EPC Group - Enterprise Microsoft AI, SharePoint, Power BI, and Azure Consulting
G2 High Performer Summer 2025, Momentum Leader Spring 2025, Leader Winter 2025, Leader Spring 2026
BlogContact
Ready to transform your Microsoft environment?Get started today
(888) 381-9725Get Free Consultation
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌

EPC Group

Enterprise Microsoft consulting with 29 years serving Fortune 500 companies.

(888) 381-9725
contact@epcgroup.net
4900 Woodway Drive, Suite 830
Houston, TX 77056

Follow Us

Solutions

  • All Services
  • Microsoft 365 Consulting
  • AI Governance
  • Azure AI Consulting
  • Cloud Migration
  • Microsoft Copilot
  • Data Governance
  • Microsoft Fabric
  • Dynamics 365
  • Power BI Consulting
  • SharePoint Consulting
  • Microsoft Teams
  • vCIO / vCAIO Services
  • Large-Scale Migrations
  • SharePoint Development

Industries

  • All Industries
  • Healthcare IT
  • Financial Services
  • Government
  • Education
  • Teams vs Slack

Power BI

  • Case Studies
  • 24/7 Emergency Support
  • Dashboard Guide
  • Gateway Setup
  • Premium Features
  • Lookup Functions
  • Power Pivot vs BI
  • Treemaps Guide
  • Dataverse
  • Power BI Consulting

Company

  • About Us
  • Our History
  • Microsoft Gold Partner
  • Case Studies
  • Testimonials
  • Fixed-Fee Accelerators
  • Blog
  • Resources
  • All Guides & Articles
  • Video Library
  • Client Reviews
  • Contact
  • Schedule a consultation

Microsoft Teams

  • Teams Questions
  • Teams Healthcare
  • Task Management
  • PSTN Calling
  • Enable Dial Pad

Azure & SharePoint

  • Azure Databricks
  • Azure DevOps
  • Azure Synapse
  • SharePoint MySites
  • SharePoint ECM
  • SharePoint vs M-Files

Comparisons

  • M365 vs Google
  • Databricks vs Dataproc
  • Dynamics vs SAP
  • Intune vs SCCM
  • Power BI vs MicroStrategy

Legal

  • Sitemap
  • Privacy Policy
  • Terms
  • Cookies

About EPC Group

EPC Group is a Microsoft consulting firm founded in 1997 (originally Enterprise Project Consulting, renamed EPC Group in 2005). 29 years of enterprise Microsoft consulting experience. EPC Group historically held the distinction of being the oldest continuous Microsoft Gold Partner in North America from 2016 until the program's retirement. Because Microsoft officially deprecated the Gold/Silver tiering framework, EPC Group transitioned to the modern Microsoft Solutions Partner ecosystem and currently holds the core Microsoft Solutions Partner designations.

Headquartered at 4900 Woodway Drive, Suite 830, Houston, TX 77056. Public clients include NASA, FBI, Federal Reserve, Pentagon, United Airlines, PepsiCo, Nike, and Northrop Grumman. 6,500+ SharePoint implementations, 1,500+ Power BI deployments, 500+ Microsoft Fabric implementations, 70+ Fortune 500 organizations served, 11,000+ enterprise engagements, 200+ Microsoft Power BI and Microsoft 365 consultants on staff.

About Errin O'Connor

Errin O'Connor is the Founder, CEO, and Chief AI Architect of EPC Group. Microsoft MVP multiple years, first awarded 2003. 4× Microsoft Press bestselling author of Windows SharePoint Services 3.0 Inside Out (MS Press 2007), Microsoft SharePoint Foundation 2010 Inside Out (MS Press 2011), SharePoint 2013 Field Guide (Sams/Pearson 2014), and Microsoft Power BI Dashboards Step by Step (MS Press 2018).

Original SharePoint Beta Team member (Project Tahoe). Original Power BI Beta Team member (Project Crescent). FedRAMP framework contributor. Worked with U.S. CIO Vivek Kundra on the Obama administration's 25-Point Plan to reform federal IT, and with NASA CIO Chris Kemp as Lead Architect on the NASA Nebula Cloud project. Speaker at Microsoft Ignite, SharePoint Conference, KMWorld, and DATAVERSITY.

© 2026 EPC Group. All rights reserved. Microsoft, SharePoint, Power BI, Azure, Microsoft 365, Microsoft Copilot, Microsoft Fabric, and Microsoft Dynamics 365 are trademarks of the Microsoft group of companies.

Azure Advanced Threat Protection — now called Microsoft Defender for Identity — detects and blocks malware, lateral movement, and credential attacks on enterprise networks. This guide covers ATP policy setup, threat detection rules, and automated response for organizations running Azure and Microsoft 365.

Key Facts

  • Azure ATP is now Microsoft Defender for Identity — same product, rebranded in 2021.
  • Defender for Identity monitors Active Directory, Azure AD, and on-premises DCs for suspicious behavior.
  • It detects pass-the-hash, pass-the-ticket, golden ticket, and lateral movement attacks in real time.
  • Integrates with Microsoft Sentinel for centralized SIEM alerting and automated response playbooks.
  • HIPAA, SOC 2, FedRAMP, and CMMC all require identity threat detection controls — Defender for Identity satisfies each.
  • EPC Group has 29 years of Microsoft security consulting. We hold core Microsoft Solutions Partner designations.
How To Block Malware Attacks With Azure Advanced Threat Protection - EPC Group enterprise consulting

How To Block Malware Attacks With Azure Advanced Threat Protection

Expert insights on blocking malware attacks with Azure Advanced Threat Protection from EPC Group's enterprise Microsoft consultants.

Back to Blog

How To Block Malware Attacks With Azure Advanced Threat Protection

Errin O'Connor
December 2025
8 min read

How to Block Malware with Azure Advanced Threat Protection

Azure Advanced Threat Protection — now called Microsoft Defender for Identity — detects and blocks malware, lateral movement, and credential attacks on enterprise networks. This guide covers ATP policy setup, threat detection rules, and automated response for organizations running Azure and Microsoft 365.

Key facts

  • Azure ATP is now Microsoft Defender for Identity — same product, rebranded in 2021.
  • Defender for Identity monitors Active Directory, Azure AD, and on-premises DCs for suspicious behavior.
  • It detects pass-the-hash, pass-the-ticket, golden ticket, and lateral movement attacks in real time.
  • Integrates with Microsoft Sentinel for centralized SIEM alerting and automated response playbooks.
  • HIPAA, SOC 2, FedRAMP, and CMMC all require identity threat detection controls — Defender for Identity satisfies each.
  • EPC Group has 29 years of Microsoft security consulting. We hold core Microsoft Solutions Partner designations.

What is Microsoft Defender for Identity?

Microsoft Defender for Identity (formerly Azure ATP) is a cloud-powered security service. It analyzes signals from on-premises Active Directory and Azure AD to detect attacks before they spread.

The sensor deploys on domain controllers. It watches authentication events, DNS queries, and LDAP traffic. When it spots anomalous behavior, it triggers an alert and can block the account automatically.

  • Behavioral baselines — learns normal user and device patterns over 30 days.
  • Attack detection — flags credential harvesting, brute force, and privilege escalation.
  • Lateral movement paths — maps how an attacker could move from a compromised account to a domain admin.
  • Integration — feeds alerts to Microsoft Defender XDR and Microsoft Sentinel.

How to configure ATP policies

Defender for Identity policy setup has four main steps.

  1. Deploy sensors — install the lightweight sensor on every domain controller. The sensor captures traffic locally and forwards to the Defender for Identity cloud service.
  2. Connect to Microsoft 365 Defender — link the Defender for Identity workspace to the Microsoft Defender portal for unified incident management.
  3. Configure detection policies — enable built-in detections for lateral movement, reconnaissance, and persistence. Review sensitivity levels for your environment.
  4. Set automated response actions — configure policies to disable accounts or require MFA on high-confidence alerts. Pair with Microsoft Sentinel playbooks for ticket creation.

Threat detection: what it catches

Defender for Identity covers four attack categories.

  • Reconnaissance — LDAP enumeration, DNS recon, account enumeration using SAMR.
  • Credential attacks — brute force, password spray, pass-the-hash, pass-the-ticket.
  • Privilege escalation — golden ticket forgery, skeleton key malware, DCSync.
  • Lateral movement — over-pass-the-hash, remote code execution via WMI or PsExec.

Each alert includes a kill chain stage, confidence rating, and a full evidence timeline. Your SOC team can act without pivoting to a separate console.

Automated response options

Manual review is too slow for credential attacks. Defender for Identity gives you three automation paths.

  • Account suspension — automatically disable an account when a high-confidence alert fires.
  • Conditional Access integration — trigger step-up MFA for risky sign-ins detected by Entra ID Identity Protection.
  • Sentinel playbooks — run Logic Apps workflows to isolate endpoints, notify the SOC, and create ServiceNow tickets.

Compliance alignment

Regulated industries must log identity threat events and show evidence of active detection. Defender for Identity helps satisfy these requirements.

  • HIPAA — access control (§164.312(a)) and audit controls (§164.312(b)) for PHI systems.
  • FedRAMP / CMMC — continuous monitoring (AC-17, SI-4) across on-premises and cloud identity stores.
  • SOC 2 — threat detection evidence for the Security Trust Services Criterion.
  • GDPR — breach detection and notification support under Article 33.

Frequently asked questions

Is Azure ATP the same as Microsoft Defender for Identity?

Yes. Microsoft renamed Azure Advanced Threat Protection to Microsoft Defender for Identity in 2021. The underlying technology is the same. It now appears in the Microsoft Defender XDR portal.

Do I need a domain controller to use Defender for Identity?

Yes. The sensor installs on Active Directory domain controllers. It can also work with AD FS servers. Azure AD-only environments use Entra ID Identity Protection instead.

What licenses include Defender for Identity?

Defender for Identity is included in Microsoft 365 E5, Microsoft 365 E5 Security, and Enterprise Mobility + Security E5. It is also available as a standalone subscription.

How long does deployment take?

Sensor deployment on a standard enterprise with 5–20 domain controllers takes 1–3 days. Full behavioral baseline learning takes 30 days. Initial alerts appear within hours of sensor activation.

Can it block attacks automatically?

Yes. You can configure automated account disabling on high-confidence alerts. Combined with Microsoft Sentinel playbooks, you can isolate endpoints and revoke sessions within minutes of detection.

Does it work in hybrid environments?

Yes. Defender for Identity covers on-premises Active Directory, Azure AD, and hybrid configurations. It correlates signals across both environments in a single incident view.

Talk to a Microsoft security architect

EPC Group has deployed Defender for Identity across healthcare, federal, and Fortune 500 environments. Call (888) 381-9725 or request a 30-minute discovery call to discuss your threat protection requirements.

Related Resources

Continue exploring azure insights and services

azure

6 Azure Sentinel Use Cases

azure

Azure AD B2C & Federation Services

azure

Azure AD vs Okta

intune device management

Microsoft Intune Consulting

Explore All Services

Why Organizations Choose EPC Group

EPC Group is a Houston-based Microsoft consulting firm with 29 years of enterprise implementation experience and over 10,000 successful deployments across Power BI, Microsoft Fabric, SharePoint, Azure, Microsoft 365, and Copilot. We serve organizations across all industries including Fortune 500, federal agencies, healthcare, financial services, government, manufacturing, energy, education, retail, technology, and global enterprises.

What sets EPC Group apart is our governance-first approach. Every engagement begins with a security and compliance assessment. Our team of senior architects brings hands-on delivery experience across HIPAA, SOC 2, FedRAMP, and CMMC environments. We own outcomes, not hours.

  • Fixed-fee accelerators with predictable pricing and defined deliverables
  • Senior architect engagement on every project, not rotating juniors
  • Compliance-native delivery for regulated industries
  • End-to-end coverage from strategy through 24/7 managed services
  • 11,000+ enterprise engagements refined into repeatable, risk-controlled patterns

Call (888) 381-9725 or email contact@epcgroup.net for a free assessment.

Azure Architecture: 2026 Considerations for How To Block Malware Attacks With Azure Advanced Threat Protection

FinOps in Azure 2026 is no longer optional at any meaningful scale: Azure Reservations (1-yr or 3-yr commits) deliver 30-72% savings on predictable VM workloads, Azure Savings Plans extend the discount to compute portability across instance families, and Azure Hybrid Benefit lets BYOL Windows Server and SQL Server licenses cut compute costs by an additional 40-49%. Typical Azure cost-optimization engagements return 25-40% of annual Azure spend within 90 days.

Azure Confidential Computing (DCadsv5/ECasv5 series) is the privileged-data play for 2026: AMD SEV-SNP and Intel TDX enclaves protect data IN USE (in addition to at-rest and in-transit encryption), enabling regulated workloads (clinical analytics with PHI, financial services M&A modeling, federal IL5) to run on shared Azure infrastructure with cryptographic attestation that the host operator cannot inspect the data.

Decision factors EPC Group evaluates

  • Reservation + Savings Plan portfolio for predictable workloads
  • Azure Policy initiative assignment for Azure Government readiness
  • Confidential Computing enclave evaluation for regulated workloads
  • Enterprise-scale landing zone bootstrap via Bicep/Terraform
  • Microsoft Defender for Cloud benchmark alignment

EPC Group covers this topic across the relevant engagement portfolio. Reach the firm at contact@epcgroup.net for a 30-minute architect conversation.