Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium
A Microsoft 365 administrator is investigating a series of suspicious login attempts originating from unusual geographic locations for several executive accounts. These attempts did not result in successful logins, but the administrator wants to enhance protection specifically for these high-value accounts against future brute-force or credential stuffing attacks. Which Microsoft Defender for Identity capability should the administrator configure?
- AUnusual travel alerts
- BLateral movement path detection
- CSensitive account protection
- DIdentity Secure Score
Show answer & explanationAnswer & explanation
Correct answer: C. Sensitive account protection
Sensitive account protection in Microsoft Defender for Identity allows administrators to specifically tag and monitor high-value accounts, applying stricter detection logic for suspicious activities, including brute-force attempts, tailored to these critical identities.
Why the other options are wrong
- A. Unusual travel alerts detect impossible travel scenarios for users, but don't specifically enhance protection against brute-force attacks on high-value accounts.
- B. Lateral movement path detection identifies ways attackers could move between systems after initial compromise, not specifically for preventing initial brute-force login attempts.
- D. Identity Secure Score provides an overall security posture assessment and recommendations, but it's not a direct configuration to protect specific accounts against brute-force attacks.
Defender for Identity Sensitive Account Protection
A feature within Microsoft Defender for Identity that allows organizations to designate specific accounts as 'sensitive' to apply enhanced monitoring, detection logic, and protection against advanced threats, such as credential theft and brute-force attacks.
- Tags high-value accounts (e.g., executives, admins).
- Applies stricter detection logic for anomalous behavior.
- Helps protect against credential compromise and abuse.
Memory trick: Identity protection needs to track movement, score security, and guard key accounts.