Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRHard

A Microsoft 365 administrator is investigating a complex attack scenario where an attacker attempted to gain unauthorized access to an on-premises application server. The attacker used a compromised service account to perform multiple reconnaissance activities, followed by an attempt to escalate privileges. The administrator needs to query the authentication activities specifically involving service accounts over the past 7 days to identify all logon attempts, source IPs, and success/failure statuses. Which Advanced Hunting table in Microsoft Defender XDR should be primarily queried to gather this information efficiently?

  1. AIdentityInfo
  2. BDeviceLogonEvents
  3. CIdentityLogonEvents
  4. DCloudAppEvents
Show answer & explanation

Correct answer: C. IdentityLogonEvents

The IdentityLogonEvents table in Advanced Hunting specifically captures information about authentication activities and logon attempts involving both user and service accounts across on-premises Active Directory and Azure Active Directory. It provides details like the account name, source IP, logon type, and success/failure status, making it ideal for investigating service account authentication.

Why the other options are wrong

  • A. IdentityInfo contains static information about identities (users, groups, service accounts) but does not record logon events.
  • B. DeviceLogonEvents focuses on interactive and non-interactive logons on *endpoints* (devices) managed by Defender for Endpoint, rather than comprehensive identity authentication events across Active Directory.
  • D. CloudAppEvents logs activities performed within connected cloud applications, not general identity authentication events across Active Directory.

Advanced Hunting IdentityLogonEvents Table

The IdentityLogonEvents table in Microsoft Defender XDR Advanced Hunting contains information about authentication attempts and logon events from both on-premises Active Directory (via Defender for Identity) and Azure Active Directory, including details for user and service accounts.

  • Captures authentication activities for identities.
  • Includes data from on-premises AD and Azure AD.
  • Records logon type, source IP, success/failure.
  • Essential for investigating identity-related threats.

Memory trick: IdentityLogonEvents is like the security guard's logbook for every person trying to enter, including the service staff.

More Implement and manage Microsoft Defender XDR questions