Activate the Microsoft Defender for Identity sensor v3.x
In brief
The documentation now covers eligible domain controllers and non-domain-controller AD FS, AD CS, and Microsoft Entra Connect servers. Activation on the latter servers is in preview and currently requires manual activation; automatic activation and migration aren't supported.
What Defender admins need to know
Administrators managing these servers should review eligibility and use manual activation where applicable. No required action or deadline is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Activate the Microsoft Defender for Identity sensor v3.x on a domain controller
For complete protection of your on-premises deployment, activate the Defender for Identity sensor v3.x on all applicableeligible servers. OnboardSupported server types include domain controllers running Windows Server 2019 or later, including domain controllers that also runand AD FS, AD CS, or Microsoft Entra Connect roles. For domain controllers running older operating systems, or for AD FS, AD CS, and Microsoft Entra Connect servers that aren't domain controllers,controllers. Eligible servers must meet the sensor v3.x prerequisites, including Windows Server 2019 or later. For supported servers running older operating systems, deploy the Defender for Identity sensor v2.x instead.
Prerequisites
See Microsoft Defender for Identity sensor v3.x prerequisitesSee Microsoft Defender for Identity sensor v3.x prerequisitesPrerequisites
all system requirements and Sensor version limitations for supported scenarios before proceeding with activating the Defender for Identity sensor v3.x on eligible domain controllers.servers.
Review the Activation page
The Activation page displays all servers from your device inventory. Defender for Identity detects all of your servers and their configuration. Each server's activation state lets you knowshows whether the server is eligible for the v3.x sensor and what you needaction to do to onboard that domain controller to Defender for Identity.take.
You can choose to activate eligible domain controllers either automatically, whereautomatically or manually. AD FS, AD CS, and Microsoft Entra Connect servers that aren't domain controllers currently support manual activation only. Automatic activation and migration aren't currently supported for these servers and will be added in a future update.
To turn on automatic activation for eligible domain controllers, use the Automatic sensor v3.x activation toggle on the Advanced features page (Settings > Identities > Advanced features). Automatic activation applies only to eligible servers onboarded to Defender for Identity activates them as soon as theyEndpoint. It doesn're discovered,t apply to onboarding without Defender for Endpoint deployment or manually, by selecting specific domain controllersto migration from the list of eligible servers.sensor v2.x to sensor v3.x.
| Activation |
Next steps |
|---|---|
| Deploy the Defender for Identity sensor v2.x from the Sensors page. | |
| OS upgrade is required | This |
| Activate sensor v3.x | The server is already onboarded to Defender for Endpoint. Activate the v3.x sensor. |
- If you have a Defender for Endpoint deployment, simply activate the sensor.
- If the domain controller is not onboarded to Defender for Endpoint, onboard the domain controller by configuring Defender for Endpoint streamlined URLs, and then downloading and running the onboarding package.-->
Activate the Defender for Identity sensor v3.x
Perform the following steps to activate the Defender for Identity sensor v3.x on a domain controller:an eligible server:
In the Microsoft Defender portal, go to System > Settings > Identities > Activation.
Select the
domain controllereligible server where you want to activate Defender for Identity, and select Activate. Confirm your selection when prompted.When v3.x sensor activation for the selected
domain controllerserver is complete, a green success banner appears. In thegreen successbanner, select Click here to see the onboarded servers.Selecting this link takes you to theThe Sensorspage,page opens, where you can checkyourthe sensor's health.:::image type="content" source="media/activated-sensor.png" alt-text="Screenshot that shows successful activation." lightbox="media/activated-sensor.png":::
Confirm sensor activation
To confirm that the v3.x sensor is working:
- In the Microsoft Defender portal, go to System > Settings > Identities > Sensors.
- Check that the activated
domain controllerserver is listed.
Related content
@@ -1,35 +1,40 @@ ----title: Activate the Defender for Identity sensor v3.x on a domain controller -description: Learn about how to activate the Microsoft Defender for Identity sensor on domain controllers.-ms.date: 06/15/2026+title: Activate the Microsoft Defender for Identity sensor v3.x+description: Learn how to activate the Microsoft Defender for Identity sensor v3.x on eligible identity-role servers.+ms.date: 08/31/2026 ms.topic: how-to ms.reviewer: rlitinsky-ms.custom: sfi-image-nochange, msecd-doc-authoring-1014+ms.custom: sfi-image-nochange, msecd-doc-authoring-1015 ai-usage: ai-assisted --- -# Activate the Defender for Identity sensor v3.x on a domain controller+# Activate the Microsoft Defender for Identity sensor v3.x -For complete protection of your on-premises deployment, activate the Defender for Identity sensor on all applicable servers. Onboard domain controllers running Windows Server 2019 or later, including domain controllers that also run AD FS, AD CS, or Microsoft Entra Connect roles. For domain controllers running older operating systems, or for AD FS, AD CS, and Microsoft Entra Connect servers that aren't domain controllers, [deploy the Defender for Identity sensor v2.x](install-sensor.md) instead.+For complete protection of your on-premises deployment, activate the Defender for Identity sensor v3.x on all eligible servers. Supported server types include domain controllers and AD FS, AD CS, or Microsoft Entra Connect servers that aren't domain controllers. Eligible servers must meet the sensor v3.x prerequisites, including Windows Server 2019 or later. For supported servers running older operating systems, [deploy the Defender for Identity sensor v2.x](install-sensor.md) instead.++> [!NOTE]+> Activating the Defender for Identity sensor v3.x on AD FS, AD CS, and Microsoft Entra Connect servers that aren't domain controllers is in preview. ## Prerequisites -See [Microsoft Defender for Identity sensor v3.x prerequisites](deploy-sensor-v3.md) for all system requirements and [sensor version limitations](deploy-sensor-v3.md#sensor-version-limitations) before proceeding with activating the Defender for Identity sensor on eligible domain controllers.+See [Microsoft Defender for Identity sensor v3.x prerequisites](deploy-sensor-v3.md) for system requirements and [Sensor version limitations](deploy-sensor-v3.md#sensor-version-limitations) for supported scenarios before activating the Defender for Identity sensor v3.x on eligible servers. <a name="the-activation-page"></a> ## Review the Activation page -The **Activation** page displays all servers from your device inventory. Defender for Identity detects all of your servers and their configuration. Each server's activation state lets you know what you need to do to onboard that domain controller to Defender for Identity.+The **Activation** page displays all servers from your device inventory. Defender for Identity detects your servers and their configuration. Each server's activation state shows whether the server is eligible for the v3.x sensor and what action to take. -You can choose to activate eligible domain controllers either automatically, where Defender for Identity activates them as soon as they're discovered, or manually, by selecting specific domain controllers from the list of eligible servers.+You can activate eligible domain controllers automatically or manually. AD FS, AD CS, and Microsoft Entra Connect servers that aren't domain controllers currently support manual activation only. Automatic activation and migration aren't currently supported for these servers and will be added in a future update.++To turn on automatic activation for eligible domain controllers, use the **Automatic sensor v3.x activation** toggle on the **Advanced features** page (**Settings** > **Identities** > **Advanced features**). Automatic activation applies only to eligible servers onboarded to Defender for Endpoint. It doesn't apply to onboarding without Defender for Endpoint deployment or to migration from sensor v2.x to sensor v3.x. -[](media/activate-sensor/blog.png#lightbox)+[](media/activate-sensor/blog.png#lightbox) -|Activation State |Next steps |+|Activation state |Next steps | |---------|---------|-|Activate new sensor |The domain controller is already onboarded to Defender for Endpoint. [Activate the sensor](#activate-the-defender-for-identity-sensor).|-|Install classic sensor|[Deploy the classic Defender for Identity sensor](install-sensor.md) from the **Sensors page**.|-|OS upgrade is required |This domain controller is running an unsupported operating system version for the new sensor. Upgrade the OS version to the latest version. |+|Install sensor v2.x|[Deploy the Defender for Identity sensor v2.x](install-sensor.md) from the **Sensors page**.|+|OS upgrade is required |This server is running an unsupported operating system version for the v3.x sensor. Upgrade the server to a supported version. |+|Activate sensor v3.x |The server is already onboarded to Defender for Endpoint. [Activate the v3.x sensor](#activate-the-defender-for-identity-sensor).| <!--|Download onboarding package |[Onboard the domain controller to Defender for Endpoint](#onboard-the-domain-controller).|--> @@ -38,17 +43,18 @@ The process for activating the sensor depends on your configuration. - If you have a Defender for Endpoint deployment, simply [activate the sensor](#activate-the-defender-for-identity-sensor). - If the domain controller is not onboarded to Defender for Endpoint, [onboard the domain controller](#onboard-the-domain-controller) by configuring Defender for Endpoint streamlined URLs, and then downloading and running the onboarding package.--> -## Activate the Defender for Identity sensor+<a name="activate-the-defender-for-identity-sensor"></a>+## Activate the Defender for Identity sensor v3.x -Perform the following steps to activate the Defender for Identity sensor on a domain controller:+Perform the following steps to activate the Defender for Identity sensor v3.x on an eligible server: 1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **System** > **Settings** > **Identities** > **Activation**.-1. Select the domain controller where you want to activate Defender for Identity, and select **Activate**. Confirm your selection when prompted. +1. Select the eligible server where you want to activate Defender for Identity, and select **Activate**. Confirm your selection when prompted. [](media/activate-sensor/image.png#lightbox) -1. When sensor activation for the selected domain controller is complete, a green success banner appears. In the green success banner, select **Click here to see the onboarded servers**. Selecting this link takes you to the **Sensors** page, where you can check your sensor health.+1. When v3.x sensor activation for the selected server is complete, a green success banner appears. In the banner, select **Click here to see the onboarded servers**. The **Sensors** page opens, where you can check the sensor's health. :::image type="content" source="media/activated-sensor.png" alt-text="Screenshot that shows successful activation." lightbox="media/activated-sensor.png"::: @@ -72,13 +78,15 @@ If the domain controller has not been onboarded to Defender for Endpoint for Ser ## Confirm sensor activation -To confirm the sensor is working: +To confirm that the v3.x sensor is working: 1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **System** > **Settings** > **Identities** > **Sensors**.-1. Check that the activated domain controller is listed. +1. Check that the activated server is listed. > [!NOTE]-> The first time you activate the Defender for Identity sensor on your domain controller, it might take up to an hour for the first sensor to show as **Running** on the **Sensors** page. Subsequent activations are shown within five minutes. The activation doesn't require a restart/reboot. +> The first Defender for Identity sensor v3.x activation in your environment might take up to an hour to show as **Running** on the **Sensors** page. Subsequent activations appear within five minutes. Activation doesn't require a restart.++<a name="next-steps"></a>+## Related content -## Next steps-- [Manage and update Microsoft Defender for Identity sensors](../sensor-settings.md).+- [Manage and update Microsoft Defender for Identity sensors](../sensor-settings.md) 

