Skip to content
← Back to the guide

Microsoft Defender for Identity explained

8slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 8

Microsoft Defender for Identity explained

Defender for Identity detects identity-based attacks against on-prem Active Directory and Entra ID. Here's how it works.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-for-identity-explained

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 8
01

What does Defender for Identity do?

It monitors on-premises Active Directory (and AD FS, AD CS, Entra Connect) through sensors on domain controllers, detecting reconnaissance, lateral movement, credential theft (pass-the-hash, Kerberoasting, DCSync), and…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-for-identity-explained

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 8
02

Do I need Defender for Identity if I am cloud-only?

No — it protects on-premises Active Directory. A tenant with no AD DS has nothing for its sensors to watch; Entra ID Protection covers cloud identity risk. Hybrid organisations need both.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-for-identity-explained

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 8
03

What licence includes Defender for Identity?

Microsoft 365 E5, E5 Security, EMS E5, or standalone. Every user whose account is protected should be licensed; Microsoft's licensing is per user, not per domain controller.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-for-identity-explained

Slide 4Download PNG
M
solvingmicrosoft365.com
5 / 8
04

Hybrid tenant with on-prem AD DS

Verdict: Yes — sensor on every DC, plus Entra Connect. Highest-leverage security purchase on E5.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-for-identity-explained

Slide 5Download PNG
M
solvingmicrosoft365.com
6 / 8
05

Cloud-only tenant, no AD DS

Verdict: Skip MDI; rely on Entra ID Protection and Defender for Cloud Apps for identity-side signal.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-for-identity-explained

Slide 6Download PNG
M
solvingmicrosoft365.com
7 / 8
06

Federated via ADFS still

Verdict: Yes — MDI sensors on ADFS pick up the token-forging and password-spray patterns you cannot see cloud-side.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-for-identity-explained

Slide 7Download PNG
M
solvingmicrosoft365.com
8 / 8
07

Migrating off AD DS onto cloud-only

Verdict: Keep MDI running through the migration; the risky window is exactly when attackers try to pivot from the on-prem side.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-for-identity-explained

Slide 8Download PNG

Auto-generated from Microsoft Defender for Identity explained. This page is not indexed and isn't part of the guide itself.