Identity Threat Detection & Response - on-prem to cloud ITDR from Microsoft

preview_player
Показать описание
Protect against identity-based attacks with Identity Threat Detection and Response capabilities. Ensure your organization is equipped to protect identities wherever they are—on-premises, in the cloud or hybrid. As an integral component of the XDR experience, identity alerts are contextualized within broader security incidents, enhancing your ability to manage threats effectively. The integrated Copilot experience and advanced hunting capabilities allow for in-depth investigation of alerts and activity logs. Security analysts and identity admins can collaborate seamlessly with bidirectional integration between Defender XDR and Microsoft Entra.

Daniel Lynch, Microsoft Defender for Identity’s Senior Product Manager, shares how Identity Threat Detection and Response can be utilized in daily operations and coordinated actions throughout every phase of an identity-related security incident, strengthening your organization's defense posture.

► QUICK LINKS:
00:00 - Stop identity-based attacks
01:13 - How to use Identity Threat Detection and Response
02:37 - See an active multi-stage incident
03:57 - Use Copilot for Security
05:08 - Advanced Hunting in Microsoft Defender XDR
05:38 - Block a compromised user account in Active Directory
06:44 - Improve security posture in Microsoft Defender XDR with Secure Score
08:04 - Wrap Up

► Link References:

► Unfamiliar with Microsoft Mechanics?
As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft.

► Keep getting this insider knowledge, join us on social:

#XDR #Cybersecurity #IdentitySecurity #MicrosoftEntra
Рекомендации по теме
Комментарии
Автор

4:19 "If I drill into our user Jeff.."
If only it was that easy to figure out why users do what users do.

matthouse
Автор

MDI is a great tool, but the licensing mechanism makes it soo damn expensive it's deterring.

Enlidev
Автор

Be interesting to see if this could replace ITDR from Crowdstrike. One thing I like about CS is I can do MFA for on-premise stuff that doesn't have native MFA capabilities.

breakingcustombc