Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRHard

A global organization uses Microsoft Defender for Identity to protect its on-premises Active Directory infrastructure. Due to network segmentation, some domain controllers are in isolated network segments and cannot directly reach the internet to communicate with the Defender for Identity cloud service. How can the administrator ensure these isolated domain controllers are still protected by Defender for Identity?

  1. ADeploy a dedicated Defender for Identity Sensor on a server within the isolated segment that has internet access.
  2. BConfigure a Microsoft Sentinel data connector to pull logs from the isolated domain controllers.
  3. CUse Microsoft Defender for Endpoint's network protection feature to forward logs from the domain controllers.
  4. DInstall the Defender for Identity Lightweight Sensor on each isolated domain controller and configure a proxy server.
Show answer & explanation

Correct answer: D. Install the Defender for Identity Lightweight Sensor on each isolated domain controller and configure a proxy server.

The Defender for Identity Lightweight Sensor must be installed directly on domain controllers. For domain controllers in isolated network segments that cannot directly reach the internet, the recommended method for the sensor to communicate with the Defender for Identity cloud service is through a proxy server. The sensor can be configured to use a proxy, allowing it to relay its data securely. Option B refers to a 'dedicated Defender for Identity Sensor' which is an older term for a standalone sensor, not the Lightweight Sensor installed directly on DCs. Options C and D are for different purposes and do not directly enable the Defender for Identity Lightweight Sensor's communication.

Why the other options are wrong

  • A. The concept of a 'dedicated Defender for Identity Sensor' is an older deployment model (standalone sensor) that is not the primary or recommended method for new deployments, especially for isolated segments where a proxy for the Lightweight Sensor is more appropriate. The Lightweight Sensor is meant to be *on* the DC.
  • B. Microsoft Sentinel can ingest logs, but this does not enable the Defender for Identity Lightweight Sensor to function and send its specific identity-based detections to the Defender for Identity cloud service.
  • C. Defender for Endpoint's network protection is for endpoint-level network traffic analysis and blocking, not for forwarding Active Directory logs or enabling Defender for Identity sensor communication.

Defender for Identity Sensor Proxy Configuration

The Microsoft Defender for Identity Lightweight Sensor, installed on domain controllers, can be configured to use a proxy server to communicate with the Defender for Identity cloud service, especially for isolated network segments.

  • Lightweight Sensor deployed directly on domain controllers.
  • Proxy configuration allows communication without direct internet access.
  • Required for DCs in isolated or air-gapped networks.
  • Ensures identity threat detection from all DCs.

Memory trick: Remember, for 'Isolated' 'DCs', the 'Defender for Identity Sensor' needs a 'Proxy' to 'Connect'.

More Implement and manage Microsoft Defender XDR questions