Microsoft Defender for Identity
Identity protection

Configure Windows event forwarding | Microsoft Defender for Identity

In brief

Updated the page metadata, corrected the Step 3 heading level, and clarified wording for selecting a subscription and verifying forwarded events.

What Defender admins need to know

No administrator action is required; the documented steps are clearer.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

gpupdate /force
```

Step 3: Create and select a subscription on your sensor

This procedure describes how to create a subscription for use with Defender for Identity and then select itthe subscription from your standalone sensor.

  1. Open an elevated command prompt and enter

    1. Return to the Event Viewer console. Right-click the created subscription and select Runtime Status to see if there are any issues with the status.

    2. After a few minutes, check to seeverify that the forwarded events you set to be forwarded is showing upappear in the Forwarded Events log on the Defender for Identity standalone sensor.

For more information, see: Configure the computers to forward and collect events.