The appliance correlates Active Directory sign-in events with the addresses on your network, so a DNS event carries the user, the device and the subnet it came from — not just a resolver log line.
That correlation is read through MS-EVEN6, the same native Windows event interface Event Viewer uses. No agent is installed on a domain controller, no WinRM, no PowerShell remoting, nothing for your EDR to quarantine and nothing to re-approve at the next change board.
Identity travels with the query to the enforcement cloud, so a block decision and the report that follows name a person, and the long-term archive on your appliance keeps that record for as long as your retention policy says.
Where no identity mapping exists, an event still carries its network and site — network DNS alone cannot always name the individual user.