Welcome to the Skills One O 1 knowledge base article. This article clarifies the distinctions and synergies between Change Auditor and Identity Defense, two products designed to address specific needs in identity and access management.
Identity Defense is a modern solution that builds upon previous offerings to tackle new use cases. It focuses on assessing the posture of Active Directory and identifying potential configuration issues. The product combines real-time monitoring of suspicious activities from human and non-human accounts, with a significant emphasis on protecting Tier 0 assets.
Key capabilities include:
Hybrid audit refers to the ability to natively audit Active Directory changes using LSAS hooking technology. This method listens to changes in memory, capturing events such as group changes and authentication events. Identity Defense offers a modern user interface and operates as a fully SaaS-based solution, eliminating the need for heavy on-premises servers.
Key features include:
Change Auditor is a long-standing auditing suite that provides real-time auditing for various platforms, including Active Directory, Exchange, SQL Server, and SharePoint. It captures critical data and offers proactive object protection to block unauthorized changes before they occur.
Key features include:
When deciding between the two products, consider the following:
Change Auditor and Identity Defense can coexist within the same environment. Organizations can leverage both products to meet specific needs, such as using Change Auditor for SQL and file server auditing while utilizing Identity Defense for Active Directory security.
Integration allows Identity Defense to pull audit data from Change Auditor, providing a comprehensive view of security and compliance across the organization.
For organizations looking to transition from Change Auditor to Identity Defense, a straightforward migration path exists for audit events. However, protection templates and specific configurations may need to be rebuilt in Identity Defense.
Data retention capabilities in Identity Defense provide a longer storage duration, alleviating the need for extensive archive databases.
Both Change Auditor and Identity Defense serve distinct yet complementary roles in identity and access management. Organizations can choose to implement one or both solutions based on their specific requirements, ensuring robust security and compliance across their environments.