Defender for Identity
Identity threat detection for Active Directory and Entra ID.
Microsoft Defender for Identity detects identity-based attacks across on-premises Active Directory and Entra ID — catching reconnaissance, credential theft, lateral movement, and domain dominance techniques that traditional tools miss. It monitors domain controllers and identity signals to surface compromised identities and insider threats. Part of Microsoft Defender XDR, it correlates identity attacks with endpoint and cloud signals. Faltrox operates it as managed identity threat detection.
Overview
What Defender for Identity is
Attackers increasingly log in rather than break in — using compromised, over-privileged, or forged identities to move through a network. Traditional tools do not see these identity-based attacks, especially in on-premises Active Directory, which remains a prime target. Defender for Identity closes that gap by monitoring identity signals and domain controllers to detect the full identity attack chain.
It detects reconnaissance, credential theft (Pass-the-Hash, Pass-the-Ticket), lateral movement, and domain dominance (Golden Ticket, DCSync), and surfaces compromised identities, risky lateral-movement paths, and insider threats across on-premises AD and Entra ID. As part of Microsoft Defender XDR, identity attacks correlate with endpoint, email, and cloud-app signals for a full cross-domain view. Faltrox deploys the sensors, tunes the detection, and operates identity threat detection and response as part of managed defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Active Directory & Entra ID
Detects identity attacks across on-premises AD and Entra ID.
Credential Theft
Catches Pass-the-Hash, Pass-the-Ticket, and credential-theft techniques.
Lateral Movement
Surfaces lateral-movement paths attackers use to reach high-value targets.
Domain Dominance
Detects Golden Ticket, DCSync, and other domain-dominance attacks.
Compromised & Insider
Surfaces compromised identities and insider-threat behaviour.
Reconnaissance
Detects the reconnaissance that precedes an identity-based attack.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Monitor
Sensors on domain controllers and identity signals monitor authentication and directory activity.
- 02
Detect
It detects the full identity attack chain — recon, credential theft, lateral movement, domain dominance.
- 03
Correlate
Identity attacks correlate with endpoint, email, and cloud signals across Defender XDR.
- 04
Prioritise
It surfaces risky lateral-movement paths and prioritises the identities most at risk.
- 05
Operate
Faltrox tunes detection and runs identity threat response as part of managed defence.
Capabilities
Key capabilities
Identity Attack Detection
Detects reconnaissance, credential theft, lateral movement, and domain dominance.
On-Prem & Cloud Coverage
Monitors on-premises Active Directory and Entra ID identity signals.
Lateral-Movement Paths
Surfaces the paths attackers would use to move from a compromised identity to high-value targets.
Compromised Identity Detection
Identifies compromised identities and insider-threat behaviour.
Domain-Dominance Detection
Catches Golden Ticket, DCSync, and other domain-takeover techniques.
Behavioural Analytics
Baselines user and entity behaviour to surface anomalies.
Defender XDR Integration
Identity attacks correlate with endpoint, email, and cloud signals across Defender XDR.
Threat Intelligence
Enriched by Microsoft’s global threat intelligence.
Works with
Part of the platform
Microsoft products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Microsoft Defender for Identity for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01Why is identity such a critical attack surface?
Because attackers increasingly log in with compromised or forged identities rather than exploiting software, and on-premises Active Directory in particular is a prime target that traditional tools do not monitor well. Defender for Identity detects the identity attack chain that would otherwise be invisible.
02What attacks does it detect?
The full identity attack chain — reconnaissance, credential theft (Pass-the-Hash, Pass-the-Ticket), lateral movement, and domain dominance (Golden Ticket, DCSync) — plus compromised identities and insider-threat behaviour across AD and Entra ID.
03Does it cover cloud identity too, or just on-premises?
Both — it monitors on-premises Active Directory and Entra ID identity signals, giving coverage of the hybrid identity estate that most organisations run.
04How does it fit Defender XDR?
Identity attacks correlate with endpoint, email, and cloud-app signals across Defender XDR, so an attack that starts with a phished credential and moves through identity to endpoints is seen as one incident rather than separate alerts.
05How does Faltrox operate it?
We deploy the sensors, tune the detection, and run identity threat detection and response as part of the managed defence and SOC services we operate — surfacing and stopping identity-based attacks across your AD and Entra estate.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us