Agent skill

Defender For Identity

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors.

MITAuto-check passedSecurity

Install Defender For Identity

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-identity -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills defender-for-identity --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/defender-for-identity .claude/skills/defender-for-identity && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
defender-for-identity
GitHub stars
175
Token cost
~2k tokens
SKILL.md length
938 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors.

  • Works in 7 steps: Map identity infrastructure — Inventory… → Confirm prerequisites before deploy —… → Use a gMSA for the Directory Service… → …
  • The goal is cloud identity protection in Entra ID (use entra-id-protection)
  • SKILL.md covers When to use, Map the attack to a detection…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Defender For Identity is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors. Covers sensor placement, prerequisites, posture assessments, and lateral-movement detection. WHEN: Defender for Identity, MDI, MDI sensors, detect lateral movement, on-prem AD threat detection, identity security posture, AD CS monitoring, ADCS abuse, domain controller sensor, detect Kerberoasting, DCSync, Golden Ticket, identity ITDR, honeytoken…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Red teaming and adversary simulation. It works with Microsoft Defender and Microsoft Entra ID. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • The goal is cloud identity protection in Entra ID (use entra-id-protection)
  • Correlating cross-workload incidents (use defender-xdr)

Example prompts

  • “/defender-for-identity”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Map identity infrastructure — Inventory every domain controller (including RODCs),
  2. Confirm prerequisites before deploy — Each sensor host needs outbound HTTPS to the MDI
  3. Use a gMSA for the Directory Service Account — Group Managed Service Accounts rotate
  4. Deploy sensors in waves — DC sensors first (highest signal), then AD CS, AD FS, Entra
  5. Tune alerts, then act on posture — Acknowledge benign first-week alerts (admin tooling
  6. Deploy honeytokens — Plant 1-2 fake high-privilege accounts (e.g. svc-legacy-backup)
  7. Correlate in Defender XDR — MDI alerts auto-correlate with MDE and Entra ID Protection

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Defender For Identity loads about 2k tokens when it runs. Until then it costs about 188 tokens; SKILL.md has 938 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~188
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 938 words, ~2,004 tokens.

Download SKILL.mdSave it as .claude/skills/defender-for-identity/SKILL.md (or your agent's skills folder).
name
defender-for-identity
description
Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors. Covers sensor placement, prerequisites, posture assessments, and lateral-movement detection. WHEN: Defender for Identity, MDI, MDI sensors, detect lateral movement, on-prem AD threat detection, identity security posture, AD CS monitoring, ADCS abuse, domain controller sensor, detect Kerberoasting, DCSync, Golden Ticket, identity ITDR, honeytoken, gMSA Directory Service Account, suspicious LDAP, ESC1 ESC8. DO NOT USE when the goal is cloud identity protection in Entra ID (use entra-id-protection) or correlating cross-workload incidents (use defender-xdr).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Defender for Identity

Microsoft Defender for Identity (MDI) is a cloud-based identity threat detection and response (ITDR) solution. Lightweight sensors on domain controllers and other identity infrastructure parse network traffic, ETW events, and AD object reads to detect reconnaissance, credential theft, lateral movement, and domain dominance. Signals correlate into Defender XDR incidents.

When to use

Detecting identity-based attacks against on-premises Active Directory, AD CS, AD FS, and Entra Connect — and surfacing identity posture issues (legacy protocols, unsecure accounts, risky delegations) that lead to those attacks.

Do not use this skill for cloud-only Entra ID risk detection — that is Entra ID Protection (entra-id-protection). MDI sees on-prem and hybrid identity infrastructure.

Map the attack to a detection source

Pick the row that matches the attacker behaviour to confirm MDI is the right control and which sensor surface produces the signal.

If the attacker is...MDI detection familySensor surface
Enumerating users, groups, SPNsReconnaissanceDC sensor (LDAP, SAMR)
Cracking service-account TGS tickets offlineKerberoastingDC sensor (Kerberos)
Replicating directory secrets (DCSync)Domain dominanceDC sensor (DRSUAPI RPC)
Forging Kerberos ticketsGolden / Silver TicketDC sensor (Kerberos anomalies)
Abusing AD CS misconfig (ESC1–ESC8)Certificate-based privilege escalationAD CS sensor
Hijacking the AD FS sign-in flowToken / SAML forgeryAD FS sensor
Stealing Entra Connect sync account credsHybrid identity compromiseEntra Connect sensor
Probing risky configurations (legacy SMB, weak SPNs)Identity Security Posture (ISPM)All sensors + cloud assessments

Rule of thumb: if the attacker touches an on-prem identity service for any step, MDI should see it. A gap in any sensor (one un-instrumented DC, AD CS, or AD FS) is a blind spot for the whole kill chain.

Approach

  1. Map identity infrastructure — Inventory every domain controller (including RODCs), every AD CS Enterprise CA, every AD FS server, and every Entra Connect / Cloud Sync host. This list is the sensor target list — gaps here become attack paths later. Verify: Get-ADDomainController -Filter * count equals the deployed sensor count in the MDI portal under Settings → Sensors.

  2. Confirm prerequisites before deploy — Each sensor host needs outbound HTTPS to the MDI cloud service, the MDI sensor MSI, a Directory Service Account (DSA), and (on DCs) the Advanced Audit Policy settings + Object Access SACLs that MDI requires. Verify: run the MDI sizing tool and confirm CPU/RAM headroom; sensors should add < 10% sustained CPU on a DC.

  3. Use a gMSA for the Directory Service Account — Group Managed Service Accounts rotate passwords automatically and remove the worst class of credential exposure. Never use a plaintext-password service account. Verify: Get-ADServiceAccount mdi-gmsa$ -Properties PrincipalsAllowedToRetrieveManagedPassword returns the sensor host group, nothing wider.

  4. Deploy sensors in waves — DC sensors first (highest signal), then AD CS, AD FS, Entra Connect. Wait 24 hours between waves to baseline traffic and avoid drowning the SOC in first-time-seen activity alerts.

  5. Tune alerts, then act on posture — Acknowledge benign first-week alerts (admin tooling noise), then work the Identity Security Posture Assessments (Secure Score panel). Posture issues (e.g. Unsecure account attributes, Legacy protocols, Dormant accounts) are the weak links attackers exploit before alerts ever fire. Verify: posture score baseline captured at week 1; track delta monthly, not daily.

  6. Deploy honeytokens — Plant 1-2 fake high-privilege accounts (e.g. svc-legacy-backup) that no human should ever touch. Any auth attempt is high-confidence malicious.

  7. Correlate in Defender XDR — MDI alerts auto-correlate with MDE and Entra ID Protection into a single XDR incident. Investigate from the incident, not the standalone alert.

Show full SKILL.md (366 more words)Show less

Guardrails

  • Every DC must have a sensor. A single un-instrumented DC is the lateral-movement landing pad attackers will find. RODCs included.
  • Sensor on AD CS is not optional in 2026. AD CS abuse (ESC1-ESC8) is the most common privilege-escalation path in current incident response cases - without the AD CS sensor you see the result (Domain Admin) but not the cause.
  • Use a gMSA for the DSA. Never a regular service account with a static password - it becomes the next Kerberoasting target.
  • Tune, don't suppress. Disabling an alert class to silence noise removes the detection. Suppress per-source instead and review monthly.
  • Honeytokens require care. Place them where reconnaissance tools see them (group memberships, descriptions) but document them so the SOC doesn't waste cycles investigating legitimate test triggers.

Common anti-patterns

  • "We'll cover the most important DCs first" - Attackers pick the un-instrumented one. All DCs or none.
  • "We use a domain admin account as the DSA for simplicity" - Hands attackers a domain admin if the sensor host is compromised. Always use gMSA with least privilege.
  • "Posture alerts are not real alerts so we ignore them" - Posture issues are pre-attack signals. Working them down is cheaper than responding to the incident they enable.
  • "We didn't deploy the AD CS sensor - we don't issue many certs" - Issuance volume is irrelevant. ESC1/ESC8 misconfigs exist in stock AD CS installs and need monitoring.
  • "MDI alerts go straight to the legacy SIEM, we don't use Defender XDR" - Loses cross- workload correlation. Even if SIEM is primary, keep XDR for the attack graph.

Example prompts

  • Plan Defender for Identity sensor coverage across DCs, AD CS, AD FS, and Entra Connect.
  • Which Defender for Identity detections cover the Kerberoasting kill chain?
  • How do I configure a gMSA Directory Service Account for MDI?
  • Which Identity Security Posture assessments should I fix first?
  • Show me how to deploy a honeytoken account in MDI.
  • Why am I seeing high CPU on a DC after installing the MDI sensor - how do I size it?

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/defender-for-identity of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Defender For Identity next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Defender For Identity compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Defender For Identity this skillvinayaklatthe/microsoft-security-skills175—~2kAutomated safety check: PassMIT
App Registration PostureSCStelz/security-investigator249—~21kAutomated safety check: PassMIT
Building Identity Federation With Saml Azure Admukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Detecting Azure Service Principal Abusemukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Detecting Service Account Abusemukul975/Anthropic-Cybersecurity-Skills34k—~904Automated safety check: PassApache-2.0
Conducting Internal Reconnaissance With Bloodhound Cemukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0

Similar skills

  • App Registration Posture

    SCStelz/security-investigator

    Audit Entra ID app registration and service principal security posture.

    249 GitHub stars~21k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Building Identity Federation With Saml Azure Ad

    mukul975/Anthropic-Cybersecurity-Skills

    Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Azure Service Principal Abuse

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Service Account Abuse

    mukul975/Anthropic-Cybersecurity-Skills

    Detect abuse of service accounts by hunting for anomalous interactive logons, privilege escalation, and lateral movement using EDR/SIEM telemetry (CrowdStrike Falcon, Microsoft Defender, Splunk…

    34k GitHub stars~904 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Conducting Internal Reconnaissance With Bloodhound Ce

    mukul975/Anthropic-Cybersecurity-Skills

    Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Azure Lateral Movement

    mukul975/Anthropic-Cybersecurity-Skills

    Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation…

    34k GitHub stars~808 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Defender For Identity

What does Defender For Identity do?

Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors. Defender For Identity is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors.

When should I use Defender For Identity?

Defender For Identity fits situations like: the goal is cloud identity protection in Entra ID (use entra-id-protection); correlating cross-workload incidents (use defender-xdr).

How do I install Defender For Identity in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-identity -a claude-code`. Or copy the skill folder (skills/defender-for-identity in vinayaklatthe/microsoft-security-skills) into .claude/skills/defender-for-identity in your project. Claude Code loads it when a task matches its description.

How do I install Defender For Identity in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-identity -a codex`. Or copy the skill folder (skills/defender-for-identity in vinayaklatthe/microsoft-security-skills) into .agents/skills/defender-for-identity in your project. Codex loads it when a task matches its description.

Can I use Defender For Identity in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-identity -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defender-for-identity, .gemini/skills/defender-for-identity, .github/skills/defender-for-identity and .opencode/skills/defender-for-identity in your project.

What does Defender For Identity need to run?

SKILL.md names no scripts, command-line tools or credentials: Defender For Identity is instructions for the agent only.

Does Defender For Identity access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Defender For Identity safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Defender For Identity use?

Defender For Identity is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Defender For Identity use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Defender For Identity?

Skills that share tags, products or a category with Defender For Identity: App Registration Posture (SCStelz/security-investigator, 249 stars), Building Identity Federation With Saml Azure Ad (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Azure Service Principal Abuse (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting Service Account Abuse (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Defender For Identity?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.