Microsoft Defender
for Identity

Microsoft Defender for Identity is a cloud-based security solution from Microsoft that is used in conjunction with an organisation’s on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions.

Microsoft Defender for Identity (renamed from Azure Advanced Threat Protection or Azure ATP) is a cloud-based security solution from Microsoft that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organisation.

Monitor users

Monitor and profile user behaviour and activities

Defender for Identity monitors and analyses user activity and information across an organisation’s network, such as group membership and permissions which allows for the creation of a behavioural baseline for each user. Defender for Identity then identifies anomalies with adaptive built-in intelligence, giving you insights into suspicious activities and events, revealing the advanced threats, compromised users, and insider threats facing your organisation. Defender for Identity’s proprietary sensors monitor organizational domain controllers, providing a comprehensive view of all user activities from every device.

Reduce the attack surface

Reduce the attack surface and protect user identities

Through insights into user identities, Defender for Identity provides insights and configuration security best-practices and with the use of security reports, user profile analytics Defender for Identity helps reduce the attack surface of your organisation, making it harder for user credentials to be compromised and for advanced attacks to occur.

Identify suspicious activities

Identify suspicious activities and advanced cyber attacks

Most commonly, attacks are aimed at any accessible entity, in most cases a low-privileged user. Attackers then move laterally through the network until they are able to gain access to valuable assets, such as domain administrator accounts and Defender for Identity is designed to identify and protect against these threats.

Identify rouge reconnaissance

Identify rouge reconnaissance

Advanced reconnaissance features in Defender for Identity allow rogue users and attackers to be identified as they attempt to again valuable organisational information such as user names, security groups, IP addresses and internal resources.

compromised credentials

Identify compromised credentials

Quickly identify attempts to compromise user credentials through brute force attacks, failed authentications, user group membership changes and more.

Detect lateral movements

Detect lateral movements

Detect attacks that mover laterally inside your organisation to gain further assess to higher privileged assets, such as domain administrator accounts, through the use of methods such as Pass the Hash, Overpass the Hash, Pass the Ticket and more.

Where can I get a license for Microsoft Defender for Identity?

Defender for Identity is available as part of Enterprise Mobility + Security 5 suite (EMS E5), and as a standalone license.

From £4.10 per user per month

Billing conditions apply

Microsoft 365 Defender family

Defender for Endpoint

Microsoft Defender Antivirus is the next-generation protection component of Microsoft Defender for Endpoint. This protection brings together machine learning, big-data analysis, in-depth threat resistance research, and the Microsoft cloud infrastructure to protect devices in your organisation.

From £2.50 to £3.90

per user per month
Billing conditions apply

Defender for Office 365

Defender for Office 365 helps organisations secure their systems by offering a comprehensive suite of prevention, detection, investigation and hunting, response and remediation, awareness and training, and secure posture features.

From £1.64 to £4.10

per user per month
Billing conditions apply

Defender for Identity

Microsoft Defender for Identity is a cloud-based security solution from Microsoft that is used in conjunction with an organisation’s on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions.

From £4.10

per user per month
Billing conditions apply

Defender for Cloud Apps

Cloud App Security (CASB) allows organisations to better understand their overall cloud position across software as a service apps (SaaS) and cloud services and add controls to protect sensitive information.

From £2.60

per user per month
Billing conditions apply