Event banner

Level up identity protection: building a modern ITDR practice

Event Ended
Wednesday, Dec 06, 2023, 09:00 AM PST
Online

Event details

Attackers don’t break in, they log in. Get an in-depth look at Microsoft's point of view on identity threat detection and response (ITDR). Identities have become the new corporate security boundary and protecting your organization against these evolving threats requires a comprehensive strategy spanning capabilities both pre- and post-breach. Join this session for a detailed look at how we can help you implement comprehensive Identity protection across your unique identity landscape.

This session is part of the Microsoft Security Tech Accelerator. RSVP for event reminders, add it to your calendar, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event.

 

Heather_Poulsen
Updated Dec 27, 2024
  • jeffjerousek's avatar
    jeffjerousek
    Copper Contributor
    What is Microsoft's current recommendation for bringing MFA to on-prem admin accounts like Domain Admins without syncing to EntraID?
    • Chris Ayres's avatar
      Chris Ayres
      Icon for Microsoft rankMicrosoft
      Hi Jeff, the current design pattern for this is to have one account that is synced to Entra to which we can apply MFA and a secondary account that is used for the actual privileged action on the end service. The first account is used to actual allow the network path to be opened and then second account is the priv account then used for performing whatever the necessary action is. With the enforcement options we are building on the DC side, what that would mean is that without first going through Entra Private Access and authenticating the network path would the connection would not be allowed mitigating any risks of going direct to the service.
  • Trevor_Rusher's avatar
    Trevor_Rusher
    Icon for Community Manager rankCommunity Manager
    Welcome to "Level up identity protection: building a modern ITDR practice" and the Microsoft Security Tech Accelerator! Have a question? Post here in the Comments so we can help. Let’s make this an active Q&A!
  • Trevor_Rusher's avatar
    Trevor_Rusher
    Icon for Community Manager rankCommunity Manager

    Thanks for joining us! We hope you enjoyed this session. The Microsoft Security Tech Accelerator continues. Up next: Ask Microsoft Anything: Microsoft SIEM & XDR: Introducing the new Unified Security Operations Platform. 

     

    If you missed the live broadcast, don’t worry—you can watch it on demand. And we’ll continue to answer questions here in the chat through the end of the week. There's more great content in store at the Microsoft Security Tech Accelerator! What do you like about the event so far? Share your feedback and help shape the direction of future events on the Tech Community! 

  • jeffjerousek's avatar
    jeffjerousek
    Copper Contributor
    What kind of auditing and alerting can be created around creating exceptions in Defender for Identity?
    • Martin_Schvartzman's avatar
      Martin_Schvartzman
      Icon for Microsoft rankMicrosoft

      Every setting change in the portal is audited. Today you can open a support case and ask for the audit logs, but we'll release soon the option to search and export the audit log directly from the portal.
      Though this page is not Defender for Identity explicit documentation, you can see more details about this capability and how to use it here: https://learn.microsoft.com/en-us/purview/audit-new-search

       

  • Dean_Gross's avatar
    Dean_Gross
    Silver Contributor
    how can organizations that are providing managed security services to clients efficiently manage the Entra features in the remote tenant? Azure Lighthouse does not support this scenario.
  • Dean_Gross's avatar
    Dean_Gross
    Silver Contributor
    Defender for Cloud and some other upcoming features use the phrase Attack Path to describe the same concept as the "Lateral Movement" screen in this solution, it would be helpful if the same terminology was used across the MS products. I would like to suggest that the Lateral Movement screen be renamed to Attack Path to emphasize the importance and to be consistent with the other products
    • Chris Ayres's avatar
      Chris Ayres
      Icon for Microsoft rankMicrosoft
      Hi Dean, thanks for the feedback. This will be certainly be taken into account as we iterate and evolve our service going forwards.
Date and Time
Dec 6, 20239:00 AM - 9:30 AM PST