https://store-images.s-microsoft.com/image/apps.8146.32a14d80-c6aa-4f22-af44-e81b89280c1d.8483146c-bfbe-473e-89a8-360b144a05b8.83f35b78-f375-4667-81c5-2f87a414d070

SEC02 - Defender for Identity: 3-Wk Proof of Concept (PoC)

Mindcore

Explore Microsoft Defender for Identity through a focused Proof of Concept to assess benefits, user experience and technical fit

Microsoft Defender for Identity monitors your on-premise active directory for user and entity behavior, changes to group membership, privileged access usage and analyses this information to recognize possible threats, like reconnaissance, compromised credentials, lateral movements and other known attack methods. Analysis is done in real-time and gives visibility into starting or ongoing attacks and enables companies to respond early in the attack and prevent attackers from getting access to vital infrastructure.​

We typically discuss Microsoft Defender for Identity with customers that have legacy infrastructure components that rely on an active directory infrastructure and where a compromise could be devastating for the business. Our customers consider Defender for Identity when replacing existing tools that perform advanced analytics based on information from active directory or as a part of implementing other parts of the Microsoft cloud security stack. ​

Start with ingesting data by installing a sensor on one of the domain controllers that serves user logins. This will give insights into how data is analyzed and how the domain controller is affected by the on-board sensor. ​

  1. PLANNING: Sensor type, Initial capacity overview, integrations, syslog integration, honeytoken account
  2. SETUP DEFENDER FOR IDENTITY: Enable Defender for Identity, install sensors, setup honeytoken account and integrations
  3. ANALYSE INFORMATION: Overview of received alerts and sensor health
  4. CONCLUSIONS & NEXT STEP: Document learnings and conclusions, present findings

At a glance

https://store-images.s-microsoft.com/image/apps.12482.32a14d80-c6aa-4f22-af44-e81b89280c1d.8483146c-bfbe-473e-89a8-360b144a05b8.079b43b7-5e87-4abd-90bf-7e4e511bcba3
https://store-images.s-microsoft.com/image/apps.17821.32a14d80-c6aa-4f22-af44-e81b89280c1d.8483146c-bfbe-473e-89a8-360b144a05b8.147864e1-5fd6-4a2e-b4f7-b75d36c4fbfb
https://store-images.s-microsoft.com/image/apps.41103.32a14d80-c6aa-4f22-af44-e81b89280c1d.8483146c-bfbe-473e-89a8-360b144a05b8.99056ce3-ea8f-4ce5-b6cd-788741684c21