Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy

A security analyst is investigating a series of suspicious activities originating from a compromised user account. They need to quickly determine if the user's credentials have been used to access sensitive resources from an unusual location or device. Which Microsoft Defender for Identity alert type is most relevant for this specific investigation?

  1. ASuspicious service creation
  2. BUnusual protocol implementation
  3. CSuspicious communication over RDP
  4. DUnusual travel
Show answer & explanation

Correct answer: D. Unusual travel

The 'Unusual travel' alert in Microsoft Defender for Identity specifically detects when a user logs in from two geographically distant locations within an implausibly short period, implying compromised credentials used from different places. This directly addresses the need to identify access from unusual locations.

Why the other options are wrong

  • A. Suspicious service creation indicates a potential persistence mechanism, not unusual login patterns.
  • B. Unusual protocol implementation relates to non-standard protocol usage, not login location anomalies.
  • C. Suspicious communication over RDP relates to RDP lateral movement, not necessarily unusual login locations.

Defender for Identity: Unusual Travel

An alert generated by Microsoft Defender for Identity when a user account logs in from two geographically distinct locations within an impossible travel time, indicating potential credential compromise.

  • Detects impossible travel scenarios.
  • Strong indicator of compromised credentials.
  • Helps identify suspicious access from unusual locations.

Memory trick: Defender for Identity is like a watchful guard, noticing if a user's 'teleporting' or doing something truly bizarre.

More Mitigate threats using Microsoft Defender XDR questions