MicrosoftMicrosoft Defender

    Defender for Identity

    Identity threat detection for Active Directory and Entra ID.

    Microsoft Defender for Identity detects identity-based attacks across on-premises Active Directory and Entra ID — catching reconnaissance, credential theft, lateral movement, and domain dominance techniques that traditional tools miss. It monitors domain controllers and identity signals to surface compromised identities and insider threats. Part of Microsoft Defender XDR, it correlates identity attacks with endpoint and cloud signals. Faltrox operates it as managed identity threat detection.

    Overview

    What Defender for Identity is

    Attackers increasingly log in rather than break in — using compromised, over-privileged, or forged identities to move through a network. Traditional tools do not see these identity-based attacks, especially in on-premises Active Directory, which remains a prime target. Defender for Identity closes that gap by monitoring identity signals and domain controllers to detect the full identity attack chain.

    It detects reconnaissance, credential theft (Pass-the-Hash, Pass-the-Ticket), lateral movement, and domain dominance (Golden Ticket, DCSync), and surfaces compromised identities, risky lateral-movement paths, and insider threats across on-premises AD and Entra ID. As part of Microsoft Defender XDR, identity attacks correlate with endpoint, email, and cloud-app signals for a full cross-domain view. Faltrox deploys the sensors, tunes the detection, and operates identity threat detection and response as part of managed defence.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Active Directory & Entra ID

    Detects identity attacks across on-premises AD and Entra ID.

    02

    Credential Theft

    Catches Pass-the-Hash, Pass-the-Ticket, and credential-theft techniques.

    03

    Lateral Movement

    Surfaces lateral-movement paths attackers use to reach high-value targets.

    04

    Domain Dominance

    Detects Golden Ticket, DCSync, and other domain-dominance attacks.

    05

    Compromised & Insider

    Surfaces compromised identities and insider-threat behaviour.

    06

    Reconnaissance

    Detects the reconnaissance that precedes an identity-based attack.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Monitor

      Sensors on domain controllers and identity signals monitor authentication and directory activity.

    2. 02

      Detect

      It detects the full identity attack chain — recon, credential theft, lateral movement, domain dominance.

    3. 03

      Correlate

      Identity attacks correlate with endpoint, email, and cloud signals across Defender XDR.

    4. 04

      Prioritise

      It surfaces risky lateral-movement paths and prioritises the identities most at risk.

    5. 05

      Operate

      Faltrox tunes detection and runs identity threat response as part of managed defence.

    Capabilities

    Key capabilities

    Identity Attack Detection

    Detects reconnaissance, credential theft, lateral movement, and domain dominance.

    On-Prem & Cloud Coverage

    Monitors on-premises Active Directory and Entra ID identity signals.

    Lateral-Movement Paths

    Surfaces the paths attackers would use to move from a compromised identity to high-value targets.

    Compromised Identity Detection

    Identifies compromised identities and insider-threat behaviour.

    Domain-Dominance Detection

    Catches Golden Ticket, DCSync, and other domain-takeover techniques.

    Behavioural Analytics

    Baselines user and entity behaviour to surface anomalies.

    Defender XDR Integration

    Identity attacks correlate with endpoint, email, and cloud signals across Defender XDR.

    Threat Intelligence

    Enriched by Microsoft’s global threat intelligence.

    Works with

    Part of the platform

    Microsoft products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Microsoft Defender for Identity for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Why is identity such a critical attack surface?

    Because attackers increasingly log in with compromised or forged identities rather than exploiting software, and on-premises Active Directory in particular is a prime target that traditional tools do not monitor well. Defender for Identity detects the identity attack chain that would otherwise be invisible.

    02What attacks does it detect?

    The full identity attack chain — reconnaissance, credential theft (Pass-the-Hash, Pass-the-Ticket), lateral movement, and domain dominance (Golden Ticket, DCSync) — plus compromised identities and insider-threat behaviour across AD and Entra ID.

    03Does it cover cloud identity too, or just on-premises?

    Both — it monitors on-premises Active Directory and Entra ID identity signals, giving coverage of the hybrid identity estate that most organisations run.

    04How does it fit Defender XDR?

    Identity attacks correlate with endpoint, email, and cloud-app signals across Defender XDR, so an attack that starts with a phished credential and moves through identity to endpoints is seen as one incident rather than separate alerts.

    05How does Faltrox operate it?

    We deploy the sensors, tune the detection, and run identity threat detection and response as part of the managed defence and SOC services we operate — surfacing and stopping identity-based attacks across your AD and Entra estate.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us