Microsoft Defender for Identity
Identity protection

Microsoft Defender for Identity health issues

In brief

The health alerts article revision date changed, and the Sensor v3.x RPC Audit Misconfigured entry now includes resolution guidance, including verifying the Unified Sensor RPC Audit configuration.

What Defender admins need to know

No action is required solely due to this update. Administrators troubleshooting this alert should use the added resolution steps.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Microsoft Defender for Identity health issues description: Learn about health issues in Microsoft Defender for Identity, including causes and resolution steps for sensor and domain-related alerts. ms.date: 08/10/09/06/2026 ms.topic: how-to ms.reviewer: rlitinsky ai-usage: ai-assisted |Radius accounting (VPN integration) data ingestion failures|The listed Defender for Identity sensors have radius accounting (VPN integration) data ingestion failures.|Validate that the shared secret in the Defender for Identity configuration settings matches your VPN server, according to the guidance described Configure VPN in Defender for Identity section, in the Defender for Identity VPN integration page.|Low|Health issues page|2.x| |Auditing for AD CS servers isn't enabled as required|The Advanced Auditing Policy Configuration or AD CS auditing isn't enabled as required. (This configuration is validated once a day, per sensor.)|Enable the Advanced Auditing Policy Configuration and AD CS auditing according to the guidance as described in the Configure auditing on AD CS section, in the Configure Windows Event collection page.|Medium|Sensors health issues tab|2.x| |Sensor failed to retrieve Microsoft Entra Connect service configuration|The sensor is unable to retrieve the configuration from the Microsoft Entra Connect service (also known as Microsoft Azure AD sync).|Ensure that the Microsoft Entra connect service (Microsoft Azure AD Sync) is running and follow the instructions in Configure permissions for the Microsoft Entra Connect (ADSync) database to grant the sensor the necessary permissions. If the issue persists, follow the troubleshooting guidance at SQL connectivity issues with Microsoft Entra Connect.|Medium|Sensors health issues tab|2.x| |Sensor v3.x RPC Audit Misconfigured|The sensor is missing the required Unified Sensor RPC Audit configuration tag, or the tag was not applied correctly.|This issue affectsTo resolve this issue, do one of the sensor's ability to enable enhanced RPC auditing, which is required for certain advanced identity detections on v3.x sensors. Without this configuration, some identity-based detections might not function, reducing Defender for Identity's visibility into suspicious activities.following:

- Verify that the Unified Sensor RPC Audit configuration is correctly applied to the relevant devices by following the instructions at Configure RPC auditing.devices. Once the tag is applied, the configuration is enforced automatically on matching devices, restoring full detection capability. Fromdevices.
- Install the July 2026 or later Windows cumulative update to upgrade the Defender for Identity sensor to version 3.0.8 or later. In sensor version 3.0.8,8 or later, RPC auditing is enabled automatically when the sensor is upgraded, soapplied automatically, and the tag is no longer required.

For more information, see Configure RPC auditing.|Medium|Sensors health issues tab|3.x|