileged user. Attackers then move laterally through the network until they are able to gain access to valuable assets, such as domain administrator accounts and Defender for Identity is designed to identify and protect against these threats.
Identify rouge reconnaissance
Advanced reconnaissance features in Defender for Identity allow rogue users and attackers to be identified as they attempt to again valuable organisational information such as user names, security groups, IP addresses and internal resources.
Identify compromised credentials
Quickly identify attempts to compromise user credentials through brute force attacks, failed authentications, user group membership changes and more.
Detect lateral movements
Detect attacks that mover laterally inside your organisation to gain further assess to higher privileged assets, such as domain administrator accounts, through the use of methods such as Pass the Hash, Overpass the Hash, Pass the Ticket and more.
Where can I get a license for Microsoft Defender for Identity?
Defender for Identity is available as part of Enterprise Mobility + Security 5 suite (EMS E5), and as a standalone license.
From £4.10 per user per month
Microsoft 365 Defender family
Defender for Endpoint
Microsoft Defender Antivirus is the next-generation protection component of Microsoft Defender for Endpoint. This protection brings together machine learning, big-data analysis, in-depth threat resistance research, and the Microsoft cloud infrastructure to protect devices in your organisation.
From £2.50 to £3.90
per user per month
Billing conditions apply
Defender for Office 365
Defender for Office 365 helps organisations secure their systems by offering a comprehensive suite of prevention, detection, investigation and hunting, response and remediation, awareness and training, and secure posture features.
From £1.64 to £4.10
per user per month
Billing conditions apply
Defender for Identity
Microsoft Defender for Identity is a cloud-based security solution from Microsoft that is used in conjunction with an organisation’s on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions.
From £4.10
per user per month
Billing conditions apply
Defender for Cloud Apps
Cloud App Security (CASB) allows organisations to better understand their overall cloud position across software as a service apps (SaaS) and cloud services and add controls to protect sensitive information.
From £2.60
per user per month
Billing conditions apply