• Home
  • Consulting Offerings
    • Copilot – AI
    • Workshops & Trainings
    • Assessments
    • Architecture design session
    • Proof of concept
    • Managed Services
    • Resources
  • Managed Services
  • E-Suite
    • E-Suite ofertas de descubrimiento
    • E-Visor
    • E-Visor Teams App
    • E-Vigilant
    • E-Inspector
    • E-Cryptor
    • E-Migrator
    • Resources
  • Solutions
    • Advanced Compliance
    • Secure Communications
    • Device Management
    • Threat Response
    • Identity Optimization
    • Information Protection
    • Resources
  • Events
  • About us
    • News and events
    • Careers
    • Partners
    • Microsoft FastTrack Ready Partner
    • Personal data processing policy
    • Terms & Conditions
    • Support
  • Blog

Microsoft Defender for Identity (MDI) E-mmersion

Introducing our E-mmersion: Microsoft Defender for Identity (MDI)

Our E-mmersion provides a hands-on, immersive learning experience designed to deepen your understanding of Microsoft Defender for Identity. Through interactive exercises and real-world scenarios, you will explore how MDI enhances identity security, detects advanced threats, and integrates seamlessly with other Microsoft security solutions. This lab empowers you to proactively safeguard your organization’s identity infrastructure against evolving cyber threats.

By participating in this E-mmersion, you will see firsthand…

Practical Experience: Implement and manage Microsoft Defender for Identity sensors in a controlled environment.
Threat Detection and Analysis: Learn to identify anomalous behaviors and investigate real-time alerts using advanced MDI capabilities.
Attack Scenario Simulation: Engage in exercises simulating lateral movement and credential theft to better understand common attack vectors.

Agenda & Activities : Your Defender for Identity E-mmersion Journey

Introduction

Welcome, objectives, and an overview of Microsoft Defender for Identity.

Lab Environment Access

Access validation and a brief tour of the lab interface.

Hands-On Exercises

Participants will explore MDI capabilities in a controlled environment, analyzing security data, user activities, and risk indicators. They will also simulate attack scenarios like lateral movement, credential theft, and reconnaissance.

Scenario Analysis & Discussion

A review of real-time alerts will provide insights into detection logic, response strategies, and best practices for mitigating identity-based threats.

Closing

The session will end with a Q&A, key takeaways, and next steps. Participants can provide feedback and receive guidance on additional resources and future training opportunities.

Identity protection in action: Real-World scenarios enhancing your security

ATTACK, DETECT & INVESTIGATE – LAB 1 – (LIGHT)

User and IP address reconnaissance (SMB)

SMB enumeration on a domain controller triggers an alert, exposing SYSVOL access patterns that attackers use to track login and move laterally.

Network Mapping Reconnaissance (DNS)

Attackers map networks via DNS reconnaissance; this alert detects unauthorized AXFR transfers and excessive queries.

Investigate a Reconnaissance & Discovery Alert

SMB enumeration on a domain controller triggers an alert, exposing SYSVOL access patterns that attackers use to track login and move laterally.

CREDENTIAL ACCESS ALERTS – LAB 2 – (FULL)

Security Principal Reconnaissance (LDAP)

Defender for Identity detects LDAP reconnaissance, the initial phase of Kerberoasting attacks where attackers enumerate SPNs to obtain TGS tickets.

Suspected DC Sync attack (replication of directory services)/p>

If attackers have DS-Replication-Get-Changes-All permission, they can replicate Active Directory data, triggering an alert if done from a non-domain controller.

Investigate a Credential Access Alert

MDI helps discover and analyze attacks, ensuring your environment's security. Investigate credential access alerts to understand potential threats.

Suspicious connection over EFS Remote Protocol

MDI detects LDAP reconnaissance, often the first phase of a Kerberoasting attack, used to gather Security Principal Names (SPNs) for obtaining TGS tickets.

Investigate a Lateral Movement Alert

Microsoft Defender for Identity helps discover and analyze attacks, ensuring security. Investigate lateral movement alerts to understand threats.

Data Exfiltration Over SMB

This alert triggers when suspicious data transfers, like copying the ntds.dit file from a domain controller to a workstation, are detected.

Investigate Other Alerts

Microsoft Defender for Identity helps discover and analyze attacks, ensuring security. Investigate other alerts to understand potential threats.

Additional information

This E-mmersion experience is designed for technical decision-makers and IT professionals to enhance their security posture using Microsoft Defender for Identity.

Gain practical experience in implementing and managing Microsoft Defender for Identity solutions to detect and respond to advanced threats targeting your organization.

Engage in hands-on activities with real-world scenarios focused on protecting identities and improving organizational security posture.

Receive technical support and expert guidance throughout the entire E-mmersion experience.

How to get started?

Contact us to learn more about the Microsoft Defender for Identity (MDI) E-mmersion experience or our consulting services:

Download Datasheet

Contact us for more information

No se pudo guardar tu contacto. Por favor inténtalo de nuevo.
Su contacto ha sido enviado exitosamente.
The SMS field must contain between 6 and 19 digits and include the country code without using +/0 (e.g. 1xxxxxxxxxx for the United States)
?

©2020 Synergy Advisors LLC. ALL RIGHTS RESERVED.

Contact Us at (+1) 425-689-3310 or through our Support Page