Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRHard

A healthcare organization is using Microsoft Defender for Identity to protect its on-premises Active Directory. Due to strict compliance requirements, they need to ensure that all domain controllers are monitored for suspicious activities, including potential Pass-the-Hash attacks and other credential theft attempts. They also need to minimize the performance impact on the domain controllers. Which component of Microsoft Defender for Identity should be deployed directly on each domain controller?

  1. AMicrosoft Defender for Identity lightweight sensor
  2. BMicrosoft Defender for Identity standalone sensor
  3. CMicrosoft Defender for Endpoint agent
  4. DMicrosoft Defender for Cloud Apps sensor
Show answer & explanation

Correct answer: A. Microsoft Defender for Identity lightweight sensor

The Microsoft Defender for Identity lightweight sensor is designed for direct deployment on domain controllers, providing comprehensive monitoring for identity-based threats like Pass-the-Hash with minimal performance overhead, making it ideal for the scenario's requirements.

Why the other options are wrong

  • B. The standalone sensor is typically deployed on a dedicated server to monitor network traffic via port mirroring, which is not direct deployment on the DC and involves higher network overhead for traffic replication.
  • C. Microsoft Defender for Endpoint agent focuses on endpoint detection and response (EDR) for workstations and servers, not specifically identity threat detection on domain controllers.
  • D. Microsoft Defender for Cloud Apps sensor is used for monitoring cloud application usage and is irrelevant for on-premises Active Directory security.

Defender for Identity Lightweight Sensor

The Microsoft Defender for Identity lightweight sensor is deployed directly on domain controllers to capture and analyze network traffic and Windows events for identity-based threats with minimal performance impact.

  • Installs directly on domain controllers.
  • Monitors local network traffic and Windows events.
  • Low resource consumption, suitable for sensitive DC environments.
  • Detects credential theft, lateral movement, and other identity attacks.

Memory trick: For DCs, LIGHTWEIGHT is the way to go to keep things fast.

More Implement and manage Microsoft Defender XDR questions