What's new | Microsoft Defender for Identity
In brief
The August 2026 documentation describes automatic auditing for eligible AD FS, AD CS, and Microsoft Entra Connect servers running sensor v3.x, sensor version 2.255.19295.47272, Windows Server 2025 domain controller migration to sensor v3.x, and migration-readiness reasons on the Sensors page.
What Defender admins need to know
Administrators can use expanded automatic auditing, migrate supported Windows Server 2025 domain controllers, and identify migration blockers more easily. No required action is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
What's new in Microsoft Defender for Identity
For updates about versions and features released six months ago or earlier, see the What's new archive for Microsoft Defender for Identity.
August 2026
Expanded automatic auditing for AD CS, AD FS and Entra Connect servers
Automatic Windows event auditing now configures auditing for AD FS, AD CS, and Microsoft Entra Connect. Auditing is configured automatically on any eligible server that runs Defender for Identity sensor v3.x, including servers that aren't domain controllers. For more information, see Configure Defender for Identity to collect Windows events automatically.
July 2026
Defender for Identity sensor updates
| Version number | Updates |
|---|---|
| 2.255.19295.47272 | This sensor update adds support for a new Event Tracing for Windows (ETW) provider and includes other improvements. |
Sensor v2.x to v3.x migration is now generally available
Migration of Defender for Identity sensors from v2.x to v3.x is now generally available. For more information, see Migrate to Defender for Identity sensor v3.x.
Migrate Windows Server 2025 domain controllers to sensor v3.x
You can now migrate domain controllers running Windows Server 2025 from sensor v2.x to sensor v3.x. For more information, see Migrate to Defender for Identity sensor v3.x.
Migration readiness reasons on the Sensors page
When a server is marked Not ready for migration on the Sensors page, you can now hover over the status to see a tooltip that lists the specific reasons the server doesn't meet the migration prerequisites. For more information, see Troubleshoot "Not ready for migration" status.
Expanded SaaS app support in Password protection (Preview)
The Password protection page now includes password risks from SaaS apps connected through Microsoft Defender for Cloud Apps, in addition to Active Directory, Microsoft Entra ID, and Okta. SaaS apps that support SaaS Security Posture Management (SSPM), such as Salesforce and ServiceNow, appear on the Password Hygiene and Password Policies tabs. Each SaaS app requires a Defender for Cloud Apps app connector. For more information, see Investigate identity password protection.
- Failed credential abuse attempt in Entra ID authentication
- Malicious sign in from a randomized user agent
- Possible use of a stolen session cookie
Stolen session cookie replay detected- Suspected Conditional Access bypass via non-compliant device
- Suspicious addition of default third-party MFA method to user account
@@ -1,11 +1,12 @@ --- title: What's new | Microsoft Defender for Identity description: This article is updated frequently to let you know what's new in the latest release of Microsoft Defender for Identity.-ms.date: 07/15/2026+ms.date: 08/12/2026 ms.topic: overview-#CustomerIntent: As a Defender for Identity customer, I want to know what's new in the latest release of Defender for Identity, so that I can take advantage of new features and functionality.+#customer intent: As a Defender for Identity customer, I want to know what's new in the latest release of Defender for Identity so that I can take advantage of new features and functionality. ms.reviewer: AbbyMSFT-ms.custom: sfi-image-nochange+ms.custom: sfi-image-nochange, msecd-doc-authoring-1016+ai-usage: ai-assisted --- # What's new in Microsoft Defender for Identity@@ -24,12 +25,32 @@ For more information, see also: For updates about versions and features released six months ago or earlier, see the [What's new archive for Microsoft Defender for Identity](whats-new-archive.md). +## August 2026++### Expanded automatic auditing for AD CS, AD FS and Entra Connect servers++Automatic Windows event auditing now configures auditing for AD FS, AD CS, and Microsoft Entra Connect. Auditing is configured automatically on any eligible server that runs Defender for Identity sensor v3.x, including servers that aren't domain controllers. For more information, see [Configure Defender for Identity to collect Windows events automatically](deploy/configure-windows-event-collection.md#configure-defender-for-identity-to-collect-windows-events-automatically).+ ## July 2026 +### Defender for Identity sensor updates++|Version number|Updates|+|---|---|+|2.255.19295.47272|This sensor update adds support for a new Event Tracing for Windows (ETW) provider and includes other improvements.|+ ### Sensor v2.x to v3.x migration is now generally available Migration of Defender for Identity sensors from v2.x to v3.x is now generally available. For more information, see [Migrate to Defender for Identity sensor v3.x](deploy/migrate-to-sensor-v3.md). +### Migrate Windows Server 2025 domain controllers to sensor v3.x++You can now migrate domain controllers running Windows Server 2025 from sensor v2.x to sensor v3.x. For more information, see [Migrate to Defender for Identity sensor v3.x](deploy/migrate-to-sensor-v3.md).++### Migration readiness reasons on the Sensors page++When a server is marked **Not ready for migration** on the **Sensors** page, you can now hover over the status to see a tooltip that lists the specific reasons the server doesn't meet the migration prerequisites. For more information, see [Troubleshoot "Not ready for migration" status](deploy/migrate-to-sensor-v3.md#troubleshoot-not-ready-for-migration-status).+ ### Expanded SaaS app support in Password protection (Preview) The Password protection page now includes password risks from SaaS apps connected through Microsoft Defender for Cloud Apps, in addition to Active Directory, Microsoft Entra ID, and Okta. SaaS apps that support SaaS Security Posture Management (SSPM), such as Salesforce and ServiceNow, appear on the Password Hygiene and Password Policies tabs. Each SaaS app requires a Defender for Cloud Apps app connector. For more information, see [Investigate identity password protection](password-protection.md).@@ -101,7 +122,6 @@ These new alerts were added to the Defender for Identity security alerts: - [Failed credential abuse attempt in Entra ID authentication](alerts-xdr.md#failed-credential-abuse-attempt-in-entra-id-authentication) - [Malicious sign in from a randomized user agent](alerts-xdr.md#malicious-sign-in-from-a-randomized-user-agent) - [Possible use of a stolen session cookie](alerts-xdr.md#possible-use-of-a-stolen-session-cookie)-- [Stolen session cookie replay detected](alerts-xdr.md#stolen-session-cookie-replay-detected) - [Suspected Conditional Access bypass via non-compliant device](alerts-xdr.md#suspected-conditional-access-bypass-via-non-compliant-device) - [Suspicious addition of default third-party MFA method to user account](alerts-xdr.md#suspicious-addition-of-default-thirdparty-mfa-method-to-user-account) 