Monitors on-premises Active Directory signals to detect and investigate advanced identity-based threats — compromised accounts, lateral movement, and privilege escalation. Integrates with Microsoft Defender XDR to correlate identity risk with endpoint, email, and cloud app signals for a fuller picture of an attack.