Microsoft Defender for Identity
Identity protection

Troubleshooting known issues

In brief

The article now identifies two affected alerts involving the ADFS and Configuration containers, clarifies that the issue affects sensor v3.x environments, and adds a Microsoft Defender portal resolution path.

What Defender admins need to know

Administrators can use the updated alert details and portal guidance when troubleshooting; detections remain unaffected.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Troubleshooting known issues description: Describes how you can troubleshoot issues in Microsoft Defender for Identity. ms.date: 09/02/04/2026 ms.topic: troubleshooting ms.reviewer: rlitinsky ms.custom:

If permissions need to be reconfigured, follow the steps outlined in this guide.

Auditing health alerts persist on sensor v3v3.x

In some v3environments running Microsoft Defender for Identity sensor environments, auditingv3.x, the following health alerts mightmay persist even when Windows auditing is correctly configured. configured correctly:

  • Auditing on the ADFS container is not enabled as required
  • Auditing on the Configuration container is not enabled as required

This issue primarily occurs with manualin environments that configure auditing configuration,manually, such as usingthrough Group Policy or PowerShell. The sensor remains healthyhealthy, and detections aren't affected. To resolve,resolve the issue, in the Microsoft Defender portal, go to Settings > Identities > Advanced features, and enable Automatic Windows auditing configuration. This issue is expected to be resolved in the Defender for Identity portal under Settings > Advanced features.a future sensor update.

Next steps