Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
238 questions
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi, I have a break-glass domain admin account in several forests whose DCs have MDI sensors installed. Is it possible to get alert/mail notification when that account has been used by someone leveraging MDI events/logs?
Hi @Bojan Zivkovic ,
You can use the Link to incident tab after creating the required query to get the identity logon events. here is the link https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-link-to-incident
Once this is done, use this link to set it up for alerts - https://learn.microsoft.com/en-us/defender-xdr/configure-email-notifications