Alerting when break-glass domain admin account has been used by someone

Bojan Zivkovic 506 Reputation points
2024-12-08T20:28:49.3066667+00:00

Hi, I have a break-glass domain admin account in several forests whose DCs have MDI sensors installed. Is it possible to get alert/mail notification when that account has been used by someone leveraging MDI events/logs?

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
238 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 670 Reputation points Microsoft Employee
    2025-01-21T06:42:54.9066667+00:00

    Hi @Bojan Zivkovic ,

    You can use the Link to incident tab after creating the required query to get the identity logon events. here is the link https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-link-to-incident

    Once this is done, use this link to set it up for alerts - https://learn.microsoft.com/en-us/defender-xdr/configure-email-notifications

    User's image

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.