Quest Identity Defense serves as our primary tool to monitor privileged and tier two and tier one level identities and identify risk configurations, investigate suspicious changes, and improve our identity security posture. We use it as a Privileged Access Management tool. It gives our security team better visibility into what is happening inside the identity environment and helps us protect our Active Directory and Microsoft Entra ID environment. A specific example of how we used Quest Identity Defense for one of those tasks involved monitoring the privileged accounts and their access. We have just-in-time access for most of the critical user roles. Recently, when we noticed an unexpected change involving a privileged Active Directory account, we used Quest Identity Defense to investigate the activity and determine what changes had been made, which account performed the action, and whether the affected object was considered a critical or tier-zero asset. The centralized audit information made the investigation much quicker because we did not have to manually correlate activity across multiple sources. After confirming that the change was not part of an administrative activity, we escalated it to the L3 level of the team, and they remediated the threat.
Quest Identity Defense serves as our primary tool to monitor privileged and tier two and tier one level identities and identify risk configurations, investigate suspicious changes, and improve our identity security posture. We use it as a Privileged Access Management tool. It gives our security team better visibility into what is happening inside the identity environment and helps us protect our Active Directory and Microsoft Entra ID environment. A specific example of how we used Quest Identity Defense for one of those tasks involved monitoring the privileged accounts and their access. We have just-in-time access for most of the critical user roles. Recently, when we noticed an unexpected change involving a privileged Active Directory account, we used Quest Identity Defense to investigate the activity and determine what changes had been made, which account performed the action, and whether the affected object was considered a critical or tier-zero asset. The centralized audit information made the investigation much quicker because we did not have to manually correlate activity across multiple sources. After confirming that the change was not part of an administrative activity, we escalated it to the L3 level of the team, and they remediated the threat.