Microsoft Defender for Identity
Identity protection

Activate the Microsoft Defender for Identity sensor v3.x

In brief

The documentation now covers eligible domain controllers and non-domain-controller AD FS, AD CS, and Microsoft Entra Connect servers. Activation on the latter servers is in preview and currently requires manual activation; automatic activation and migration aren't supported.

What Defender admins need to know

Administrators managing these servers should review eligibility and use manual activation where applicable. No required action or deadline is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Activate the Microsoft Defender for Identity sensor v3.x on a domain controller

For complete protection of your on-premises deployment, activate the Defender for Identity sensor v3.x on all applicableeligible servers. OnboardSupported server types include domain controllers running Windows Server 2019 or later, including domain controllers that also runand AD FS, AD CS, or Microsoft Entra Connect roles. For domain controllers running older operating systems, or for AD FS, AD CS, and Microsoft Entra Connect servers that aren't domain controllers,controllers. Eligible servers must meet the sensor v3.x prerequisites, including Windows Server 2019 or later. For supported servers running older operating systems, deploy the Defender for Identity sensor v2.x instead.

Prerequisites

See Microsoft Defender for Identity sensor v3.x prerequisites

Prerequisites

See Microsoft Defender for Identity sensor v3.x prerequisites for all system requirements and Sensor version limitations for supported scenarios before proceeding with activating the Defender for Identity sensor v3.x on eligible domain controllers.servers.

Review the Activation page

The Activation page displays all servers from your device inventory. Defender for Identity detects all of your servers and their configuration. Each server's activation state lets you knowshows whether the server is eligible for the v3.x sensor and what you needaction to do to onboard that domain controller to Defender for Identity.take.

You can choose to activate eligible domain controllers either automatically, whereautomatically or manually. AD FS, AD CS, and Microsoft Entra Connect servers that aren't domain controllers currently support manual activation only. Automatic activation and migration aren't currently supported for these servers and will be added in a future update.

To turn on automatic activation for eligible domain controllers, use the Automatic sensor v3.x activation toggle on the Advanced features page (Settings > Identities > Advanced features). Automatic activation applies only to eligible servers onboarded to Defender for Identity activates them as soon as theyEndpoint. It doesn're discovered,t apply to onboarding without Defender for Endpoint deployment or manually, by selecting specific domain controllersto migration from the list of eligible servers.sensor v2.x to sensor v3.x.

Screenshot of the Microsoft Defender portal Activation page listing servers and their activation states.

Activation Statestate Next steps
Activate newInstall sensorThe domain controller is already onboarded to Defender for Endpoint. Activate the sensor.
Install classic sensor v2.x Deploy the Defender for Identity sensor v2.x from the Sensors page.
OS upgrade is required This domain controllerserver is running an unsupported operating system version for the newv3.x sensor. Upgrade the OS versionserver to the latesta supported version.
Activate sensor v3.xThe server is already onboarded to Defender for Endpoint. Activate the v3.x sensor.
  • If you have a Defender for Endpoint deployment, simply activate the sensor.
  • If the domain controller is not onboarded to Defender for Endpoint, onboard the domain controller by configuring Defender for Endpoint streamlined URLs, and then downloading and running the onboarding package.-->

Activate the Defender for Identity sensor v3.x

Perform the following steps to activate the Defender for Identity sensor v3.x on a domain controller:an eligible server:

  1. In the Microsoft Defender portal, go to System > Settings > Identities > Activation.

  2. Select the domain controllereligible server where you want to activate Defender for Identity, and select Activate. Confirm your selection when prompted.

    Screenshot that shows how to activate an new server.

  3. When v3.x sensor activation for the selected domain controllerserver is complete, a green success banner appears. In the green success banner, select Click here to see the onboarded servers. Selecting this link takes you to theThe Sensors page,page opens, where you can check yourthe sensor's health.

    :::image type="content" source="media/activated-sensor.png" alt-text="Screenshot that shows successful activation." lightbox="media/activated-sensor.png":::

Confirm sensor activation

To confirm that the v3.x sensor is working:

  1. In the Microsoft Defender portal, go to System > Settings > Identities > Sensors.
  2. Check that the activated domain controllerserver is listed.

.

Related content