Skip to main content

By Errin O'Connor, Founder & Chief AI Architect, EPC Group

Azure Advanced Threat Protection — now called Microsoft Defender for Identity — detects and blocks malware, lateral movement, and credential attacks on enterprise networks. This guide covers ATP policy setup, threat detection rules, and automated response for organizations running Azure and Microsoft 365.

Key Facts

  • Azure ATP is now Microsoft Defender for Identity — same product, rebranded in 2021.
  • Defender for Identity monitors Active Directory, Azure AD, and on-premises DCs for suspicious behavior.
  • It detects pass-the-hash, pass-the-ticket, golden ticket, and lateral movement attacks in real time.
  • Integrates with Microsoft Sentinel for centralized SIEM alerting and automated response playbooks.
  • HIPAA, SOC 2, FedRAMP, and CMMC all require identity threat detection controls — Defender for Identity satisfies each.
  • EPC Group has Microsoft security consulting since 1997. We hold core Microsoft Solutions Partner designations.
Back to Blog

How To Block Malware Attacks With Azure Advanced Threat Protection

Errin O'Connor
8 min read

How to Block Malware with Azure Advanced Threat Protection

Azure Advanced Threat Protection — now called Microsoft Defender for Identity — detects and blocks malware, lateral movement, and credential attacks on enterprise networks. This guide covers ATP policy setup, threat detection rules, and automated response for organizations running Azure and Microsoft 365.

Key facts

  • Azure ATP is now Microsoft Defender for Identity — same product, rebranded in 2021.
  • Defender for Identity monitors Active Directory, Azure AD, and on-premises DCs for suspicious behavior.
  • It detects pass-the-hash, pass-the-ticket, golden ticket, and lateral movement attacks in real time.
  • Integrates with Microsoft Sentinel for centralized SIEM alerting and automated response playbooks.
  • HIPAA, SOC 2, FedRAMP, and CMMC all require identity threat detection controls — Defender for Identity satisfies each.
  • EPC Group has Microsoft security consulting since 1997. We hold core Microsoft Solutions Partner designations.

What is Microsoft Defender for Identity?

Microsoft Defender for Identity (formerly Azure ATP) is a cloud-powered security service. It analyzes signals from on-premises Active Directory and Azure AD to detect attacks before they spread.

The sensor is installed on domain controllers. It monitors authentication events, DNS queries, and LDAP traffic. If it detects unusual behavior, it will trigger an alert and can automatically block the account.

  • Behavioral baselines — learns normal user and device patterns over 30 days.
  • Attack detection — flags credential harvesting, brute force, and privilege escalation.
  • Lateral movement paths — maps how an attacker could move from a compromised account to a domain admin.
  • Integration — feeds alerts to Microsoft Defender XDR and Microsoft Sentinel.

How to configure ATP policies

Defender for Identity policy setup has four main steps.

  1. Deploy sensors — install the lightweight sensor on every domain controller. The sensor captures traffic locally and forwards to the Defender for Identity cloud service.
  2. Connect to Microsoft 365 Defender — link the Defender for Identity workspace to the Microsoft Defender portal for unified incident management.
  3. Configure detection policies — enable built-in detections for lateral movement, reconnaissance, and persistence. Review sensitivity levels for your environment.
  4. Set automated response actions — configure policies to disable accounts or require MFA on high-confidence alerts. Pair with Microsoft Sentinel playbooks for ticket creation.

Threat detection: what it catches

Defender for Identity covers four attack categories.

  • Reconnaissance — LDAP enumeration, DNS recon, account enumeration using SAMR.
  • Credential attacks — brute force, password spray, pass-the-hash, pass-the-ticket.
  • Privilege escalation — golden ticket forgery, skeleton key malware, DCSync.
  • Lateral movement — over-pass-the-hash, remote code execution via WMI or PsExec.

Each alert includes a kill chain stage, confidence rating, and a full evidence timeline. Your SOC team can act without pivoting to a separate console.

Automated response options

Manual review is too slow for credential attacks. Defender for Identity gives you three automation paths.

  • Account suspension — automatically disable an account when a high-confidence alert fires.
  • Conditional Access integration — trigger step-up MFA for risky sign-ins detected by Entra ID Identity Protection.
  • Sentinel playbooks — run Logic Apps workflows to isolate endpoints, notify the SOC, and create ServiceNow tickets.

Compliance alignment

Regulated industries must log identity threat events and show evidence of active detection. Defender for Identity helps satisfy these requirements.

  • HIPAA — access control (§164.312(a)) and audit controls (§164.312(b)) for PHI systems.
  • FedRAMP / CMMC — continuous monitoring (AC-17, SI-4) across on-premises and cloud identity stores.
  • SOC 2 — threat detection evidence for the Security Trust Services Criterion.
  • GDPR — breach detection and notification support under Article 33.

Frequently asked questions

Is Azure ATP the same as Microsoft Defender for Identity?

Yes. Microsoft renamed Azure Advanced Threat Protection to Microsoft Defender for Identity in 2021. The underlying technology is the same. It now appears in the Microsoft Defender XDR portal.

Do I need a domain controller to use Defender for Identity?

Yes. The sensor installs on Active Directory domain controllers. It can also work with AD FS servers. Azure AD-only environments use Entra ID Identity Protection instead.

What licenses include Defender for Identity?

Defender for Identity is included in Microsoft 365 E5, Microsoft 365 E5 Security, and Enterprise Mobility + Security E5. It is also available as a standalone subscription.

How long does deployment take?

Deploying sensors on a typical enterprise with 5–20 domain controllers takes between 1 and 3 days. The full behavioral baseline learning process requires 30 days. Initial alerts will appear within hours after the sensor is activated.

Can it block attacks automatically?

Yes. You can configure automated account disabling on high-confidence alerts. Combined with Microsoft Sentinel playbooks, you can isolate endpoints and revoke sessions within minutes of detection.

Does it work in hybrid environments?

Yes. Defender for Identity covers on-premises Active Directory, Azure AD, and hybrid configurations. It correlates signals across both environments in a single incident view.

Talk to a Microsoft security architect

EPC Group has deployed Defender for Identity across healthcare, federal, and Fortune 500 environments. Call (888) 381-9725 or request a 30-minute discovery call to discuss your threat protection requirements.

Related Resources

Continue exploring azure insights and services

Why Organizations Choose EPC Group

EPC Group is a Microsoft consulting firm based in Houston. We have experience in enterprise implementation since 1997 and over 10,000 successful deployments. Our expertise includes:

  • Power BI
  • Microsoft Fabric
  • SharePoint
  • Azure
  • Microsoft 365
  • Copilot

We serve organizations in various industries, including:

  • Fortune 500 companies
  • Federal agencies
  • Healthcare
  • Financial services
  • Government
  • Manufacturing
  • Energy
  • Education
  • Retail
  • Technology
  • Global enterprises

EPC Group stands out due to our governance-first approach. Each engagement starts with a security and compliance assessment.

Our team of senior architects has practical delivery experience in:

  • HIPAA
  • SOC 2
  • FedRAMP
  • CMMC environments

We focus on outcomes, not hours.

  • Fixed-fee accelerators with predictable pricing and defined deliverables
  • Senior architect engagement on every project, not rotating juniors
  • Compliance-native delivery for regulated industries
  • End-to-end coverage from strategy through 24/7 managed services
  • 11,000+ enterprise engagements refined into repeatable, risk-controlled patterns

Call (888) 381-9725 or email contact@epcgroup.net for a free assessment.

Azure Architecture: 2026 Considerations for How To Block Malware Attacks With Azure Advanced Threat Protection

FinOps in Azure 2026 is essential for any significant scale. Azure Reservations, which include 1-year or 3-year commitments, provide savings of 30-72% on predictable VM workloads. Azure Savings Plans offer discounts that apply to compute portability across instance families. Additionally, the Azure Hybrid Benefit allows you to use your existing Windows Server and SQL Server licenses, reducing compute costs by another 40-49%.

Typical Azure cost-optimization efforts can recover 25-40% of annual Azure spending within 90 days.

Azure Confidential Computing (DCadsv5/ECasv5 series) is the key solution for privileged data in 2026. It uses AMD SEV-SNP and Intel TDX enclaves to protect data in use. This protection complements encryption for data at rest and in transit.

This technology allows regulated workloads to operate on shared Azure infrastructure. Examples include:

With cryptographic attestation, the host operator cannot inspect the data.

Decision factors EPC Group evaluates

EPC Group covers this topic across the relevant engagement portfolio. Reach the firm at contact@epcgroup.net for a 30-minute architect conversation.

AI assistant — not human