Contoso's SOC team discovers that a compromised admin account was used to create a new Global Admin and disable audit logging. Which Microsoft 365 Defender feature would have alerted the team to this lateral movement in near real-time?
-
A
Microsoft Secure Score recommendations
-
B
Identity Protection risky sign-in alerts
-
C
Microsoft Sentinel UEBA anomaly detection
-
D
Defender for Cloud Apps activity policies