Courseiva

Microsoft Defender for Identity: Monitored Activities

Your organization is implementing Microsoft Defender for Identity to protect on-premises Active Directory. Which THREE activities does Defender for Identity monitor?

Quick Answer

The answer is reconnaissance attacks using LDAP queries, lateral movement paths, and privilege escalation. Defender for Identity monitors these specific on-premises Active Directory activities because they represent the core stages of a cyberattack chain: reconnaissance via LDAP queries reveals how attackers map the environment, lateral movement paths show potential routes to high-value accounts, and privilege escalation indicates an attempt to gain elevated access. On the Microsoft Cybersecurity Architect exam, this question tests your ability to distinguish Defender for Identity’s scope from other Microsoft security tools—a common trap is confusing it with file integrity monitoring (Defender for Servers) or network traffic monitoring (Defender for Network). Remember that Defender for Identity is laser-focused on identity-based attack behaviors within AD, not files or internet traffic. A helpful memory tip: think “R-L-P” for Recon, Lateral movement, Privilege escalation—the three pillars of identity threat detection.

⚠ Common exam trap

SC-100 often tests the boundary between Defender for Identity (identity/AD attack detection) and Defender for Servers/Endpoint (file integrity, host monitoring) — candidates pick file integrity or network monitoring because those sound security-relevant but belong to other products.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privilege escalation attempts

Defender for Identity is designed to detect advanced threats against on-premises Active Directory by analyzing signals from domain controllers and AD FS. Option A is correct because it identifies privilege escalation attempts, such as unauthorized additions to privileged groups or abuse of AdminSDHolder, by monitoring directory changes and authentication events. Option B is correct because it detects lateral movement techniques like Pass-the-Hash by correlating NTLM authentication anomalies and suspicious logon patterns across domain controllers. Option D is correct because it flags reconnaissance attacks that use LDAP queries to enumerate users, groups, and privileged accounts, which is a common precursor to AD attacks. Option C is not correct because file integrity monitoring on domain controllers is not a Defender for Identity capability; that is handled by other tools such as Microsoft Defender for Endpoint or File Integrity Monitoring in Defender for Cloud. Option E is not correct because Defender for Identity focuses on identity and directory signals rather than monitoring outbound network traffic to external IP addresses, which is covered by network security solutions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Privilege escalation attempts

    Why this is correct

    Defender for Identity monitors domain controller traffic for privilege escalation attempts, detecting techniques such as adding accounts to privileged groups or exploiting unpatched escalation paths, which satisfies the stem's requirement to identify on-premises Active Directory attack activity.

  • ✓

    Lateral movement paths using Pass-the-Hash

    Why this is correct

    Pass-the-Hash detection works because Defender for Identity inspects NTLM authentication traffic on domain controllers, flagging reused credential material across hosts. This satisfies the stem's requirement to monitor lateral movement paths, identifying compromised accounts moving between on-premises Active Directory systems.

  • ✗

    File integrity changes on domain controllers

    Why it's wrong here

    Defender for Identity parses authentication, directory-replication and DNS traffic; it does not baseline domain controller file integrity, which is File Integrity Monitoring's role. It would be tempting where host file tampering must be detected, but that sensor is absent here.

  • ✓

    Reconnaissance attacks using LDAP queries

    Why this is correct

    LDAP-based reconnaissance is detected because Defender for Identity analyses directory queries against domain controllers, spotting enumeration patterns such as excessive sensitive attribute reads. This satisfies the stem's requirement to monitor reconnaissance activity targeting on-premises Active Directory.

  • ✗

    Network traffic to external IP addresses

    Why it's wrong here

    Defender for Identity inspects authentication, replication and DNS events on domain controllers, not outbound traffic to external IP addresses, which network inspection tools handle. Monitoring egress destinations would be the right choice for detecting command-and-control beaconing, not identity threats.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Defender for Identity (MDI) to protect on-premises Active Directory. You need to integrate MDI with Microsoft Sentinel to centralize detection and response. What is the required configuration?

medium
  • A.Deploy the MDI sensor on an Azure VM to send data to Sentinel.
  • B.Integrate Microsoft Entra ID Protection with Sentinel instead.
  • ✓ C.Enable the Microsoft Defender for Identity data connector in Microsoft Sentinel.
  • D.Configure MDI to forward logs to a Syslog server, then use the Syslog connector in Sentinel.

Why C: The correct option is C: enabling the Microsoft Defender for Identity data connector in Microsoft Sentinel. MDI integrates with Sentinel through a built-in data connector that streams MDI alerts and related identity events into the Sentinel workspace, allowing centralized detection and response without extra infrastructure. Option A is unnecessary because the MDI sensor is deployed on domain controllers or AD FS servers, not Azure VMs, and the sensor does not send data directly to Sentinel. Option B is incorrect because Entra ID Protection covers cloud identity risk, not on-premises AD signals from MDI. Option D is incorrect because MDI does not natively forward to Syslog for Sentinel ingestion; the supported path is the MDI data connector.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.