Microsoft Defender for Identity
Troubleshooting

Troubleshoot the Defender for Identity sensor using logs

In brief

The page now uses clearer descriptions of sensor and deployment logs, including their locations, archived-file handling, and troubleshooting use cases.

What Defender admins need to know

Admins can more easily locate and interpret logs when investigating sensor installation or runtime issues. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Troubleshooting Microsoft Defender for Identity sensor using the Defender for Identity logs

The Defender for Identity logs provide insight into what each component of Microsoft Defender for Identity sensor is doingactivity and status at any given point in time.

The Defender for Identity sensor logs are located in a subfolder calledthe Logs where Defender for Identitysubfolder under the sensor installation directory. By default, the sensor is installed; the default location is:installed in C:\Program Files\Azure Advanced Threat Protection Sensor. In the default installation location,, and the Logs folder can be found at: C:\Program Files\Azure Advanced Threat Protection Sensor\version number\Logs.

Defender for Identity sensor logs

  • Microsoft.Tri.Sensor.Updater-Errors.log – This log contains just the errors that are caught by the Defender for Identity sensor updater. Its main use is performing health checks and investigating issues that need to be correlated to specific times.

Defender for Identity deployment logs

The Defender for Identity deployment logs are located in the temp directory of the user who installed the product. Typically, you can find these logs at %USERPROFILE%\AppData\Local\Temp. If the deployment was performed by a service, the deployment logs might be located in C:\Windows\Temp or C:\Windows\SystemTemp, depending on your Windows version and patch level.

Defender for Identity sensor deployment logs:

  • Azure Advanced Threat Protection Sensor_YYYYMMDDHHMMSS_001_MsiPackage.log - This log file lists the steps in the process of the deployment of the Defender for Identity sensor binaries. Its main use is tracking the deployment of the Defender for Identity sensor binaries.

Related content