Microsoft Defender for Identity
Architecture and deployment

Deploy the Defender for Identity sensor v3.x

In brief

The documentation now covers v3.x sensors on non-domain-controller AD FS, AD CS, and Microsoft Entra Connect servers. Activation there is in preview, requires manual activation, and does not support automatic activation or migration.

What Defender admins need to know

If deploying only to these servers, install at least one v3.x sensor on a domain controller. Review the updated activation and auditing requirements.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Deploy the Defender for Identity sensor v3.x

Deploy the Defender for Identity sensor v3.x on supportedeligible domain controllers and AD FS, AD CS, or Microsoft Entra Connect servers that aren't domain controllers. Complete the prerequisite checks before activation, then configure auditing and identity settings afterward.settings.

Before you activate

Supported server types

The v3.x sensor supports domain controllers, includingcontrollers. It also supports servers that aren't domain controllers with theseand run the following identity roles:

  • Active Directory Federation Services (AD FS)
  • Active Directory Certificate Services (AD CS)
  • Microsoft Entra Connect

Use the Defender for Identity sensor v2.x for servers that aren't domain controllers and run AD FS, AD CS, or Microsoft Entra Connect.

Licensing requirements

Licensing requirements

The Defender for Identity sensor v3.x limits CPU utilization to 30% and memory usage to 1.5 GB. However, if another service uses substantial system resources, the server might still experience performance strain. If the sensor reaches the CPU limit, it throttles some event processing. If the sensor reaches the memory limit, the sensor service might restart.

Refer to the Defender for Identity Capacity Planning documentation to determine whether your domain controller servers have enough resources for a Microsoft Defender for Identity sensor.

Service account requirements

DSA and gMSA health alerts in environments with both v2.x and v3.x sensors

If your workspace still has a Directory Service Account (DSA) or group Managed Service Account (gMSA) configured because v2.x sensors on AD FS, AD CS, or Entra Connect servers still require it, DSA and gMSA credentials continue to be validated on all sensors in the workspace, including v3.x sensors. If DSA or gMSA credential validation fails, the Directory services user credentials are incorrect health alert appears. Workspace-level validation of DSA and gMSA credentials on all sensors is by design. Defender for Identity validates DSA and gMSA credentials at the workspace level for all sensors as long as those accounts exist, regardless of whether individual sensors use them for auditing or response actions.

Defender for Identity v3.x sensors ignore the DSA and gMSA for auditing and response actions, but they're still included in workspace-level credential validation. To stop receiving this health alert on v3.x sensors, remove the workspace-level DSA or gMSA after all sensors are fully migrated to v3.x and no v2.x sensors require it.

Test your prerequisites

After confirming all prerequisites, activate the sensor from the Microsoft Defender portal.

After you activateConfigure settings after activation

Complete these configuration steps after the sensor is activated and running.

Configure Windows event auditing

Defender for Identity relies on Windows event logs for many detections. For v3.x sensors on domain controllers,sensors, enable automatic auditing, which handles all auditing settings without manual configuration.

If automatic auditing isn't available or you opted out, configure auditing manually or configure Windows event collection using PowerShell.

Configure RPC auditing

Use the following recommended settings to help ensure stable sensor performance:

  • Set the Power Option of the machine running the Defender for Identity sensor to High Performance.
  • Synchronize the time on servers and domain controllers where you install the sensor to within five minutes of each other.

Next step