Migrate from Advanced Threat Analytics
In brief
The article now uses a shared ATA end-of-life notice, adds a Defender for Identity prerequisites link, identifies the final ATA release, and updates product names and links to Microsoft Defender.
What Defender admins need to know
Administrators planning an ATA migration should review the prerequisites and use the updated references when validating the migration.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Migrate from Advanced Threat Analytics (ATA) to Microsoft Defender for Identity
This article describes how to migrate from an existing ATA installation to a Microsoft Defender for Identity sensor, andsensor. Before you begin, make sure your environment meets the Defender for Identity prerequisites. The migration includes the following steps:
[!div class="checklist"]
Defender for Identity is a cloud-based security solution that uses your on-premises Active Directory signals. Defender for Identity is highly scalable and is frequently updated.
In contrast to the ATA sensor,Lightweight Gateway, the Defender for Identity sensor also uses data sources such as Event Tracing for Windows (ETW) enabling Defender for Identity to deliver extra detections. Defender for Identity also provides:
- Support for multi-forest environments
- Microsoft Secure Score posture assessments
This migration guide is designed for Defender for Identity sensors only, and not standalone sensors.
While you can migrate to Defender for Identity from any ATA version, your ATA data isn't migrated. Therefore, we recommend that you plan to retain your ATA Data Center and any alerts required for ongoing investigations until all ATA alerts are closed or remediated.
Prerequisites
Alert exclusions
.: Exclusions are not transferable from ATA to Defender for Identity, so details of each exclusion are required to replicate the exclusions as Defender for Identity in MicrosoftDefender XDR.Defender.Account details for entity tags
.: If you don't already have dedicated entity tags, create new ones for use with Defender for Identity. For more information, see Defender for Identity entity tags in Microsoft Defender.A complete list of all entities, such as computers, groups, or users, that you want to manually tag as Sensitive entities
.: For more information, see Defender for Identity entity tags in Microsoft Defender.Report scheduling and classic reports
, including: Including a list of all reports and scheduled timing.
Move to Defender for Identity
Validate your migration
In Microsoft Defender, check the following areas to validate your migration:
- Review any Defender for Identity health alerts for signs of service issues.
- Review Defender for Identity sensor error logs for any unusual errors.
Post-migration activities
Make sure that you've recorded or remediated all existing ATA alerts. Existing ATA security alerts aren't imported to Defender for Identity with the migration.
Do one or both of the following:
- Decommission the ATA Center
.: We recommend keeping ATA data online for a period of time. - Back up Mongo DB
if: If you want to keep the ATA data indefinitely. For more information, see Backing up the ATA database.
- Decommission the ATA Center
Related content
After migrating to Defender for Identity, learn more about investigating alerts in Microsoft Defender XDR:
- View and manage security alerts
Investigate Defender for Identity security alerts in Microsoft Defender XDR\ No newline at end of file
@@ -1,21 +1,18 @@ ----title: Migrate from Advanced Threat Analytics | Microsoft Defender for Identity+title: Migrate from Advanced Threat Analytics description: Learn how to move an existing Advanced Threat Analytics installation to Microsoft Defender for Identity.-ms.date: 06/15/2026+ms.date: 07/02/2026 ms.topic: how-to ms.reviewer: martin77s ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Migrate from Advanced Threat Analytics (ATA) to Microsoft Defender for Identity -> [!IMPORTANT]-> ATA is end of life. ATA ended Mainstream Support on January 12, 2021, and Extended Support ended in January 2026. No further updates, including security fixes, will be provided. For more information, read [End of mainstream support for Advanced Threat Analytics](https://techcommunity.microsoft.com/t5/microsoft-security-and/end-of-mainstream-support-for-advanced-threat-analytics-january/ba-p/1539181).->-> We strongly recommend migrating to Defender for Identity as soon as possible using the steps in this article.+[!INCLUDE [Advanced Threat Analytics end of life](includes/advanced-threat-analytics-end-of-life.md)] -This article describes how to migrate from an existing ATA installation to a Microsoft Defender for Identity sensor, and includes the following steps:+This article describes how to migrate from an existing ATA installation to a Microsoft Defender for Identity sensor. Before you begin, make sure your environment meets the [Defender for Identity prerequisites](prerequisites.md). The migration includes the following steps: > [!div class="checklist"] >@@ -30,7 +27,7 @@ ATA is a standalone on-premises solution with multiple components, such as the A Defender for Identity is a cloud-based security solution that uses your on-premises Active Directory signals. Defender for Identity is highly scalable and is frequently updated. -In contrast to the ATA sensor, the Defender for Identity sensor also uses data sources such as Event Tracing for Windows (ETW) enabling Defender for Identity to deliver extra detections. Defender for Identity also provides:+In contrast to the ATA Lightweight Gateway, the Defender for Identity sensor also uses data sources such as Event Tracing for Windows (ETW) enabling Defender for Identity to deliver extra detections. Defender for Identity also provides: - Support for [multi-forest environments](deploy/multi-forest.md) - [Microsoft Secure Score posture assessments](/defender-for-identity/security-assessment)@@ -43,8 +40,9 @@ Defender for Identity also uses the Microsoft 365 security portfolio to automati > This migration guide is designed for Defender for Identity sensors only, and not standalone sensors. > > While you can migrate to Defender for Identity from any ATA version, your ATA data isn't migrated. Therefore, we recommend that you plan to retain your ATA Data Center and any alerts required for ongoing investigations until all ATA alerts are closed or remediated.-> +> [!NOTE]+> The final release of ATA is [Update 3 for Microsoft Advanced Threat Analytics 1.9](https://support.microsoft.com/help/4568997/update-3-for-microsoft-advanced-threat-analytics-1-9). ATA ended Mainstream Support on January 12, 2021. Extended Support will continue until January 2026. For more information, read [End of mainstream support for Advanced Threat Analytics](https://techcommunity.microsoft.com/t5/microsoft-security-and/end-of-mainstream-support-for-advanced-threat-analytics-january/ba-p/1539181). ## Prerequisites @@ -66,16 +64,16 @@ Before starting the migration, gather all of the following information: - **[VPN integration details](vpn-integration.md)**. -- **Alert exclusions**. Exclusions are not transferable from ATA to Defender for Identity, so details of each exclusion are required to [replicate the exclusions as Defender for Identity](exclusions.md) in Microsoft Defender XDR.+- **Alert exclusions**: Exclusions are not transferable from ATA to Defender for Identity, so details of each exclusion are required to [replicate the exclusions as Defender for Identity](exclusions.md) in Microsoft Defender. -- **Account details for entity tags**. If you don't already have dedicated entity tags, create new ones for use with Defender for Identity. For more information, see [Defender for Identity entity tags in Microsoft Defender XDR](entity-tags.md).+- **Account details for entity tags**: If you don't already have dedicated entity tags, create new ones for use with Defender for Identity. For more information, see [Defender for Identity entity tags in Microsoft Defender](entity-tags.md). -- **A complete list of all entities, such as computers, groups, or users, that you want to manually tag as *Sensitive* entities**. For more information, see [Defender for Identity entity tags in Microsoft Defender XDR](entity-tags.md).+- **A complete list of all entities, such as computers, groups, or users, that you want to manually tag as *Sensitive* entities**: For more information, see [Defender for Identity entity tags in Microsoft Defender](entity-tags.md). -- **[Report scheduling and classic reports](/defender-for-identity/classic-reports)**, including a list of all reports and scheduled timing.+- **[Report scheduling and classic reports](/defender-for-identity/classic-reports)**: Including a list of all reports and scheduled timing. > [!CAUTION]-> Do not uninstall the ATA Center until all ATA Gateways are removed. Uninstalling the ATA Center with ATA Gateways still running leaves your organization exposed with no threat protection.+> Don't uninstall the ATA Center until all ATA Gateways are removed. Uninstalling the ATA Center with ATA Gateways still running leaves your organization exposed with no threat protection. ## Move to Defender for Identity @@ -95,9 +93,9 @@ After the migration is complete, allow two hours for the Defender for Identity s ## Validate your migration -In Microsoft Defender XDR, check the following areas to validate your migration:+In Microsoft Defender, check the following areas to validate your migration: -- Review any [health issues](health-alerts.md) for signs of service issues.+- Review any [Defender for Identity health alerts](health-alerts.md) for signs of service issues. - Review Defender for Identity [sensor error logs](troubleshooting-using-logs.md) for any unusual errors. ## Post-migration activities@@ -107,13 +105,10 @@ After completing your migration to Defender for Identity, do the following to cl 1. Make sure that you've recorded or remediated all existing ATA alerts. Existing ATA security alerts aren't imported to Defender for Identity with the migration. 1. Do one or both of the following: - - **Decommission the ATA Center**. We recommend keeping ATA data online for a period of time. - - **Back up Mongo DB** if you want to keep the ATA data indefinitely. For more information, see [Backing up the ATA database](/advanced-threat-analytics/ata-database-management#backing-up-the-ata-database).+ - **Decommission the ATA Center**: We recommend keeping ATA data online for a period of time.+ - **Back up Mongo DB**: If you want to keep the ATA data indefinitely. For more information, see [Backing up the ATA database](/advanced-threat-analytics/ata-database-management#backing-up-the-ata-database). <a name="related-information"></a> ## Related content -After migrating to Defender for Identity, learn more about investigating alerts in Microsoft Defender XDR:--- [Understanding security alerts](understanding-security-alerts.md)-- [Investigate Defender for Identity security alerts in Microsoft Defender XDR](manage-security-alerts.md)+- [View and manage security alerts](understanding-security-alerts.md)\ No newline at end of file 