How to detect identity attacks before they cause damage
Attackers rarely start by deploying ransomware or stealing data. More often, they begin with identity reconnaissance, password spraying, token theft, suspicious sign-ins, or abuse of a legitimate user account. In 2026, the fastest way to reduce damage is to detect those signals early, correlate them across Microsoft 365, endpoints, identities, cloud apps, and email, and respond before the attacker can move laterally.
From ATA to Microsoft Defender XDR: what changed
The original version of this article focused on Microsoft Advanced Threat Analytics (ATA), Azure Active Directory Premium, and Cloud App Security. Those names and portals are now outdated. ATA has been retired and replaced by Microsoft Defender for Identity. Azure Active Directory is now Microsoft Entra ID, with Entra ID P1 and P2 plans. Cloud App Security is now Microsoft Defender for Cloud Apps. The modern investigation experience is Microsoft Defender XDR, which brings together identity, endpoint, email, collaboration, and cloud app signals into correlated incidents.
What modern identity attack detection should include
A current Microsoft security architecture should detect both known attack techniques and abnormal behavior. Microsoft Defender for Identity helps identify identity reconnaissance, lateral movement, credential theft techniques, suspicious Kerberos activity, Pass-the-Hash, Pass-the-Ticket, Kerberoasting, abnormal LDAP queries, and risky domain controller activity. Microsoft Entra ID Protection, included with Entra ID P2, adds user risk and sign-in risk detections such as leaked credentials, atypical travel, unfamiliar sign-in properties, and suspicious sign-in patterns. Microsoft Defender for Cloud Apps extends visibility into SaaS usage, risky OAuth apps, impossible travel, unusual downloads, data exfiltration patterns, and session risk.
A modern attack flow: from suspicious sign-in to containment
A typical incident may begin with password spraying or username enumeration. Entra ID sign-in logs and risk detections can identify failed sign-in patterns, unfamiliar locations, and risky authentication attempts. If the attacker succeeds, Defender XDR can correlate the compromised user with endpoint activity, email events, cloud app behavior, and Defender for Identity alerts from Active Directory. Instead of reviewing isolated alerts, the security team investigates a single incident timeline with affected users, devices, mailboxes, apps, evidence, and recommended response actions.
What responders should do when credentials are suspected to be compromised
When the evidence indicates account compromise, response should be fast and controlled. Common actions include disabling or restricting the account, forcing a password reset, revoking refresh tokens, requiring MFA re-registration when appropriate, removing malicious inbox rules, blocking suspicious OAuth applications, isolating affected devices, reviewing privileged role assignments, and checking whether the attacker accessed or exfiltrated sensitive data. Defender XDR can support automated investigation and response, while Microsoft Sentinel can run SOAR playbooks for repeatable response workflows.
Prevention still matters: reduce the chance of compromise
Detection is most effective when combined with strong preventive controls. Organizations should enforce multifactor authentication, prioritize phishing-resistant authentication such as passkeys or certificate-based authentication where appropriate, use Conditional Access, require compliant or managed devices for sensitive access, apply least privilege, protect administrator roles with Microsoft Entra Privileged Identity Management, review guest access, govern app consent, and continuously monitor Microsoft Secure Score and exposure recommendations. These controls reduce the number of incidents your team must investigate.
Where Microsoft Sentinel fits
Microsoft Defender XDR is the primary portal for Microsoft 365 security investigation and response. Microsoft Sentinel adds SIEM and SOAR capabilities for organizations that need long-term log retention, custom correlation across Microsoft and non-Microsoft systems, advanced hunting, automation playbooks, and compliance-driven reporting. Sentinel is consumption-based, so planning should include data ingestion, retention, analytics rules, and automation requirements.
Licensing considerations in 2026
The right licensing depends on organization size, risk profile, and current Microsoft 365 plan. Microsoft 365 Business Premium includes strong security capabilities for many small and midsize businesses, including Entra ID P1, Microsoft Defender for Business, Intune, and Conditional Access. Microsoft 365 E5 and Microsoft 365 E5 Security add broader enterprise security capabilities, including Microsoft Defender XDR components and advanced identity and cloud app protection depending on the plan. Entra ID P2 is required for Entra ID Protection and Privileged Identity Management. Microsoft Sentinel is licensed separately based on usage. For CSP/NCE customers, subscription terms, add-ons, and annual or monthly commitment options should be reviewed before deployment.
How IT Partner can help
IT Partner can assess your current Microsoft 365 security posture, review identity and Conditional Access policies, validate Defender XDR readiness, configure Defender for Identity, evaluate Entra ID Protection, connect Defender for Cloud Apps, and design Microsoft Sentinel integration where it makes sense. The goal is not just to deploy tools, but to create a practical detection and response process your team can operate.
Key takeaways
- Microsoft Advanced Threat Analytics is retired; Microsoft Defender for Identity is the modern replacement for detecting many on-premises and hybrid identity attack techniques.
- Microsoft Defender XDR should be the central investigation experience for correlated Microsoft 365 security incidents.
- Microsoft Entra ID Protection helps detect risky users and risky sign-ins and can drive risk-based Conditional Access policies.
- Microsoft Defender for Cloud Apps adds SaaS activity, OAuth app, session, and data exfiltration visibility.
- Microsoft Sentinel is useful when you need SIEM/SOAR, long-term retention, custom correlation, and automation across Microsoft and non-Microsoft sources.
- Detection works best with prevention: MFA, phishing-resistant authentication, Conditional Access, least privilege, PIM, device compliance, and app governance.
If you are not sure whether your Microsoft 365 tenant can detect and contain identity attacks quickly, IT Partner can perform a Microsoft 365 security assessment or Defender XDR and Entra ID security review and provide a prioritized remediation plan.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.