Microsoft Defender for Identity
Architecture and deployment

Plan capacity for deployment | Microsoft Defender for Identity

In brief

The article now more clearly describes using the sizing tool, reviewing prerequisites, following the tool’s steps, and using manual sizing guidance when the tool is unavailable.

What Defender admins need to know

Administrators can use the updated guidance to assess domain controller resources before deploying sensor v2.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use the Microsoft Defender for Identity sizing tool to determine whether your domain controller servers have enough resources for a Microsoft Defender for Identity sensor v2. Before you run the sizing tool, review the Prerequisites section later in this article..

While domain controller performance may not be affected if the server doesn't have required resources, the Defender for Identity sensor may not operate as expected. For more information, see Microsoft Defender for Identity prerequisites.

Use the sizing tool

Use the following steps to run the sizing tool and review the results:

  1. Run the Defender for Identity sizing tool, TriSizingTool.exe, from the zip file you downloaded.

  2. When the tool finishes running, open the Excel file results.

Manual sizing estimation for domain controllers

If you're unable to use the Defender for Identity sizing tool described earlier in this article,Use the sizing tool, you can manually estimate whether your domain controller servers have enough resources for a Defender for Identity sensor instead.

Manually gather the packet/second counter information from all your domain controllers, over 24 hours with a low collection interval like 5 seconds. For each domain controller, calculate the daily average and the busiest period (15 minutes) average.