Edit

Activate the Microsoft Defender for Identity sensor v3.x

For complete protection of your on-premises deployment, activate the Microsoft Defender for Identity sensor v3.x on all eligible servers. Supported server types include domain controllers. They also include Active Directory Federation Services (AD FS), Active Directory Certificate Services (AD CS), and Microsoft Entra Connect servers that aren't domain controllers. Eligible servers must meet the sensor v3.x prerequisites, including Windows Server 2019 or later. For supported servers running older operating systems, deploy the Defender for Identity sensor v2.x instead.

Note

Activating the Defender for Identity sensor v3.x on AD FS, AD CS, and Microsoft Entra Connect servers that aren't domain controllers is in preview.

Prerequisites

See Microsoft Defender for Identity sensor v3.x prerequisites for system requirements and Sensor version limitations for supported scenarios before activating the Defender for Identity sensor v3.x on eligible servers.

Turn on automatic sensor activation

Automatic activation applies only to eligible domain controllers onboarded to Defender for Endpoint.

To turn on automatic sensor activation:

  1. In the Microsoft Defender portal, go to Settings > Identities > Advanced features.
  2. Turn on Automatic sensor v3.x activation.

The Advanced features page also includes Automatic Windows auditing configuration. For details, see Configure automatic Windows event auditing.

Activate the Defender for Identity sensor v3.x

To activate the Defender for Identity sensor v3.x on an eligible server, follow these steps:

  1. On the Sensor management tab of the On-premises page in the Microsoft Defender portal, select the eligible server where you want to activate Defender for Identity.

  2. Select Activate, and confirm your selection when prompted.

  3. When v3.x sensor activation for the selected server is complete, a green success banner appears. In the banner, select Click here to see the onboarded servers. The Sensor management tab opens, where you can check the sensor's health.

    Screenshot of the successful sensor activation banner with a link to view onboarded servers.

Onboard a domain controller without Defender for Endpoint deployment (preview)

Use onboarding without Defender for Endpoint deployment to activate the Defender for Identity sensor v3.x without first onboarding the domain controller to Defender for Endpoint:

Important

This onboarding method supports new sensor v3.x deployments on eligible domain controllers that don't have sensor v2.x installed.

  1. Configure your network environment to ensure connectivity with Defender for Endpoint by using streamlined URLs.

  2. On the Sensor management tab of the On-premises page in the Microsoft Defender portal, select Download onboarding package.

  3. In the Download onboarding package pane, expand Windows Server 2019 or later, enter a Package name, and select Generate package.

    Screenshot of the Download onboarding package pane with package name and Generate package options for Windows Server 2019 or later.

  4. When the package is ready, download it and copy the access key.

    Important

    The access key is used only during sensor installation. Regenerating the key invalidates the existing key, and installations that use the previous key fail.

  5. Copy the downloaded package to the domain controller.

  6. Extract the package, making sure the resources subfolder is preserved.

  7. Open PowerShell as an administrator, change to the extracted folder, and run the onboarding script:

    Set-Location .\DfiOnboarding
    .\DefenderForIdentityV3StandaloneOnboardingScript.cmd
    
  8. When prompted, enter the access key from the Microsoft Defender portal. The input is masked.

Confirm sensor activation

To confirm that the v3.x sensor is working:

  1. On the Sensor management tab of the On-premises page in the Microsoft Defender portal, check that the activated server is listed.

Note

The first Defender for Identity sensor v3.x activation in your environment might take up to an hour to show as Running on the Sensor management tab. Subsequent activations appear within five minutes. Activation doesn't require a restart.

What if I want to add Defender for Endpoint later?

If you onboarded a domain controller with Defender for Identity only and now want to add Defender for Endpoint, follow these steps:

  1. Offboard the domain controller and remove the sensor.
  2. Onboard the domain controller to Defender for Endpoint.
  3. After the domain controller appears on the Sensor management tab, activate the Defender for Identity sensor v3.x.

Next step