Microsoft Defender for Identity
Identity protection

Microsoft Defender for Identity Overview

In brief

The page date changed to July 23, 2026, and wording was corrected and clarified, including “non-human” and examples of high-value targets.

What Defender admins need to know

Administrators have clearer, more current reference information when reviewing Defender for Identity’s identity coverage and threat examples.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Microsoft Defender for Identity Overview description: Learn how Microsoft Defender for Identity helps detect, investigate, and respond to identity-based attacks across on-premises, cloud, and hybrid environments. ms.date: 02/19/07/23/2026 ms.topic: overview #customer intent: As a security analyst or identity administrator, I want to understand what Microsoft Defender for Identity does and when to use it so that I can detect and respond to identity-based attacks. ms.reviewer: AbbyMSFT

Detect identity-based threats

Defender for Identity is designed to detect threats that specifically target identities, including both human and nonh-umannon-human identities such as service accounts, synchronization accounts, and applications. Detection is based on behavioral analytics and signal correlation rather than single events.

Defender for Identity monitors and analyzes identity activity such as:

| Lateral movement| Detects attempts to move laterally and expand control of sensitive identities and across different environments. | | AD Domain dominance | Highlights behavior associated with full domain compromise, such as remote code execution on domain controllers, DCShadow, malicious domain controller replication, and Golden Ticket activity. |

Attackers often begin with any accessible identity and then move laterally toward high high-value targets such as privileged accounts such as domain administrators, global admin,administrators, and application admins andadministrators, along with sensitive data. Defender for Identity helps identify these behaviors early by building behavioral profiles for users, devices, and accounts and detecting deviations that indicate attacker activity.

Investigate identity threats