Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Advanced Threat Analytics (ATA) was an on-premises platform that monitored enterprise Active Directory environments for identity attacks and suspicious behavior. It analyzed network traffic and Windows event data, then used behavioral analytics to flag activity such as pass-the-hash, reconnaissance, brute-force attempts, and malicious directory replication. ATA is now unsupported; Microsoft recommends replacing it with Microsoft Defender for Identity.

What did Microsoft ATA do?

ATA collected signals from an organization’s Active Directory environment and correlated them to detect activity associated with compromised accounts, malicious insiders, and other identity threats. It combined network protocol analysis, Windows event collection, and behavioral profiling: by learning normal activity for users and other entities, it could flag deviations for investigation.

Documented data sources included domain controllers, DNS, port-mirrored network traffic, Lightweight Gateways, Windows Event Forwarding, and SIEM integrations. The combination helped ATA add identity context to network activity rather than treating each connection or event in isolation.

Threats and behaviors it could alert on

ATA’s documented alert families included:

  • Identity theft and abnormal user behavior, including activity associated with Pass-the-Hash and Pass-the-Ticket.
  • Kerberos attacks, including Golden Ticket activity, and encryption downgrades that could indicate Golden Ticket, overpass-the-hash, or skeleton-key activity.
  • Account enumeration, DNS reconnaissance, and unusual protocol implementation.
  • LDAP simple-bind brute force and suspicious authentication failures.
  • Malicious replication of directory services.
  • Honeytoken activity, remote execution attempts, and abnormal changes to sensitive groups.

These are examples from ATA’s event reference, not a guarantee that every deployment would detect every instance. Alerting depended on the available telemetry and the system’s analysis of the environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How was ATA built and deployed?

ATA used a central ATA Center and one or more components to collect and analyze signals. The Center provided centralized storage, correlation, and the management console. ATA Gateways ran on standalone servers to capture and analyze network traffic; Lightweight Gateways could run directly on domain controllers.

Organizations could provide network traffic through port mirroring and supplement it with event data, including Windows Event Forwarding. Deployment therefore involved on-premises infrastructure and access to relevant network and identity telemetry, rather than installing a single desktop application.

Is Microsoft ATA discontinued and still supported?

Yes: ATA has reached end of life and is no longer supported. Microsoft says mainstream support ended January 12, 2021, and extended support ended January 13, 2026. The product receives no further updates, including security updates. Its final release was ATA 1.9 Update 3.

For lifecycle details, see Microsoft’s ATA migration guidance and its ATA FAQ.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What replaced ATA?

Microsoft recommends Microsoft Defender for Identity. Unlike ATA’s standalone, on-premises architecture, Defender for Identity is a cloud-based security solution that uses signals from on-premises Active Directory. Microsoft describes it as frequently updated, with broader integrations and identity data that contributes to Microsoft Defender XDR. Its capabilities also include newer telemetry, multi-forest support, and posture assessments.

Area ATA Defender for Identity
Deployment model Standalone, on-premises Center and Gateways Cloud-based service using on-premises Active Directory signals
Lifecycle Unsupported; no further updates, including security updates Actively maintained service
Integration and coverage Network and Windows event telemetry with behavioral analytics Newer telemetry, multi-forest support, posture assessments, and Microsoft security-portfolio integrations
Existing ATA data Stored in ATA Not automatically migrated

For Microsoft’s product descriptions and migration context, consult the migration overview and FAQ.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do you migrate from ATA to Defender for Identity?

Microsoft’s guidance treats migration as a replacement deployment, not an in-place conversion of ATA into Defender for Identity. ATA data is not migrated automatically, so plan for investigation continuity before retiring the old system.

  1. Plan the replacement deployment. Follow Microsoft’s ATA migration overview to prepare and deploy Defender for Identity for your environment.
  2. Review open ATA investigations. Identify alerts that still require investigation, remediation, or recordkeeping.
  3. Retain ATA records as needed. Keep the ATA Data Center and alerts required for ongoing investigations until the relevant alerts are closed or remediated, as described in Microsoft’s migration prerequisites.
  4. Move operations to Defender for Identity. Use the replacement service for ongoing identity-threat monitoring; do not assume historical ATA data or alert history will appear in it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.