Microsoft Defender for Identity: Protect the Domain Controllers Behind Every Login

Justin Kirsch | | 12 min read
Microsoft 365 hero image: three domain controllers connected to a Microsoft Defender for Identity shield linked to Active Directory and Microsoft Entra ID, with the lines Sign-ins keep flowing, Domain controllers watched, Monitoring examiners expect

At five minutes to eight on a Monday morning, every teller, loan officer, and member service representative at your institution signs in. If your institution runs its own Windows servers, a domain controller checks each of those sign-ins against Active Directory and grants access to the file shares and applications staff need before the doors open. In a hybrid setup, the same accounts sync to Microsoft Entra ID, so the password that unlocks a teller workstation also opens Outlook and Teams.

That dependence is why attackers go after the domain controller. In September 2026, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), with cyber agencies in Australia, Canada, New Zealand, and the United Kingdom, revised their joint guide to Active Directory compromises. It calls Active Directory "the most widely used authentication and authorisation solution in enterprise information technology (IT) networks globally" and walks through the techniques attackers use against it, from Kerberoasting to Golden Ticket attacks.

Microsoft Defender for Identity is Microsoft's identity threat detection and response service for Active Directory. Sensors on your domain controllers and identity servers read Windows events and authentication traffic. The detections land in the same Microsoft Defender portal that handles email and endpoint alerts.

At ABT, a Tier-1 Microsoft Cloud Solution Provider, we've served more than 750 financial institutions over 25 years. This guide covers what Defender for Identity detects and how credit unions, banks, and mortgage companies get it, including the add-on that brings it to Microsoft 365 Business Premium. It also explains what changed in 2026 to make deployment lighter and the rule text examiners work from.

Finding

In more than 78% of human-operated cyberattacks Microsoft has seen, threat actors successfully breach a domain controller. In more than 35% of cases, the domain controller is the primary spreader device, the system that distributes ransomware at scale.

Microsoft Security Blog, How cyberattackers exploit domain controllers using ransomware, April 9, 2025

Active Directory security starts with every staff sign-in

Microsoft describes domain controllers as "the backbone of any on-premises environment, managing identity and access through Active Directory (AD)." They authenticate users and devices, hand out Kerberos tickets for file shares and applications, and keep account data consistent across every site. Take the domain controllers away and staff lose the file shares and every application that relies on Windows authentication.

Hybrid sync makes the domain controller matter to Microsoft 365 too. Microsoft Entra Connect copies Active Directory accounts to Microsoft Entra ID, and the joint guide notes that "The default and most used configuration is Password Hash Synchronisation (PHS)." With password hash sync, the password an attacker steals on premises is also the password for that person's Microsoft 365 account. The server that runs Microsoft Entra Connect Sync belongs in the same protected tier as your domain controllers.

The guide names that tier explicitly: "Tier 0 computer objects include Domain Controllers, the AD FS server, the AD CS root certificate authority, backup servers, and the Microsoft Entra Connect server." AD FS is Active Directory Federation Services, which handles federated sign-in, and AD CS is Active Directory Certificate Services, which issues certificates. Five terms carry the rest of this article.

Domain controller

A Windows server that runs Active Directory Domain Services and authenticates the users and computers in the domain.

Tier 0

The systems that control identity for everything else: domain controllers, AD FS, the AD CS root certificate authority, backup servers, and the Entra Connect server.

Kerberoasting

Requesting Kerberos service tickets for accounts that have a service principal name (SPN), then cracking the ticket offline to recover the service account's password.

DCSync

Sending a directory replication request from a computer that isn't a domain controller, to pull password hashes out of Active Directory.

Golden Ticket

A forged Kerberos ticket, made with the key of KRBTGT, the built-in account Active Directory uses to sign Kerberos tickets. It grants access to any resource for as long as the attacker chooses.

Where does the Microsoft 365 side of your identity stand?

Accounts that Entra Connect syncs can also sign in to Microsoft 365. ABT's free assessment reviews that side of your identity: multifactor authentication (MFA) coverage, Conditional Access policies, legacy authentication exposure, and admin account hygiene.

What attackers do once they reach Active Directory

The joint guide explains why Active Directory is such a reliable target: it "is susceptible to compromise due to its permissive default settings, its complex relationships, and permissions; support for legacy protocols and a lack of tooling for diagnosing Active Directory security issues." Microsoft's security research reaches the same conclusion: "most identity attacks utilize common misconfigurations in Active Directory and continued use of legacy components (such as NTLMv1 protocol)." NTLM, short for NT LAN Manager, is an older Windows authentication protocol that many networks still allow.

Most identity attacks start with a password. Microsoft's Digital Defense Report 2025 found that "more than 97% of identity attacks are password attacks", and that identity-based attacks surged 32% in the first half of 2025. A sprayed password or a phished account gives an attacker a foothold inside the domain. From there, the guide warns, "Kerberoasting may be executed by malicious actors shortly after gaining initial access to an Active Directory domain to attempt to escalate privileges and move laterally."

Service accounts are the usual target. The joint guide notes that "The types of user objects configured with SPNs are commonly referred to as service accounts," and that a service account compromised through Kerberoasting "often provides additional privileges and access." Two of our recent guides cover that ground: the forgotten service accounts a password spray found, and the move from RC4 to AES Kerberos encryption that makes cracked tickets harder to come by. After a service account falls, the path to full control of the domain can be short: reuse a stolen hash on another server, pull password hashes with DCSync, then forge a Golden Ticket.

From there, ransomware can spread across the network. The FBI's 2025 Internet Crime Report counted more than 3,600 complaints reporting ransomware. It notes that the reported losses run artificially low, because some victims report no loss amount at all.

Microsoft 365 infographic: the five stages of an Active Directory attack, from reconnaissance to persistence, each paired with the Microsoft Defender for Identity alert that flags it
Each stage of an Active Directory attack has a named Defender for Identity alert.

What Microsoft Defender for Identity watches

Microsoft Learn describes the service plainly: "Defender for Identity monitors identity signals from on-premises Active Directory and Microsoft Entra ID." Its sensors "run on your identity infrastructure, capturing and parsing relevant network traffic and Windows events locally," and only the signals the detections need go to Microsoft's cloud service. It covers people and machines alike, "including both human and non-human identities such as service accounts, synchronization accounts, and applications."

The detections follow the attack path above. Each alert below uses the name in Microsoft's classic alert reference (the Golden Ticket row groups six variants), along with the learning period Microsoft lists before it fires.

Attack stageWhat the attacker doesDefender for Identity alertLearning period
ReconnaissanceGuesses valid user names against the domainAccount Enumeration reconnaissance (LDAP)None
Credential accessSprays one password across many accounts over Kerberos or NTLMSuspected Brute Force attack (Kerberos, NTLM)One week
Credential accessRequests service tickets to crack offline (Kerberoasting)Suspected Kerberos SPN exposureNone
Lateral movementReuses a stolen NTLM hash on another computerSuspected identity theft (pass-the-hash)None
Domain dominancePulls password hashes with a replication request from a non-domain controllerSuspected DCSync attack (replication of directory services)None
PersistenceAdds an account to a highly privileged groupSuspicious additions to sensitive groupsFour weeks per domain controller
PersistenceUses a forged Kerberos ticketSuspected Golden Ticket usage (six variants)None for five variants; five days for the encryption downgrade variant

Two lines from Microsoft's documentation belong in every deployment plan. The first is that coverage follows the sensors: "If you have domain controllers on which Defender for Identity sensors aren't installed, those domain controllers aren't covered by Defender for Identity." Microsoft recommends a sensor on every domain controller.

The second is that Defender for Identity is a detection service, and it "only captures the data required for its detection and recommendation mechanisms." Keep your Windows and Microsoft 365 audit logs on their own retention schedule, as covered in Microsoft 365 audit log retention for financial institutions.

Detection comes with response. For accounts that live in Active Directory, Microsoft says "Actions are executed by the Microsoft Defender for Identity sensor on the domain controller," including disabling an account and forcing a password change. Microsoft Defender's automatic attack disruption can act on its own: for an Active Directory account synced to Entra ID, "Defender for Identity triggers the disable user action via onboarded domain controllers. Attack disruption also disables the user account in Microsoft Entra ID."

The service also runs a continuous Active Directory security assessment. Defender for Identity adds identity security posture assessments to Microsoft Secure Score in six categories: hybrid security, identity infrastructure, certificates, Group Policy, accounts, and cloud identities. Microsoft ties them to the license: "You must have a Defender for Identity license to view Defender for Identity security posture assessments in Microsoft Secure Score." With it, your Active Directory configuration shows up in the same Secure Score your team already tracks for Microsoft 365.

Is Defender for Identity included in Microsoft 365 Business Premium?

Defender for Identity sits outside Microsoft 365 Business Premium. Business Premium includes Microsoft Entra ID P1, Microsoft Defender for Office 365 Plan 1, Microsoft Defender for Business, Microsoft Intune, and Microsoft Purview data loss prevention. Microsoft's prerequisites include Enterprise Mobility + Security E5 (EMS E5), Microsoft 365 E5, and a standalone Defender for Identity license, available directly or through the Cloud Solution Provider program.

If your institution already owns Microsoft 365 E5, the license may be sitting unused. Our guide to the E5 security features institutions pay for but don't use walks through the check.

For Business Premium customers, the path is the Microsoft Defender Suite for Microsoft 365 Business Premium add-on. Microsoft lists it at $10.00 per user per month, paid yearly, and it requires Business Premium. Microsoft Learn says the add-on brings "Identity protection with Microsoft Defender for Identity, which is an identity threat detection and response (ITDR) solution", along with four other upgrades.

Microsoft 365 Business Premium

  • Microsoft Entra ID P1: Conditional Access and multifactor authentication
  • Microsoft Defender for Business on endpoints
  • Microsoft Defender for Office 365 Plan 1
  • Microsoft Intune and Microsoft Purview data loss prevention

With the Defender Suite for Business Premium

  • Microsoft Defender for Identity on domain controllers and identity servers
  • Microsoft Entra ID P2: risk-based Conditional Access and Privileged Identity Management
  • Microsoft Defender for Endpoint Plan 2 and Defender for Office 365 Plan 2
  • Microsoft Defender for Cloud Apps

Plan the purchase for every user. Microsoft describes Defender for Identity as "a per-user subscription license" and says its features "are enabled at the tenant level for all users within the tenant." The service isn't currently "capable of limiting benefits to specific users."

The endpoint half of the add-on has its own rule: "Microsoft Defender for Business doesn't support mixed licensing." In Microsoft's example, an organization with 80 Business Premium users that upgrades only 30 of them stays on the Defender for Business endpoint experience for all 80. Moving to Defender for Endpoint Plan 2 takes a license for every user and a request to Microsoft Support. That's why ABT recommends one order that covers every seat.

The Defender Suite for Business Premium is the minimum upgrade we recommend for every Business Premium institution, because it also adds risk-based Conditional Access and Privileged Identity Management. As a Tier-1 Microsoft Cloud Solution Provider, we sell it at Microsoft's price, on its own line of your quote. When your Microsoft 365 licenses sit with ABT, Guardian Foundation, the hardened tenant baseline, is included at no additional charge.

What changed in 2026: a lighter deployment

Earlier versions of Defender for Identity asked a lot of a two-person IT team: a sensor installed on each server, a directory service account, and advanced audit policy configured by hand. Microsoft's What's new page shows how much of that work moved into the Defender portal during 2026.

March 2026
Sensor migration moves into the portal

Sensors move from v2.x to v3.x from the Microsoft Defender portal. The old sensor keeps running until the new one is ready, so there's no downtime.

April 2026
Automatic audit configuration reaches general availability

Sensor v3.x applies the Windows event auditing its detections need.

July 2026
v2.x to v3.x migration is generally available

Remote Procedure Call (RPC) auditing turns on automatically with sensor version 3.0.8 or later.

August 2026
Automatic auditing extends to identity servers

Auditing is configured automatically for AD FS, AD CS, and Microsoft Entra Connect on servers running sensor v3.x.

September 2026
Activation without Defender for Endpoint (preview)

New v3.x sensors can be activated on eligible domain controllers running Windows Server 2019 or later without first onboarding them to Defender for Endpoint. A second preview adds AD FS, AD CS, and Entra Connect servers that aren't domain controllers.

The v3.x sensor has firm prerequisites. Microsoft's deployment page lists Windows Server 2019 or later with "the Windows Server July 2026 or later cumulative update installed," plus onboarding to Defender for Endpoint, which the September preview replaces on eligible domain controllers. The page also says v3.x replaces the directory service account and action account that v2.x needed: "LocalSystem handles this automatically."

Domain controllers on Windows Server 2016 run the v2.x sensor, which supports "Domain controllers running Windows Server 2016 or earlier". Microsoft ends extended support for Windows Server 2016 in January 2027, so a domain controller upgrade plan and a Defender for Identity plan fit together. Our October 2026 end-of-support guide covers the Windows 10 and Office dates that land first.

A deployment plan for a small IT team

Microsoft's standard deployment path reduces to six steps for an institution with a handful of domain controllers.

Tier-1 Cloud Solution Provider (CSP)

Microsoft Defender for Identity Deployment Path

1
Confirm the license

Microsoft 365 E5, EMS E5, a standalone license, or the Defender Suite for Business Premium.

2
Inventory identity servers

List every domain controller, AD FS federation server, AD CS certificate authority, and Entra Connect server.

3
Check each server

Sensor v3.x needs Windows Server 2019 or later, the July 2026 or later cumulative update, and Defender for Endpoint onboarding.

4
Activate the sensors

Turn on v3.x sensors from the Microsoft Defender portal, and use sensor v2.x where the server is older.

5
Let auditing configure itself

Automatic Windows event auditing applies the settings the detections need on v3.x sensors.

6
Work the Secure Score recommendations

Review the identity posture assessments, then tag sensitive accounts and set up a decoy honeytoken account.

Three decisions keep the deployment useful after the first week.

  • Deploy before you need it. Several detections fire on day one, but the sensitive-group and group-membership reconnaissance alerts learn for four weeks per domain controller. A sensor installed during an incident sees only what happens next.
  • Set up a honeytoken. Microsoft describes honeytoken accounts as "decoy accounts set up to identify and track malicious activity," and any authentication from one raises an alert with no learning period.
  • Name who answers the alert. Decide who reviews a high-severity identity alert at 2 a.m., who can disable an account, and how the decision is recorded for your incident file. The Microsoft 365 incident response plan guide covers the paperwork.
Microsoft 365 infographic: a six-step checklist for deploying Microsoft Defender for Identity, from confirming the license to working the Microsoft Secure Score recommendations
Six steps from license to live detections.

What examiners expect you to be watching

Federal rules describe the monitoring outcome and leave the product choice to the institution. The Interagency Guidelines Establishing Information Security Standards, adopted by each federal banking agency, list the security measures a bank must consider and adopt where appropriate:

Interagency Guidelines Establishing Information Security Standards (12 CFR Part 364, Appendix B)

Monitoring systems and procedures to detect actual and attempted attacks on or intrusions into customer information systems;

Section III.C.1.f; the Office of the Comptroller of the Currency (OCC) version appears at 12 CFR Part 30, Appendix B

Federally insured credit unions work from the same language in the National Credit Union Administration (NCUA) rules. Part 748, Appendix A calls for "Monitoring systems and procedures to detect actual and attempted attacks on or intrusions into member information systems." Mortgage companies and other non-bank lenders under the Federal Trade Commission (FTC) Safeguards Rule have a more specific version at 16 CFR 314.4(c)(8): "Implement policies, procedures, and controls designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information by such users."

Each rule asks whether the institution can detect an intrusion into the systems that hold customer information, and in an institution that runs Active Directory, the domain controllers are the front door to those systems. Defender for Identity gives you dated, named alerts for the attacks this article describes. Alongside your review procedures and investigation records, those alerts help answer the monitoring question. The FBI makes the operational case in its own ransomware guidance, recommending that organizations "implement a tool that logs and reports all network traffic, including lateral movement activity on a network."

How ABT helps

ABT makes the Defender Suite for Business Premium one conversation: a seat count that covers every user, which servers count as Tier 0, and how the endpoint upgrade lands for every seat at once.

Identity has two halves in a hybrid institution, and M365 Guardian covers the Microsoft 365 half. We manage your Microsoft 365 tenant, and every Guardian rung includes a hardened tenant: Zero Trust identity and device baselines, Microsoft Entra ID Conditional Access, multifactor authentication, Microsoft Intune device compliance, Microsoft Purview data loss prevention, and Microsoft Defender for Office 365 configuration. Defender for Identity watches the Active Directory half those synced accounts come from. With both in place, a stolen password meets Conditional Access in the cloud and Defender for Identity sensors on premises.

To see where the Microsoft 365 half of your identity stands today, start with the free Microsoft 365 Security Assessment.

Protect both halves of your identity: Active Directory and Microsoft 365

Some detections learn for four weeks per domain controller, so start before you need them.

🎯

Start with the Microsoft 365 side

Get a free review of MFA coverage, Conditional Access policies, legacy authentication exposure, and admin account hygiene in your tenant.

Request a Free Microsoft 365 Security Assessment
💬

Add Defender for Identity

Talk through the Defender Suite for Business Premium: a seat count that covers every user, and which servers count as Tier 0 in your environment.

Talk to an ABT M365 licensing specialist

Frequently Asked Questions

Microsoft Defender for Identity is Microsoft's identity threat detection and response service for on-premises Active Directory and Microsoft Entra ID. Sensors on domain controllers and identity servers read Windows events and authentication traffic, and alerts for attacks such as Kerberoasting, pass-the-hash, and DCSync appear in the Microsoft Defender portal alongside email and endpoint alerts.

Microsoft 365 Business Premium does not include Defender for Identity. Business Premium customers add it with the Microsoft Defender Suite for Microsoft 365 Business Premium, which Microsoft lists at $10.00 per user per month, paid yearly. Defender for Identity also comes with Microsoft 365 E5, Enterprise Mobility + Security E5, or a standalone license.

Defender for Identity detects reconnaissance, credential theft, lateral movement, and domain takeover in Active Directory. Its alerts include account enumeration, password spray and brute force over Kerberos or NTLM, Kerberoasting, pass-the-hash, DCSync replication from a non-domain controller, suspicious additions to sensitive groups, and forged Golden Ticket usage.

Microsoft recommends a Defender for Identity sensor on every domain controller, because domain controllers without a sensor are not covered. Sensor v3.x needs Windows Server 2019 or later, the July 2026 or later cumulative update, and Defender for Endpoint onboarding, which a preview makes optional for new sensors on eligible domain controllers. Older domain controllers use v2.x.

Defender for Identity works alongside audit logs. Microsoft says it only captures the data its detections and recommendations need, and it is not designed as an auditing or logging solution. Institutions keep Windows security logs and Microsoft 365 audit logs on their own retention schedule and use Defender for Identity for detection and response on top of them.

Examiners work from rules that describe monitoring outcomes. The Interagency Guidelines call for monitoring systems and procedures to detect actual and attempted attacks on customer information systems. NCUA's Appendix A says the same for member information systems, and the FTC Safeguards Rule requires monitoring and logging of authorized users' activity. Institutions choose the tools that produce the evidence.


Justin Kirsch

Justin Kirsch

Co-Founder & CEO, Access Business Technologies

Justin Kirsch has been building and managing Microsoft collaboration environments for financial institutions since 1999. As Co-Founder and CEO of Access Business Technologies, a Tier-1 Microsoft Cloud Solution Provider primarily dedicated to financial services and serving more than 750 financial institutions, he helps banks, credit unions, and mortgage companies protect the identities their staff sign in with every day.