Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium
A global financial institution uses Microsoft 365 and Microsoft Defender for Identity. They have a strict compliance requirement to ensure that all sensitive on-premises Active Directory objects (e.g., domain controllers, privileged user accounts) are continuously monitored for suspicious activities and potential compromise. The institution wants to ensure the highest fidelity of alerts and comprehensive coverage without requiring direct access to domain controllers for sensor installation. Which component of Defender for Identity should be deployed and configured to meet this requirement effectively?
- ADefender for Identity lightweight sensor
- BMicrosoft Defender for Cloud Apps app connector
- CDefender for Identity standalone sensor
- DAzure AD Connect Health agent
Show answer & explanationAnswer & explanation
Correct answer: A. Defender for Identity lightweight sensor
The Defender for Identity lightweight sensor is designed to be installed directly on domain controllers, providing the highest fidelity monitoring of Active Directory traffic without requiring direct access for installation on the domain controller itself, as it is integrated and has minimal impact. It's crucial for monitoring sensitive on-premises AD objects.
Why the other options are wrong
- B. Microsoft Defender for Cloud Apps app connectors are used for monitoring cloud applications, not on-premises Active Directory.
- C. A standalone sensor is typically deployed on a dedicated server, requiring port mirroring, which can introduce latency and might not offer the same fidelity as direct DC installation for sensitive objects.
- D. Azure AD Connect Health is for monitoring synchronization health and identity infrastructure, not for detecting suspicious activities on on-premises Active Directory objects.
Defender for Identity Lightweight Sensor
A component of Microsoft Defender for Identity installed directly on domain controllers to monitor network traffic and Windows events, providing real-time protection and detection of advanced threats against Active Directory.
- Installed directly on domain controllers.
- Provides high-fidelity monitoring of Active Directory.
- Collects network traffic and Windows events for analysis.
- Crucial for protecting sensitive on-premises AD objects.
Memory trick: Lightweight sensor is like a tiny spy, sitting right inside the Active Directory brain.