Microsoft Defender for Identity
Identity protection

Migrate To Sensor V3

In brief

Migration is unsupported on non-domain-controller servers running AD FS, AD CS, or Microsoft Entra Connect, while domain controllers running these roles are included. RPC auditing is automatic from sensor 3.0.8, and v3.x updates through Windows Update without the v2.x delayed-update option. Readiness reasons now appear in the Sensors page tooltip.

What Defender admins need to know

Review migration eligibility and account for operating-system-managed sensor updates; use the Sensors page tooltip to troubleshoot readiness.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#customer intent: As a security admin, I want to migrate my Defender for Identity sensors from v2.x to v3.x so that I can use the latest sensor without downtime or data loss.

You can migrate your Defender for Identity sensors from v2.x to v3.x directly from the Microsoft Defender portal. The migration automatically completes the switchover and maintains your server configurations and security monitoring, with no downtime or data duplication.

Before migrating, review the prerequisites and sensor version limitations, including that v3.x doesn't support VPN integration or syslog notifications.

Prerequisites

To migrate, each server must meet the following requirements:

  • Domain controller, including a domain controller that also runs AD FS, AD CS, or Microsoft Entra Connect
  • Defender for Identity sensor v2.x (version 2.254.19112.470 or later)
  • Windows Server 2019 or later
  • Microsoft Defender for Endpoint deployed, with the July 2026 or later Windows Server cumulative update installed.

Understand migration states

To migrate,The Migration state column on the Sensors page shows the current status of each server must meetserver:

For optimal protection and monitoring, complete the following requirements:

  • Domain controller without additional identity roles
  • Defender for Identity sensor v2.x (version 2.254.19112.470 or later)
  • Windows Server 2019 or later
  • Microsoft Defender for Endpoint deployed, with the July 2026 or later Windows Server cumulative update installed.

Migration states

The Migration state column on the Sensors page shows the current status of each server:

For optimal protection and monitoring, complete the configuration steps described in Defender for Identity sensor v3.x prerequisitesconfiguration steps described in Defender for Identity sensor v3.x prerequisites, including:

  • Configure RPC auditing.
  • Configure automatic Windows event auditing. Existing auditing configurations from the v2.x sensor are preserved and converted for v3.x, but we recommend enabling automatic Windows event auditing for optimal configuration validation.
  • Switch action accounts from gMSA to local system. The v3.x sensor uses the local system identity for response actions. If you had a gMSA configured for action accounts, select Automatically use the sensor's local system account in the Microsoft Defender portal. If gMSA remains enabled for action accounts, response actions (including attack disruption) won't work.
  • Understand DSA and gMSA health alerts in environments with both v2 and v3 sensors. If your workspace still has a Directory Service Account (DSA) or group Managed Service Account (gMSA) configured for v2 sensors, DSA and gMSA credentials continue to be validated on all sensors, including v3 sensors. This is by design. V3 sensors ignore the DSA and gMSA for auditing and response actions, but credential validation occurs at the workspace level. To stop receiving the Directory services user credentials are incorrect health alert, remove the DSA or gMSA after all sensors are migrated to v3.
  • Configure RPC auditing. Starting with sensor version 3.0.8 (July 2026 release), RPC auditing is enabled automatically when you upgrade the sensor, so no manual configuration is required.

Troubleshoot "Not ready for migration" status

IfWhen a server showsis marked Not ready for migration, usehover over the status on the Sensors page to see a tooltip that lists the reasons the server doesn't meet the migration prerequisites.

The following table lists each reason that can appear in the tooltip, how to verify it, and how to resolve it:

Reason shown in the tooltipHow to verifyResolution
Device isn't properly onboarded to Microsoft Defender for Endpoint.Run the Microsoft Defender for Endpoint Client Analyzer and the following table to identify which condition is failing:
ConditionHow to verifyResolution if failing
Defender for Endpoint sensor is runningClient Analyzer report shows Sense service Status is Running.Verify Microsoft Defender for Endpoint onboarding is complete.
Defender for Endpoint onboarding info existsClient Analyzer: Checkcheck RegOnboardingInfoPolicy.Json in the results ZIP. If empty, the policy key is missing. The connectivity log also shows "OnboardingInfo could not be found in the registry" if the onboarding info is missing. Re-onboard the server to Microsoft Defender for Endpoint.
Device has a registered Defender for Endpoint device IDClient Analyzer report shows Device ID field contains a valid GUID.Verify Microsoft Defender for Endpoint onboarding completed successfully. Re-onboard the server if SenseMachineId is empty.
Defender for Identity v2.x sensor is runningGo to the Sensors page in the portal and validate the Service status column shows Running, or run sc query AATPSensorUpdater and confirm the service state is Running.Start the AATPSensorUpdater service. If the service fails to start, reinstall the v2.x sensor.
Defender for Identity v2.x sensorOperating system version is 2.254 or laterCheck the installed sensor version in Programs and Features or on the Sensors page in the portal.Update the Defender for Identity v2 sensor to version 2.254.19112.470 or later. Ensure delayed updates arenisn't blocking the update.
Defender for Endpoint sensor version is 10.8735 or laterClient Analyzer report: the Sense version field displays the installed version.Update the Defender for Endpoint sensor to the latest version.
supported. Requires Windows Server 2019 or later with July 2026 or later cumulative updatelater. Run winver to confirm the OSoperating system version and build number. Upgrade the operating system to Windows Server 2019 or later and install the July 2026 or later cumulative update.
Domain controller without additional identity rolesMicrosoft Defender for Endpoint sensor version is outdated or unsupported. VerifyIn the Client Analyzer report, check the Sense version field.Update the Microsoft Defender for Endpoint sensor to the latest version.
Microsoft Defender for Endpoint (Sense) service isn't running.In the Client Analyzer report, confirm the Sense service Status is Running.Start the Sense service and verify Microsoft Defender for Endpoint onboarding is complete.
Migration is currently supported only for domain controllers.Confirm the server is a pure domain controller and doesn't run AD FS, AD CS, or Entra Connect alongside the DC role.controller. MigrationIn-place migration is available only supported on purefor domain controllers. Use
Microsoft Defender for Endpoint device ID is missing or not registered.In the Client Analyzer report, confirm the Device ID field contains a valid GUID.Verify Microsoft Defender for Endpoint onboarding completed successfully, and re-onboard the server if the device ID is empty.
Sensor v2.x status is unreachable or disconnected.On the Sensors page, check the sensor's status.Verify network connectivity between the server and the Defender for Identity service, and confirm the sensor for servers with additional roles.v2.x is running.
Sensor v2.x service status is not running.On the Sensors page, confirm the Service status column shows Running, or run sc query AATPSensorUpdater to confirm the service state.Start the AATPSensorUpdater service. If the service fails to start, reinstall the sensor v2.x.

Troubleshoot migration failures