Microsoft Defender for Identity [New Commerce Experience]
Microsoft Defender for Identity
Microsoft Defender for Identity detects identity attacks against on-premises Active Directory: privilege escalation, lateral movement, and exploitable misconfigurations such as unconstrained Kerberos delegation. It works by installing sensors on domain controllers, and on AD FS, AD CS and Microsoft Entra Connect servers, which parse local traffic and Windows events and send only the required signals to the cloud service. That architecture decides who should buy it. A tenant with no domain controllers has nothing to install a sensor on, and for an environment of Microsoft Entra accounts only, Microsoft directs you to Microsoft Entra ID Protection instead.
What it is
Microsoft Defender for Identity is an identity threat detection and response service for hybrid environments. It reads signals from on-premises Active Directory and contributes them to Microsoft Defender XDR, where identity alerts correlate with endpoint, email and cloud app signals into single incidents.
Who it is for
Organisations running Active Directory Domain Services on-premises, or in a hybrid arrangement with Microsoft Entra ID. It protects on-premises AD DS accounts and accounts synchronised into Entra ID.
Who should not buy it
A cloud-only tenant. Defender for Identity works through sensors installed on domain controllers and related identity servers. With no domain controllers there is nowhere to install one. For an environment made up only of Microsoft Entra accounts, Microsoft's guidance is to use Microsoft Entra ID Protection instead. This is the single most common mis-purchase on this product.
Key capabilities
- Detection of privilege escalation, lateral movement and identity-based attack techniques
- Identity security posture assessments that surface exploitable misconfigurations and give remediation paths
- Monitoring of all devices authenticating against Active Directory, including non-Windows and mobile devices
- Multi-forest support, including forests with no trust between them
- Remediation actions on affected identities, executed by the sensor on the domain controller
- Contribution to Microsoft Defender XDR incidents and automatic attack disruption
What it collects
Network traffic to and from domain controllers such as Kerberos and NTLM authentication and DNS queries, Windows security events, Active Directory structure information, and entity information such as names and email addresses. Sensors parse locally and send only the required signals, so there is no port mirroring and no dedicated on-premises appliance.
Requirements
Domain controllers on Windows Server 2016, 2019 with KB4487044, 2022 or 2025. Microsoft .NET Framework 4.7 or later. At least two cores and 6 GB of RAM on the domain controller, and a minimum of 6 GB of free disk space with 10 GB recommended. Outbound access to the Defender for Identity cloud service on port 443. There is a default limit of 30 directory service credentials per workspace, which matters in multi-forest estates.
Do I need Defender for Identity if my tenant is cloud only?
No. It works through sensors on domain controllers and related identity servers, so a tenant with no on-premises Active Directory has nothing to install. For an environment of Microsoft Entra accounts only, Microsoft directs you to Microsoft Entra ID Protection instead.
Where do the sensors go?
On all domain controllers including read-only ones, and on AD FS, AD CS and Microsoft Entra Connect servers where those exist and are not domain controllers.
What are the server requirements?
Domain controllers on Windows Server 2016, 2019 with KB4487044, 2022 or 2025, with .NET Framework 4.7 or later, at least two cores and 6 GB of RAM, and 6 GB of free disk space with 10 GB recommended. Outbound access on port 443 to the cloud service is required.
Does it only see Windows devices?
No. It monitors every device performing authentication and authorisation requests against Active Directory, including non-Windows and mobile devices.
Does it work across multiple forests?
Yes, including forests with no trust between them. One credential covers all forests with a two-way trust; each untrusted forest needs its own. The default limit is 30 directory service credentials per workspace.
- Vendor
- Microsoft
- Category
- Security
- Type
- SaaS
- Billing
- Monthly
- Commitment
- 1-Year
- Available terms
- 1-Year, Monthly
- Unit price
- €4.50 /mo
- SKU
- MST-NCE-133-C100
Attachable SKUs from the same category. Check each add-on's prerequisites for base-licence eligibility.
- 1You prepay through ITSailor (Malta) — VAT handled, reverse-charge for valid EU VAT IDs.
- 2We provision through Pax8 wholesale into your Microsoft tenant — no third-party MSP markup.
- 3You keep the tenant. Sovereign by default — every engagement closes with an Exit Kit.
Pax8 wholesale, margin in the price
Microsoft Defender Vulnerability Management Add-on (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management add-on is available to Defender for Endpoint Plan 2 customers to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.
Microsoft Entra ID P1 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P1 provides single sign-on to thousands of cloud (SaaS) apps and access to web apps you run on-premises. Built for ease of use, Microsoft Entra ID P1 features multi-factor authentication (MFA); access control based on device health, user location, and identity; and holistic security reports, audits,
Microsoft Entra ID P2 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P2 includes all the capabilities of P1 plus advanced identity protection features such as Identity Protection, which helps detect potential vulnerabilities affecting your organization’s identities, and Privileged Identity Management, which helps manage, control, and monitor access within your organiz
Microsoft Defender Vulnerability Management (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management standalone is a comprehensive vulnerability management solution to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.