Microsoft Defender for Identity
Architecture and deployment

Deploy Microsoft Defender for Identity sensors

In brief

The deployment article now states that VPN integration and syslog notifications require the v2.x sensor on applicable domain controllers; these features aren't supported by v3.x.

What Defender admins need to know

Organizations using either capability must deploy the v2.x sensor on the relevant domain controllers.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Deploy Microsoft Defender for Identity sensors description: Learn how to deploy Microsoft Defender for Identity sensors on domain controllers and identity servers. Choose the right sensor version for your environment. ms.date: 08/07/15/2026 ms.topic: overview ms.custom: msecd-doc-authoring-106 ms.reviewer: rlitinsky

Defender for Identity supports mixed environments with both v3.x and v2.x sensors. For example, you might deploy v3.x on domain controllers running Windows Server 2019 or later, and v2.x on older domain controllers or on AD FS, AD CS, and Microsoft Entra Connect servers that aren't domain controllers. Both sensor versions work together and report to the same Defender for Identity workspace.

If your organization requires VPN integration or syslog notifications, use the v2.x sensor on the applicable domain controllers. These features aren't supported by the v3.x sensor.