Microsoft Defender for Identity
Identity protection

Manage and Update Sensors

In brief

The documentation now includes domain controllers running AD FS, AD CS, or Microsoft Entra Connect, and states that v3.x sensors update through Windows Update. It also clarifies that the per-sensor Delayed update option applies only to v2.x sensors and expands migration-state descriptions.

What Defender admins need to know

Review migration eligibility and update scheduling for v3.x sensors; the v2.x Delayed update setting does not apply to v3.x.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Manage and update sensorsUpdate Sensors description: Learn how to view, manage, and update Microsoft Defender for Identity sensors in the Microsoft Defender portal, including sensor health, migration state, and delayed updates. ms.date: 07/15/09/01/2026 ms.topic: how-to ms.reviewer: rlitinsky ms.custom: msecd-doc-authoring-10141016

  • msecd-doc-authoring-106
  • sfi-image-nochange ai-usage: ai-assisted

Manage and update Microsoft Defender for Identity sensors

This article explains how to view, manage, and update Defender for Identity sensors in the Microsoft Defender portal. It covers sensor status and health monitoring, sensor property details, update processes for both v2.x and v3.x sensors, and proxy configuration. This guidance is intended for security administrators who manage Defender for Identity deployments. Some tasks described in this article require specific permissions or configuration prerequisites, such as proxy settings or sensor installation prerequisites, which are referenced in the relevant sections.

View sensor settings and status

  1. In the left sidebar, under Deployment, select On-premises.
  2. Select the Sensors tab.

:::image type="content" source="media/sensor-settings/sensor-settings-page.png" alt-text="Screenshot that shows the Sensors tab on the On-premises page in the Microsoft Defender portal." lightbox="media/sensor-settings/sensor-settings-page.png":::

The Sensors tab shows all Defender for Identity sensors deployed in your environment. From this tab you can: The Sensors tab shows the following columns. For columns with multiple possible values, see the tables below.

  • Sensor: The sensor's NetBIOS computer name.
  • Type: The sensor type. For possible values, see Sensor type.
  • Domain: The fully qualified domain name of the Active Directory domain where the sensor is installed.
  • Migration state: Indicates if sensors are eligible for migration from v2.x to v3.x. For possible values, see Sensor migration state.
  • Service status: The current state of the sensor service on the server. For possible values, see Sensor service status.
  • Sensor status: The current update and configuration state of the sensor software. For possible values, see Sensor status values.
  • Version: The sensor version installed.
  • Delayed update: Whether delayed updates are enabled or disabled. Delayed updates are supported by version 2 of the sensor. For more information, see Delayed update for sensor v2.x.
  • Health issues: The count of open health issues on the sensor.
  • Health status: The overall health of the sensor based on the highest severity open health issue. For possible values, see Sensor health status.
  • Created: The date the sensor was installed.

Sensor migration state

The migration state column shows ifindicates whether a Defender for Identity sensor running v2.x can be upgraded in place to v3.x. Possible values include Ready for migration, Not ready for migration, Migrating, Up to date, and Migration failed, as described in the sensor is eligible fortable later in this section. For more information about the migration process, see migration from v2.x to v3.x.

For a server to be eligible for migration, it must be:

  • A domain controller, including a domain controller without additional identity roles (ADthat also runs AD FS, AD CS, or Microsoft Entra Connect) running. Domain controllers with identity roles support v3.x for new deployments, but in-place migration isn't currently supported for these servers.Connect.
  • Running a Defender for Identity sensor v2.x.
  • Running Windows Server 2019 or later.
  • Includes the July 2026 or later cumulative update.

Defender for Identity sensor v3.x is delivered as a component of Microsoft Defender for Endpoint and is updated automatically through Windows Updates. No manual sensor update process is required for v3.x sensors.

The following sensor update information applies only to Defender for Identity sensor v2.x.

Defender for Identity sensor v2.x update types

  • Restarted: Defender for Identity sensor services

The following sensor update information applies only to Defender for Identity sensor v2.x.

Defender for Identity sensor v2.x update types

  • Restarted: Defender for Identity sensor services

Delayed update for sensor v2.x

For any sensor that fails to complete the update process, a relevant [health alert](health-alerts.md) is triggered, and is sent as a notification.

Silently update the Defender for Identity v2.x sensor

Use the following command to silently update the Defender for Identity v2.x sensor:

Syntax

The following command shows the basic syntax for running the sensor installer silently or interactively:

"Azure ATP sensor Setup.exe" [/quiet] [/Help] [NetFrameworkCommandLineArguments="/q"]


#### Installation options

> [!div class="mx-tableFixed"]
>
> |Help|/help|No|Provides help and quick reference. Displays the correct use of the setup command including a list of all options and behaviors.|
> |NetFrameworkCommandLineArguments="/q"|NetFrameworkCommandLineArguments="/q"|Yes|Specifies the parameters for the .Net Framework installation. Must be set to enforce the silent installation of .Net Framework.|

#### Examples

The following example runs the sensor installer silently from the command line without user interaction:


## Configure proxy settings

We recommend that you configure initial proxy settings during silent installation [using command line switches](deploy/install-sensor.md#perform-a-defender-for-identity-silent-installation). If you need to update your proxy settings later on, use either the [CLI method](deploy/configure-proxy.md#change-proxy-configuration-using-the-cli) or [PowerShell method](deploy/configure-proxy.md#change-proxy-configuration-using-powershell).

If you'd previously configured your proxy settings via either WinINet or a registry key and need to update them, you'll need to [use the legacy proxy configuration method](deploy/configure-proxy.md#change-proxy-configuration-using-legacy-methods) you used originally.

For more information, see [Configure endpoint proxy and internet connectivity settings](deploy/configure-proxy.md).

## Related content

- [Microsoft Defender for Identity sensor v2.x prerequisites](deploy/prerequisites-sensor-version-2.md)
- [Deploy the Defender for Identity sensor v3.x](deploy/deploy-sensor-v3.md)
- [Configure Windows event forwarding to your Defender for Identity standalone sensor](deploy/configure-event-forwarding.md)
- [Defender for Identity community forum](<https://aka.ms/MDIcommunity>)