Skip to content
Microsoft logo
Microsoft

Microsoft Defender for Identity [New Commerce Experience]

SecuritySaaSMonthly1-Year
SKU MST-NCE-133-C100

Microsoft Defender for Identity

Microsoft Defender for Identity detects identity attacks against on-premises Active Directory: privilege escalation, lateral movement, and exploitable misconfigurations such as unconstrained Kerberos delegation. It works by installing sensors on domain controllers, and on AD FS, AD CS and Microsoft Entra Connect servers, which parse local traffic and Windows events and send only the required signals to the cloud service. That architecture decides who should buy it. A tenant with no domain controllers has nothing to install a sensor on, and for an environment of Microsoft Entra accounts only, Microsoft directs you to Microsoft Entra ID Protection instead.

What it is

Microsoft Defender for Identity is an identity threat detection and response service for hybrid environments. It reads signals from on-premises Active Directory and contributes them to Microsoft Defender XDR, where identity alerts correlate with endpoint, email and cloud app signals into single incidents.

Who it is for

Organisations running Active Directory Domain Services on-premises, or in a hybrid arrangement with Microsoft Entra ID. It protects on-premises AD DS accounts and accounts synchronised into Entra ID.

Who should not buy it

A cloud-only tenant. Defender for Identity works through sensors installed on domain controllers and related identity servers. With no domain controllers there is nowhere to install one. For an environment made up only of Microsoft Entra accounts, Microsoft's guidance is to use Microsoft Entra ID Protection instead. This is the single most common mis-purchase on this product.

Key capabilities

  • Detection of privilege escalation, lateral movement and identity-based attack techniques
  • Identity security posture assessments that surface exploitable misconfigurations and give remediation paths
  • Monitoring of all devices authenticating against Active Directory, including non-Windows and mobile devices
  • Multi-forest support, including forests with no trust between them
  • Remediation actions on affected identities, executed by the sensor on the domain controller
  • Contribution to Microsoft Defender XDR incidents and automatic attack disruption

What it collects

Network traffic to and from domain controllers such as Kerberos and NTLM authentication and DNS queries, Windows security events, Active Directory structure information, and entity information such as names and email addresses. Sensors parse locally and send only the required signals, so there is no port mirroring and no dedicated on-premises appliance.

Requirements

Domain controllers on Windows Server 2016, 2019 with KB4487044, 2022 or 2025. Microsoft .NET Framework 4.7 or later. At least two cores and 6 GB of RAM on the domain controller, and a minimum of 6 GB of free disk space with 10 GB recommended. Outbound access to the Defender for Identity cloud service on port 443. There is a default limit of 30 directory service credentials per workspace, which matters in multi-forest estates.

Features
Sensors on domain controllers, AD FS, AD CS and Entra Connect
Detection of privilege escalation and lateral movement
Identity security posture assessments with remediation paths
Monitors all devices authenticating against Active Directory
Multi-forest support including untrusted forests
Remediation actions on compromised identities
Feeds Microsoft Defender XDR incidents
Use cases
Detecting lateral movement between workstations using compromised accounts
Surfacing exploitable Active Directory misconfigurations before an attacker does
Correlating on-premises identity signals with endpoint and email alerts
Monitoring authentication across forests left over from mergers
FAQ
Do I need Defender for Identity if my tenant is cloud only?

No. It works through sensors on domain controllers and related identity servers, so a tenant with no on-premises Active Directory has nothing to install. For an environment of Microsoft Entra accounts only, Microsoft directs you to Microsoft Entra ID Protection instead.

Where do the sensors go?

On all domain controllers including read-only ones, and on AD FS, AD CS and Microsoft Entra Connect servers where those exist and are not domain controllers.

What are the server requirements?

Domain controllers on Windows Server 2016, 2019 with KB4487044, 2022 or 2025, with .NET Framework 4.7 or later, at least two cores and 6 GB of RAM, and 6 GB of free disk space with 10 GB recommended. Outbound access on port 443 to the cloud service is required.

Does it only see Windows devices?

No. It monitors every device performing authentication and authorisation requests against Active Directory, including non-Windows and mobile devices.

Does it work across multiple forests?

Yes, including forests with no trust between them. One credential covers all forests with a two-way trust; each untrusted forest needs its own. The default limit is 30 directory service credentials per workspace.

Plan details
Vendor
Microsoft
Category
Security
Type
SaaS
Billing
Monthly
Commitment
1-Year
Available terms
1-Year, Monthly
Unit price
€4.50 /mo
SKU
MST-NCE-133-C100
How buying works
  1. 1You prepay through ITSailor (Malta) — VAT handled, reverse-charge for valid EU VAT IDs.
  2. 2We provision through Pax8 wholesale into your Microsoft tenant — no third-party MSP markup.
  3. 3You keep the tenant. Sovereign by default — every engagement closes with an Exit Kit.
Microsoft NCE termsNew Commerce Experience applies: within 7 days of activation you may cancel or reduce seats (pro-rated). After day 7 the subscription is committed for the term. We mirror this verbatim — no surprises.
Your price
Term
Billing cycle
€4.90/mo
Pax8 suggested retail €5.042% off Pax8 suggested retail
Quantity
1
Ask a question

Pax8 wholesale, margin in the price

More in Security
Add-on
Microsoft

Microsoft Defender Vulnerability Management Add-on (Education Student Pricing) [New Commerce Experience]

Microsoft Defender Vulnerability Management add-on is available to Defender for Endpoint Plan 2 customers to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.

€0.28/mo
SecurityEDU
SaaS
Microsoft

Microsoft Entra ID P1 (Education Student Pricing) [New Commerce Experience]

Microsoft Entra ID P1 provides single sign-on to thousands of cloud (SaaS) apps and access to web apps you run on-premises. Built for ease of use, Microsoft Entra ID P1 features multi-factor authentication (MFA); access control based on device health, user location, and identity; and holistic security reports, audits,

€0.28/mo
SecurityEDU
SaaS
Microsoft

Microsoft Entra ID P2 (Education Student Pricing) [New Commerce Experience]

Microsoft Entra ID P2 includes all the capabilities of P1 plus advanced identity protection features such as Identity Protection, which helps detect potential vulnerabilities affecting your organization’s identities, and Privileged Identity Management, which helps manage, control, and monitor access within your organiz

€0.42/mo
SecurityEDU
SaaS
Microsoft

Microsoft Defender Vulnerability Management (Education Student Pricing) [New Commerce Experience]

Microsoft Defender Vulnerability Management standalone is a comprehensive vulnerability management solution to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.

€0.42/mo
SecurityEDU