Most attacks on rely on an identical local Administrator password across all workstations, on credentials stored in memory, and on lack of monitoring. The following three defenses address exactly that.
- Windows — a unique, rotating local password on every computer, stored in . Breaks Lateral Movement.
- — isolates LSASS using virtualization, so a Hash can't be extracted from it.
- Protected Users + Tiering — prevents admin credentials from being stored on regular workstations.
- Microsoft Defender for Identity (MDI) — a sensor on the DC that detects , , and suspicious scans.