Microsoft Defender for Identity
Identity protection

Microsoft Defender for Identity sensor v2.x prerequisites | Microsoft Defender for Identity

In brief

The prerequisites page now recommends sensor v3.x for Windows Server 2019 or later and clarifies that CPU, memory, and disk requirements are additional to resources used by the operating system and domain controller services.

What Defender admins need to know

Review deployment planning and capacity calculations; no required change is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Licensing requirements

Deploying Defender for Identity requires one of the following Microsoft 365 licenses:

Prerequisite / Recommendation Description
Specifications Make sure to installThe Defender for Identity on Windows version 2016 or higher, on asensor requires the following resources beyond those already used by the operating system and domain controller server with a minimum of:services:

- two cores
- 6 GB of RAM
- 6 GB of disk space required, 10 GB recommended, including space for Defender for Identity binaries and logs

Defender for Identity supports read-only domain controllers (RODC).
Performance For optimal performance, set the Power Option of the machine running the Defender for Identity sensor to High Performance.
Network interface configuration If you're using VMware virtual machines, make sure the virtual machine's NIC configuration has Large Send Offload (LSO) disabled. For more information, see VMware virtual machine sensor issue for more details.
Maintenance window We recommend scheduling a maintenance window for your domain controllers, as a restart might be required if the installation runs and a restart is already pending, or if .NET Framework needs to be installed.

If .NET Framework version 4.7 or later isn't already found on the system, .NET Framework version 4.7 is installed, and might require a restart.