Note
Kailangan ng pahintulot para ma-access ang page na ito. Maaari mong subukang mag-sign in o magpalit ng mga direktoryo.
Ang pag-access sa pahinang ito ay nangangailangan ng pahintulot. Maaari mong subukang baguhin ang mga direktoryo.
For complete protection of your on-premises deployment, activate the Defender for Identity sensor on all applicable servers. Onboard domain controllers running Windows Server 2019 or later, including domain controllers that also run AD FS, AD CS, or Microsoft Entra Connect roles. For domain controllers running older operating systems, or for AD FS, AD CS, and Microsoft Entra Connect servers that aren't domain controllers, deploy the Defender for Identity sensor v2.x instead.
Prerequisites
See Microsoft Defender for Identity sensor v3.x prerequisites for system requirements and Sensor version limitations for supported scenarios before proceeding with activating the Defender for Identity sensor on eligible domain controllers.
Review the Activation page
The Activation page displays all servers from your device inventory. Defender for Identity detects all of your servers and their configuration. Each server's activation state lets you know what you need to do to onboard the corresponding domain controller to Defender for Identity.
You can choose to activate eligible domain controllers either automatically, where Defender for Identity activates them as soon as they're discovered, or manually, by selecting specific domain controllers from the list of eligible servers.
| Activation State | Next steps |
|---|---|
| Activate new sensor | The domain controller is already onboarded to Defender for Endpoint. Activate the sensor. |
| Install classic sensor | Deploy the classic Defender for Identity sensor from the Sensors page. |
| OS upgrade is required | This domain controller is running an unsupported operating system version for the new sensor. Upgrade the OS version to the latest version. |
Activate the Defender for Identity sensor
Perform the following steps to activate the Defender for Identity sensor on a domain controller:
In the Microsoft Defender portal, go to System > Settings > Identities > Activation.
Select the domain controller where you want to activate Defender for Identity, and select Activate. Confirm your selection when prompted.
When sensor activation for the selected domain controller is complete, a green success banner appears. In the green success banner, select Click here to see the onboarded servers. Selecting Click here to see the onboarded servers takes you to the Sensors page, where you can check your sensor health.
Confirm sensor activation
To confirm the sensor is working:
- In the Microsoft Defender portal, go to System > Settings > Identities > Sensors.
- Check that the activated domain controller is listed.
Note
The first time you activate the Defender for Identity sensor on your domain controller, it might take up to an hour for the first sensor to show as Running on the Sensors page. Subsequent activations are shown within five minutes. The activation doesn't require a restart/reboot.

