20+ years with Microsoft 1,100+ organisations under management 131 countries invoiced locally 5 of 6 Solutions Partner designations 4-hour first response
IT Partner.Microsoft Solutions Partner +44 20 8142 5752 Talk to us Get a quote

HomeLicensingPrice list › Microsoft Defender for Identity

Security · Microsoft Defender for Identity

Watching Active Directory for the moves an attacker makes after the first foothold

Most breaches do not start with domain admin; they get there. Defender for Identity reads the signals on your domain controllers — reconnaissance, credential theft, lateral movement — and raises them in the same portal as the endpoint alerts.

What it is

Sensors on on-premises domain controllers and AD FS servers, behavioural analytics for identities, detection of reconnaissance, lateral movement and domain-dominance techniques, and investigation in the Defender portal.

Included in: Included in Microsoft 365 E5 and E5 Security. Irrelevant for a cloud-only tenant with no domain controllers.

Who needs it

  • Organisations that still run on-premises Active Directory alongside Microsoft 365.
  • Hybrid estates where a compromised workstation could reach the domain.
  • Security teams consolidating on Defender XDR.

Buying options, at Microsoft’s list price in EUR

Loading the price list…

List prices for the region chosen at the top of the page; the proposal you build here carries them. Annual-commitment lines are billed as shown; monthly lines can be reduced or cancelled at each renewal.

Asked before buying

We are cloud-only. Do we need it?

No. Without domain controllers there is nothing for it to watch; Entra ID P2's identity protection covers the cloud identities.

What does it need on-premises?

A sensor installed on each domain controller; no network changes.

Related