Microsoft Defender for Identity
Identity protection

Migrate from Advanced Threat Analytics

In brief

The article now uses a shared ATA end-of-life notice, adds a Defender for Identity prerequisites link, identifies the final ATA release, and updates product names and links to Microsoft Defender.

What Defender admins need to know

Administrators planning an ATA migration should review the prerequisites and use the updated references when validating the migration.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Migrate from Advanced Threat Analytics (ATA) to Microsoft Defender for Identity

This article describes how to migrate from an existing ATA installation to a Microsoft Defender for Identity sensor, andsensor. Before you begin, make sure your environment meets the Defender for Identity prerequisites. The migration includes the following steps:

[!div class="checklist"]

Defender for Identity is a cloud-based security solution that uses your on-premises Active Directory signals. Defender for Identity is highly scalable and is frequently updated.

In contrast to the ATA sensor,Lightweight Gateway, the Defender for Identity sensor also uses data sources such as Event Tracing for Windows (ETW) enabling Defender for Identity to deliver extra detections. Defender for Identity also provides:

  • Support for multi-forest environments
  • Microsoft Secure Score posture assessments

    This migration guide is designed for Defender for Identity sensors only, and not standalone sensors.

    While you can migrate to Defender for Identity from any ATA version, your ATA data isn't migrated. Therefore, we recommend that you plan to retain your ATA Data Center and any alerts required for ongoing investigations until all ATA alerts are closed or remediated.

Prerequisites

Move to Defender for Identity

Validate your migration

In Microsoft Defender, check the following areas to validate your migration:

Post-migration activities

  1. Make sure that you've recorded or remediated all existing ATA alerts. Existing ATA security alerts aren't imported to Defender for Identity with the migration.

  2. Do one or both of the following:

    • Decommission the ATA Center.: We recommend keeping ATA data online for a period of time.
    • Back up Mongo DB if: If you want to keep the ATA data indefinitely. For more information, see Backing up the ATA database.

Related content

After migrating to Defender for Identity, learn more about investigating alerts in Microsoft Defender XDR: