Microsoft Defender for Identity
Identity protection

Configure sensors for AD FS, AD CS, and Microsoft Entra Connect | Microsoft Defender for Identity

In brief

The documentation now states that sensor v3.x can be used in preview on eligible AD FS, AD CS, and Microsoft Entra Connect servers running Windows Server 2019 or later. Sensor v2.x procedures remain documented for other applicable servers.

What Defender admins need to know

Administrators deploying sensors on these servers should review which sensor version applies to their Windows Server version.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure sensors for AD FS, AD CS, and Microsoft Entra Connect

Install and configure sensors on non-domain-controller servers

Install and configure the Defender for Identity sensor v2.x on Active Directory Federation Services (AD FS), Active Directory Certificate Services (AD CS), and Microsoft Entra Connect servers that aren't domain controllers. Before you begin, make sure you've completed the prerequisites listed latersensor installation prerequisites.