Microsoft Defender for Identity health issues
In brief
The article adds context for Configuration-container auditing, clarifies the no-traffic alert wording, and makes minor metadata and RPC audit text updates.
What Defender admins need to know
Administrators have clearer guidance when reviewing and troubleshooting Defender for Identity health alerts; no action is specified.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Microsoft Defender for Identity health issues
|All/Some of the selected capture network adapters on the Defender for Identity sensor are disabled or disconnected|Network traffic for some/all of the domain controllers is no longer captured by the Defender for Identity sensor. This issue affects the ability to detect suspicious activities, related to those domain controllers.|Make sure these selected capture network adapters on the Defender for Identity sensor are enabled and connected.|Medium|Sensors health issues tab|2.x|
|Directory services user credentials are incorrect|The credentials for the directory services user account are incorrect. This issue affects sensors' ability to detect activities using LDAP queries against domain controllers.|- For a standard AD accounts: Verify that the username, password, and domain in the Directory services configuration page are correct.
- For group Managed Service Accounts: Verify that the username and domain in the Directory Services configuration page are correct. Also check all the other gMSA account prerequisites described on the Directory Service account recommendations page.
- For v3.x sensors in environments with both v2 and v3 sensors: DSA and gMSA credentials continue to be validated on all sensors, including v3 sensors, as long as a workspace-level DSA or gMSA exists. This is by design. V3 sensors ignore the DSA and gMSA for auditing and response actions, but credential validation occurs at the workspace level. To stop receiving this alert, remove the DSA or gMSA after all sensors are migrated to v3. For more information, see DSA and gMSA health alerts in environments with both v2 and v3 sensors.
- For information about gMSA password rotation and temporary credential alerts, see the Directory services user credentials are incorrect note at the end of this section.|Medium|Global health issues tab|All|
|Low success rate of active name resolution|The listed Defender for Identity sensors are failing to resolve IP addresses to device names more than 90% of the time using the following methods:
- NTLM over RPC
- NetBIOS
- Reverse DNS. This issue affects Defender for Identity's detections capabilities and might increase the number of false positive alarms.|- For NTLM over RPC: Check that port 135 is open for inbound communication from Defender for Identity sensors on all computers in the environment.
- For reverse DNS: Check that the sensors can reach the DNS server and that Reverse Lookup Zones are enabled.
- For NetBIOS: Check that port 137 is open for inbound communication from Defender for Identity sensors on all computers in the environment.
Additionally, make sure that the network configuration (such as firewalls) isn't preventing communication to the relevant ports.|Low|Sensors health issues tab and Global health issues tab|2.x|
|No network traffic received from domain controller|No network traffic was received from any domain controller via this Defender for Identity sensor. This issue might indicate that port mirroring from the domain controllers to the Defender for Identity sensor isn't configured yet or not working.|Verify that port mirroring is configured properly on your network devices.
On the Defender for Identity sensor capture NIC, disable these features in Advanced Settings:
Receive Segment Coalescing (IPv4)
Receive Segment Coalescing (IPv6)|Medium|Sensors health issues tab and Global health issues tab|2.x|
|Read-only user password to expire shortly|The read-only user password, used to perform resolution of entities against Active Directory, is about to expire in less than 30 days. If the password for this user expires, all Defender for Identity sensors stop running and no new data is collected.|Change the domain connectivity password and then update the Directory Service account password.|Medium|Global health issues tab|2.x|
|Read-only user password expired|The read-only user password, used to get directory data, expired. All Defender for Identity sensors stop running, or will stop running soon, and no new data is collected.|Change the domain connectivity password and then update the Directory Service account password.|High|Global health issues tab|2.x|
|Sensor outdated (v2)|A Defender for Identity sensor is running a version that can't communicate with the Defender for Identity cloud infrastructure.|Manually update the sensor and check to see why the sensor isn't automatically updating. If this option doesn't work, download the latest sensor installation package and uninstall and reinstall the sensor. For more information, see Download the Microsoft Defender for Identity sensor and Install the Microsoft Defender for Identity sensor.|Medium|Sensors health issues tab and Global health issues tab|2.x|
|NTLM Auditing is not enabled|NTLM Auditing (for event ID 8004) isn't enabled on the server. (This configuration is validated once a day, per sensor.)|Enable NTLM Auditing events according to the guidance as described at the Event ID 8004 section, in the Configure Windows Event collection page.|Medium|Sensors health issues tab|All|
|Directory Services Advanced Auditing is not enabled as required|The Directory Services Advanced Auditing configuration doesn't include all the categories and subcategories as required. (This configuration is validated once a day, per sensor.)|Enable the Directory Services Advanced Auditing events. For more information, see Configure audit policies for Windows event logs.|Medium|Sensors health issues tab|All|
|Directory Services Object Auditing is not enabled as required|The Directory Services Object Auditing configuration doesn't include all the object types and permissions as required. (This configuration is validated once a day, per domain.)|Enable the Directory Services Object Auditing events according to the guidance as described in the Configure domain object auditing section, in the Configure Windows Event collection page.|Medium|Global health issues tab|All|
|Auditing on the Configuration container is not enabled as required|The Directory Services Auditing on the Domain's Configuration container isn't enabled as required. (This configuration is validated once a day, per domain.) Active Directory replicates the configuration container throughout the forest, so configure auditing once for the entire forest. The health alert might appear for multiple domains because sensors in each domain report the state of the shared configuration container.|Enable the Directory Services Auditing on the Domain's Configuration container according to the guidance as described in the Configure Audit Policies section, in the Configure Windows Event collection page.|Medium|Global health issues tab|All|
|Auditing on the ADFS container is not enabled as required|The Directory Services Auditing on the ADFS container isn't enabled as required. (This configuration is validated once a day, per domain.)|Enable the Directory Services Auditing on the ADFS container according to the guidance as described in the Configure auditing on an Active Directory Federation Services (AD FS) section, in the Configure Windows Event collection page.|Medium|Global health issues tab|All|
|Power mode isn't configured for optimal processor performance|The operating system's power mode isn't configured to the optimal processor performance settings. (This configuration is validated once a day, per sensor.) This issue can affect the server's performance and the sensors' ability to detect suspicious activities.|Do one of the following:
- Configure the power option of the machine running the Defender for Identity sensor to High Performance
- Set both the minimum and maximum processor state to 100
For more information, see the Server requirements section in the Defender for Identity prerequisites page.|Low|Sensors health issues tab|2.x|
|Sensor failed to write to the custom log path|The custom log path provided in the sensor configuration can't be created.|1. Stop the AATPSensorUpdater and AATPSensor services.
2. Change the SensorCustomLogLocation in the sensor configuration file to a valid path or set it to null.
3. Start the AATPSensorUpdater and AATPSensor services again.|Low|Sensors health issues tab|2.x|
|Radius accounting (VPN integration) data ingestion failures|The listed Defender for Identity sensors have radius accounting (VPN integration) data ingestion failures.|Validate that the shared secret in the Defender for Identity configuration settings matches your VPN server, according to the guidance described Configure VPN in Defender for Identity section, in the Defender for Identity VPN integration page.|Low|Health issues page|2.x|
|Auditing for AD CS servers isn't enabled as required|The Advanced Auditing Policy Configuration or AD CS auditing isn't enabled as required. (This configuration is validated once a day, per sensor.)|Enable the Advanced Auditing Policy Configuration and AD CS auditing according to the guidance as described in the Configure auditing on AD CS section, in the Configure Windows Event collection page.|Medium|Sensors health issues tab|2.x|
|Sensor failed to retrieve Microsoft Entra Connect service configuration|The sensor is unable to retrieve the configuration from the Microsoft Entra Connect service (also known as Microsoft Azure AD sync).|Ensure that the Microsoft Entra connect service (Microsoft Azure AD Sync) is running and follow the instructions in Configure permissions for the Microsoft Entra Connect (ADSync) database to grant the sensor the necessary permissions. If the issue persists, follow the troubleshooting guidance at SQL connectivity issues with Microsoft Entra Connect.|Medium|Sensors health issues tab|2.x|
|Sensor v3.x RPC Audit Misconfigured|The sensor is missing the required Unified Sensor RPC Audit configuration tag, or the tag was not applied correctly.|This issue affects the sensor's ability to enable enhanced RPC auditing, which is required for certain advanced identity detections on V3.v3.x sensors. Without this configuration, some identity-based detections might not function, reducing Defender for Identity's visibility into suspicious activities. Verify that the Unified Sensor RPC Audit configuration is correctly applied to the relevant devices by following the instructions at Configure RPC auditing. Once the tag is applied, the configuration is enforced automatically on matching devices, restoring full detection capability. From sensor version 3.0.8, RPC auditing is enabled automatically when the sensor is upgraded, so the tag is no longer required.|Medium|Sensors health issues tab|3.x|
@@ -1,15 +1,14 @@ --- title: Microsoft Defender for Identity health issues description: Learn about health issues in Microsoft Defender for Identity, including causes and resolution steps for sensor and domain-related alerts.-ms.date: 07/15/2026+ms.date: 08/10/2026 ms.topic: how-to ms.reviewer: rlitinsky ai-usage: ai-assisted ms.custom:- - msecd-doc-authoring-1014- - msecd-doc-authoring-106+ - msecd-doc-authoring-1015 - sfi-image-nochange-#Customer intent: As an IT admin, I want to understand and resolve Defender for Identity health issues so that my identity threat detection stays fully operational.+#customer intent: As an IT admin, I want to understand and resolve Defender for Identity health issues so that my identity threat detection stays fully operational. --- # Microsoft Defender for Identity health issues@@ -71,7 +70,7 @@ Each health issue table includes a **Displayed in** column that indicates whethe |**All/Some of the selected capture network adapters on the Defender for Identity sensor are disabled or disconnected**|Network traffic for some/all of the domain controllers is no longer captured by the Defender for Identity sensor. This issue affects the ability to detect suspicious activities, related to those domain controllers.|Make sure these selected capture network adapters on the Defender for Identity sensor are enabled and connected.|Medium|Sensors health issues tab|2.x| |**Directory services user credentials are incorrect**|The credentials for the directory services user account are incorrect. This issue affects sensors' ability to detect activities using LDAP queries against domain controllers.|- For a **standard** AD accounts: Verify that the username, password, and domain in the **Directory services** configuration page are correct.<br>- For **group Managed Service Accounts:** Verify that the username and domain in the **Directory Services** configuration page are correct. Also check all the other **gMSA account** prerequisites described on the [Directory Service account recommendations](directory-service-accounts.md) page.<br>- For **v3.x sensors in environments with both v2 and v3 sensors:** DSA and gMSA credentials continue to be validated on all sensors, including v3 sensors, as long as a workspace-level DSA or gMSA exists. This is by design. V3 sensors ignore the DSA and gMSA for auditing and response actions, but credential validation occurs at the workspace level. To stop receiving this alert, remove the DSA or gMSA after all sensors are migrated to v3. For more information, see [DSA and gMSA health alerts in environments with both v2 and v3 sensors](deploy/deploy-sensor-v3.md#dsa-and-gmsa-health-alerts-in-environments-with-both-v2-and-v3-sensors). <br> - For information about gMSA password rotation and temporary credential alerts, see the **Directory services user credentials are incorrect** note at the end of this section.|Medium|Global health issues tab|All| |**Low success rate of active name resolution**|The listed Defender for Identity sensors are failing to resolve IP addresses to device names more than 90% of the time using the following methods:<br />- NTLM over RPC<br />- NetBIOS<br />- Reverse DNS. This issue affects Defender for Identity's detections capabilities and might increase the number of false positive alarms.|- For NTLM over RPC: Check that port 135 is open for inbound communication from Defender for Identity sensors on all computers in the environment.<br />- For reverse DNS: Check that the sensors can reach the DNS server and that Reverse Lookup Zones are enabled.<br />- For NetBIOS: Check that port 137 is open for inbound communication from Defender for Identity sensors on all computers in the environment.<br />Additionally, make sure that the network configuration (such as firewalls) isn't preventing communication to the relevant ports.|Low|Sensors health issues tab and Global health issues tab|2.x|-|**No traffic received from domain controller**|No traffic was received from any domain controller via this Defender for Identity sensor. This issue might indicate that port mirroring from the domain controllers to the Defender for Identity sensor isn't configured yet or not working.|Verify that [port mirroring is configured properly on your network devices](deploy/configure-port-mirroring.md).<br></br>On the Defender for Identity sensor capture NIC, disable these features in Advanced Settings:<br></br>Receive Segment Coalescing (IPv4)<br></br>Receive Segment Coalescing (IPv6)|Medium|Sensors health issues tab and Global health issues tab|2.x|+|**No network traffic received from domain controller**|No network traffic was received from any domain controller via this Defender for Identity sensor. This issue might indicate that port mirroring from the domain controllers to the Defender for Identity sensor isn't configured yet or not working.|Verify that [port mirroring is configured properly on your network devices](deploy/configure-port-mirroring.md).<br></br>On the Defender for Identity sensor capture NIC, disable these features in Advanced Settings:<br></br>Receive Segment Coalescing (IPv4)<br></br>Receive Segment Coalescing (IPv6)|Medium|Sensors health issues tab and Global health issues tab|2.x| |**Read-only user password to expire shortly**|The read-only user password, used to perform resolution of entities against Active Directory, is about to expire in less than 30 days. If the password for this user expires, all Defender for Identity sensors stop running and no new data is collected.|Change the domain connectivity password and then [update the Directory Service account](directory-service-accounts.md) password.|Medium|Global health issues tab|2.x| |**Read-only user password expired**|The read-only user password, used to get directory data, expired. All Defender for Identity sensors stop running, or will stop running soon, and no new data is collected.|Change the domain connectivity password and then [update the Directory Service account](directory-service-accounts.md) password.|High|Global health issues tab|2.x| |**Sensor outdated (v2)**|A Defender for Identity sensor is running a version that can't communicate with the Defender for Identity cloud infrastructure.|Manually update the sensor and check to see why the sensor isn't automatically updating. If this option doesn't work, download the latest sensor installation package and uninstall and reinstall the sensor. For more information, see [Download the Microsoft Defender for Identity sensor](download-sensor.md) and [Install the Microsoft Defender for Identity sensor](install-sensor.md).|Medium|Sensors health issues tab and Global health issues tab|2.x|@@ -90,14 +89,14 @@ Each health issue table includes a **Displayed in** column that indicates whethe |**NTLM Auditing is not enabled**|NTLM Auditing (for event ID 8004) isn't enabled on the server. (This configuration is validated once a day, per sensor.)|Enable NTLM Auditing events according to the guidance as described at the [Event ID 8004](configure-windows-event-collection.md#configure-ntlm-auditing) section, in the [Configure Windows Event collection](configure-windows-event-collection.md) page.|Medium|Sensors health issues tab|All| |**Directory Services Advanced Auditing is not enabled as required**|The Directory Services Advanced Auditing configuration doesn't include all the categories and subcategories as required. (This configuration is validated once a day, per sensor.)|Enable the Directory Services Advanced Auditing events. For more information, see [Configure audit policies for Windows event logs](configure-windows-event-collection.md).|Medium|Sensors health issues tab|All| |**Directory Services Object Auditing is not enabled as required**|The Directory Services Object Auditing configuration doesn't include all the object types and permissions as required. (This configuration is validated once a day, per domain.)|Enable the Directory Services Object Auditing events according to the guidance as described in the [Configure domain object auditing](configure-windows-event-collection.md#configure-domain-object-auditing) section, in the [Configure Windows Event collection](configure-windows-event-collection.md) page.|Medium|Global health issues tab|All|-|**Auditing on the Configuration container is not enabled as required**|The Directory Services Auditing on the Domain's Configuration container isn't enabled as required. (This configuration is validated once a day, per domain.)|Enable the Directory Services Auditing on the Domain's Configuration container according to the guidance as described in the [Configure Audit Policies](configure-windows-event-collection.md#enable-auditing-on-an-exchange-object) section, in the [Configure Windows Event collection](configure-windows-event-collection.md) page.|Medium|Global health issues tab|All|+|**Auditing on the Configuration container is not enabled as required**|The Directory Services Auditing on the Domain's Configuration container isn't enabled as required. (This configuration is validated once a day, per domain.) Active Directory replicates the configuration container throughout the forest, so configure auditing once for the entire forest. The health alert might appear for multiple domains because sensors in each domain report the state of the shared configuration container.|Enable the Directory Services Auditing on the Domain's Configuration container according to the guidance as described in the [Configure Audit Policies](configure-windows-event-collection.md#enable-auditing-on-an-exchange-object) section, in the [Configure Windows Event collection](configure-windows-event-collection.md) page.|Medium|Global health issues tab|All| |**Auditing on the ADFS container is not enabled as required**|The Directory Services Auditing on the ADFS container isn't enabled as required. (This configuration is validated once a day, per domain.)|Enable the Directory Services Auditing on the ADFS container according to the guidance as described in the [Configure auditing on an Active Directory Federation Services (AD FS)](configure-windows-event-collection.md#configure-auditing-on-an-active-directory-federation-services-ad-fs) section, in the [Configure Windows Event collection](configure-windows-event-collection.md) page.|Medium|Global health issues tab|All| |**Power mode isn't configured for optimal processor performance**|The operating system's power mode isn't configured to the optimal processor performance settings. (This configuration is validated once a day, per sensor.) This issue can affect the server's performance and the sensors' ability to detect suspicious activities.|Do one of the following: <br><br>- Configure the power option of the machine running the Defender for Identity sensor to *High Performance*<br>- Set both the minimum and maximum processor state to *100*<br><br>For more information, see the [Server requirements](deploy/prerequisites-sensor-version-2.md#server-requirements) section in the [Defender for Identity prerequisites](deploy/prerequisites-sensor-version-2.md) page.|Low|Sensors health issues tab|2.x| |**Sensor failed to write to the custom log path**|The custom log path provided in the sensor configuration can't be created.|1. Stop the `AATPSensorUpdater` and `AATPSensor` services. <br>2. Change the `SensorCustomLogLocation` in the sensor configuration file to a valid path or set it to null. <br>3. Start the `AATPSensorUpdater` and `AATPSensor` services again.|Low|Sensors health issues tab|2.x| |**Radius accounting (VPN integration) data ingestion failures**|The listed Defender for Identity sensors have radius accounting (VPN integration) data ingestion failures.|Validate that the shared secret in the Defender for Identity configuration settings matches your VPN server, according to the guidance described [Configure VPN in Defender for Identity](vpn-integration.md#configure-vpn-in-defender-for-identity) section, in the [Defender for Identity VPN integration](vpn-integration.md) page.|Low|Health issues page|2.x| |**Auditing for AD CS servers isn't enabled as required**|The Advanced Auditing Policy Configuration or AD CS auditing isn't enabled as required. (This configuration is validated once a day, per sensor.)|Enable the Advanced Auditing Policy Configuration and AD CS auditing according to the guidance as described in the [Configure auditing on AD CS](configure-windows-event-collection.md#configure-auditing-on-ad-cs) section, in the [Configure Windows Event collection](configure-windows-event-collection.md) page.|Medium|Sensors health issues tab|2.x| |**Sensor failed to retrieve Microsoft Entra Connect service configuration**|The sensor is unable to retrieve the configuration from the Microsoft Entra Connect service (also known as Microsoft Azure AD sync).|Ensure that the Microsoft Entra connect service **(Microsoft Azure AD Sync)** is running and follow the instructions in [Configure permissions for the Microsoft Entra Connect (ADSync) database](deploy/active-directory-federation-services.md#configure-permissions-for-the-microsoft-entra-connect-adsync-database) to grant the sensor the necessary permissions. If the issue persists, follow the troubleshooting guidance at [SQL connectivity issues with Microsoft Entra Connect](/entra/identity/hybrid/connect/tshoot-connect-tshoot-sql-connectivity).|Medium|Sensors health issues tab|2.x|-|**Sensor v3.x RPC Audit Misconfigured**|The sensor is missing the required Unified Sensor RPC Audit configuration tag, or the tag was not applied correctly.|This issue affects the sensor's ability to enable enhanced RPC auditing, which is required for certain advanced identity detections on V3.x sensors. Without this configuration, some identity-based detections might not function, reducing Defender for Identity's visibility into suspicious activities. Verify that the Unified Sensor RPC Audit configuration is correctly applied to the relevant devices by following the instructions at [Configure RPC auditing](deploy/deploy-sensor-v3.md#configure-rpc-auditing). Once the tag is applied, the configuration is enforced automatically on matching devices, restoring full detection capability. From sensor version 3.0.8, RPC auditing is enabled automatically when the sensor is upgraded, so the tag is no longer required.|Medium|Sensors health issues tab|3.x|+|**Sensor v3.x RPC Audit Misconfigured**|The sensor is missing the required Unified Sensor RPC Audit configuration tag, or the tag was not applied correctly.|This issue affects the sensor's ability to enable enhanced RPC auditing, which is required for certain advanced identity detections on v3.x sensors. Without this configuration, some identity-based detections might not function, reducing Defender for Identity's visibility into suspicious activities. Verify that the Unified Sensor RPC Audit configuration is correctly applied to the relevant devices by following the instructions at [Configure RPC auditing](deploy/deploy-sensor-v3.md#configure-rpc-auditing). Once the tag is applied, the configuration is enforced automatically on matching devices, restoring full detection capability. From sensor version 3.0.8, RPC auditing is enabled automatically when the sensor is upgraded, so the tag is no longer required.|Medium|Sensors health issues tab|3.x| >[!NOTE] 