Microsoft Defender for Identity
Identity protection

What's new | Microsoft Defender for Identity

In brief

The August 2026 documentation describes automatic auditing for eligible AD FS, AD CS, and Microsoft Entra Connect servers running sensor v3.x, sensor version 2.255.19295.47272, Windows Server 2025 domain controller migration to sensor v3.x, and migration-readiness reasons on the Sensors page.

What Defender admins need to know

Administrators can use expanded automatic auditing, migrate supported Windows Server 2025 domain controllers, and identify migration blockers more easily. No required action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

What's new in Microsoft Defender for Identity

For updates about versions and features released six months ago or earlier, see the What's new archive for Microsoft Defender for Identity.

August 2026

Expanded automatic auditing for AD CS, AD FS and Entra Connect servers

Automatic Windows event auditing now configures auditing for AD FS, AD CS, and Microsoft Entra Connect. Auditing is configured automatically on any eligible server that runs Defender for Identity sensor v3.x, including servers that aren't domain controllers. For more information, see Configure Defender for Identity to collect Windows events automatically.

July 2026

Defender for Identity sensor updates

Version numberUpdates
2.255.19295.47272This sensor update adds support for a new Event Tracing for Windows (ETW) provider and includes other improvements.

Sensor v2.x to v3.x migration is now generally available

Migration of Defender for Identity sensors from v2.x to v3.x is now generally available. For more information, see Migrate to Defender for Identity sensor v3.x.

Migrate Windows Server 2025 domain controllers to sensor v3.x

You can now migrate domain controllers running Windows Server 2025 from sensor v2.x to sensor v3.x. For more information, see Migrate to Defender for Identity sensor v3.x.

Migration readiness reasons on the Sensors page

When a server is marked Not ready for migration on the Sensors page, you can now hover over the status to see a tooltip that lists the specific reasons the server doesn't meet the migration prerequisites. For more information, see Troubleshoot "Not ready for migration" status.

Expanded SaaS app support in Password protection (Preview)

The Password protection page now includes password risks from SaaS apps connected through Microsoft Defender for Cloud Apps, in addition to Active Directory, Microsoft Entra ID, and Okta. SaaS apps that support SaaS Security Posture Management (SSPM), such as Salesforce and ServiceNow, appear on the Password Hygiene and Password Policies tabs. Each SaaS app requires a Defender for Cloud Apps app connector. For more information, see Investigate identity password protection.