A security solution that detects identity-based threats and suspicious activities in on-premises Active Directory environments
Hello Kalel,
Yes,“Ready for migration” means that server is eligible to migrate from the Defender for Identity v2.x sensor to the v3.x sensor. In the portal, the Migration state column is specifically about v2.x → v3.x migration. Once it finishes, that state changes to Up to date, which means the server is now running sensor v3.x. That is separate from Sensor status, which only shows the update/configuration state of the currently installed sensor.
If you click Migrate, Microsoft says the migration is done directly from the Defender portal and typically takes up to 20 minutes. During that time, the v2.x sensor continues running until v3.x is ready, so monitoring stays in place without interruption and without data duplication.
So in normal circumstances, the impact to the domain controller should be low. Microsoft’s current guidance does not describe downtime for the migration itself. The only restart-related note I found is for the cleanup afterward: once migration is complete, the old v2.x software remains installed but disabled, and uninstalling that old v2.x sensor later might require a server restart.