Deploying MDI to multiple On-premise DC for monitoring purposes

Bry Ozark 0 Reputation points
2024-02-15T04:54:24.4166667+00:00

Hello Team,

When deploying MDI to all my on-premise domain controllers for monitoring purposes. Do I need to add new sensors for each dc? or can I use the package and access key from one sensor to all my dc's? Thank you!

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,055 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
165 questions
{count} votes

1 answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,496 Reputation points Microsoft Employee
    2024-02-15T18:31:00.43+00:00

    @Bry Ozark

    Thank you for your post!

    Based off my research, when it comes to deploying the Microsoft Defender for Identity (MDI) sensor(s), it's recommended that you have a Defender for Identity sensor or standalone sensor for each one of your domain controllers. This'll ensure accurate and effective monitoring of each domain controller and its associated network traffic, as each sensor is designed to monitor a specific domain controller.

    For more information, see Defender for Identity sensor sizing. User's image

    Additional Links:

    I hope this helps!

    If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.