Microsoft Defender for Identity
Identity protection

Security Testing Best Practices

In brief

The guidance changes references from Microsoft Defender XDR to Microsoft Defender and updates the Security operations overview link.

What Defender admins need to know

Administrators will see updated terminology and the corresponding link when reviewing integration guidance. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

|Check that Defender for Identity is deployed on all domain controllers |Deployment on all domain controllers ensures that you're getting all of the signals for threat detection. Not having full protection can lead to missed detections or false positives. |Microsoft Defender for Identity deployment overview | |Check that Defender for Identity is deployed on all AD FS, AD CS, and Microsoft Entra Connect servers |Deployment on all these servers ensures that you're getting all of the signals for threat detection. Not having full protection can lead to missed detections or false positives.| Configure sensors for AD FS, AD CS, and Microsoft Entra Connect | |Check the health of your Defender for Identity sensors |It's critical that your sensor is healthy and reporting as expected to ensure optimal performance. Having an unhealthy sensor can lead to missed detections. Review all health alerts before running any tests. |Microsoft Defender for Identity health issues | |Consider integrating with Microsoft XDR|Defender|Defender for Identity provides alerting on identity-based threats. Integrating with Microsoft Defender XDR lets you correlate these alerts with other signals for a more comprehensive view of threats and potential solutions.

Microsoft Defender XDR is a unified pre-breach and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response acrossin endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks.|Microsoft Defender.| |Check Windows event collection configuration|Optimal event collection is essential for Defender for Identity to analyze and detect threats effectively. Check your configuration before running any tests. |- Configure Windows event collection for domain controllers
- Configure Windows event collection for AD CS
- Configure Windows event collection for AD FS
- Configure Windows event collection for Microsoft Entra Connect
- Use PowerShell to check your configuration| |Check that NNR is configured correctly|NNR is a critical component of Defender for Identity. Defender for Identity uses NNR to correlate between raw activities containing IP addresses and the computers involved in each activity. Defender for Identity profiles entities, including computers, and generates security alerts for suspicious activities. It's important for NNR to be configured correctly for a successful deployment and to help detect advanced threats.|Configure Network Name Resolution (NNR) for Microsoft Defender for Identity| |Check that you have a Directory Service account (DSA) |While a DSA is optional in some scenarios, we recommend that you configure a DSA for Defender for Identity for full security protection. When you have a DSA configured:
- The DSA connects to the domain controller at startup.
- The DSA queries the domain controller for data on entities seen in network traffic, monitored events, and monitored Event Tracing for Windows (ETW) activities.

A DSA is required for the following features and functionality:
- When working with a sensor installed on an AD FS / AD CS server
- To access the DeletedObjects container to collect information about deleted users and computers
- For domain and trust mapping, which occurs at sensor startup, and again every 10 minutes.
- To query another domain via LDAP for details, when detecting activities from entities in those other domains. |Directory Service Accounts for Microsoft Defender for Identity|

Related content