Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
01Microsoft Defender XDR6 modules · 53 units · Defender XDR, Defender for Office 365, Entra ID Protection, Defender for Identity, and Defender for Cloud Apps0/53 units complete
Learning path 01 · Microsoft Defender XDR

6 modules · 53 units · Defender XDR, Defender for Office 365, Entra ID Protection, Defender for Identity, and Defender for Cloud Apps

0%

Study focus

Incident operations

Correlate, investigate, hunt, and remediate threats across Defender XDR.

Domain protection

Protect email, identities, Active Directory, cloud apps, and sensitive data.

6 modules · 53 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

05

Module 5

Safeguard your environment with Microsoft Defender for Identity

Focus: identity posture, sensors, Active Directory attack detection, investigation, remediation, and XDR integrations.
0/5
01 / 05Introduction to Defender for Identity

Defender for Identity monitors identity signals from on-premises AD, Entra ID, and supported providers. It builds behavioral baselines, detects anomalies, surfaces posture weaknesses in Secure Score, and identifies attack stages from reconnaissance to domain dominance.

  • Reconnaissance: suspicious LDAP or SMB enumeration.
  • Credential compromise: brute force and password spray.
  • Lateral movement: pass-the-ticket and overpass-the-hash.
  • Domain dominance: DCShadow or rogue domain-controller behavior.
Exam takeaway: MDI combines posture assessment with detection across the identity attack kill chain.
Official lessonCapabilities, posture, and attack techniques
02 / 05Configure Defender for Identity sensors

Sensors capture domain-controller network traffic, receive Windows and RADIUS events, resolve users/groups/computers, and send parsed security data to the cloud service.

  • Manage under Defender portal → Settings → Identities → On-premises → Sensors.
  • Sensor types include domain controller, AD FS, standalone, Entra Connect, and AD CS.
  • Standalone sensors require monitored DC FQDNs and capture adapters; include at least one global catalog.
  • Validate the sensor service and error log; verify DNS-query activity as MdiDnsQuery.
03 / 05Review compromised accounts or data

MDI alerts include title, description, evidence, affected entities, and an Excel export. Investigation follows the attack chain: reconnaissance → credential compromise → lateral movement → domain dominance → exfiltration.

The lesson scenario connects SMB reconnaissance, overpass-the-hash, pass-the-ticket, remote command execution, and creation of a privileged account. The key skill is correlating separate identity alerts into a coherent sequence and identifying where containment must occur.

Official lessonCompromised-domain investigation scenario
04 / 05Integrate with other Microsoft tools

MDI contributes on-premises and Entra identity signals directly to Defender XDR's unified incidents and graphs. Defender for Endpoint adds device-process context; Defender for Cloud Apps adds cloud activity; Security Copilot supports natural-language triage.

Other supported integrations include PAM platforms such as CyberArk, Delinea, and BeyondTrust, plus Okta identity activity.

Exam takeaway: MDI integration is native in Defender XDR—identity, endpoint, and cloud alerts are automatically correlated.
Official lessonXDR, Endpoint, Cloud Apps, PAM, Okta, and Copilot
05 / 05Summary and knowledge check
Requires on-premises Active Directory → True
The sensor-based core protection monitors on-premises identity infrastructure.
Advanced threat category → Reconnaissance
Not listed as an MDI integration → Intune
Official assessmentSummary and three questions
End of learning pathMicrosoft Defender XDR