Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium
An organization is looking to implement a security solution that provides identity-driven security across their hybrid environment. They need to protect Active Directory users and their identities from advanced threats, including credential theft, lateral movement, and privilege escalation. The solution must integrate with their existing Active Directory infrastructure. Which Microsoft security solution is designed for this specific purpose?
- AMicrosoft Defender for Identity
- BMicrosoft Defender for Cloud
- CAzure Active Directory Identity Protection
- DMicrosoft Defender for Endpoint
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Defender for Identity
Microsoft Defender for Identity (formerly Azure Advanced Threat Protection) is a cloud-based security solution that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.
Why the other options are wrong
- B. Microsoft Defender for Cloud provides cloud security posture management and cloud workload protection, not specific Active Directory identity threat detection.
- C. Azure Active Directory Identity Protection focuses on real-time risk detection for Azure AD sign-ins and user accounts, primarily in the cloud context.
- D. Microsoft Defender for Endpoint is for endpoint security, not identity protection within Active Directory.
Microsoft Defender for Identity
A cloud-based security solution that protects hybrid identities and detects advanced threats targeting Active Directory.
- Monitors on-premises Active Directory traffic.
- Detects credential theft, lateral movement, and privilege escalation.
- Provides behavioral analytics for suspicious identity activities.
Memory trick: Defender for Identity is your 'AD bodyguard,' watching for sneaky identity attacks.