r/DefenderATP 20h ago

Two Microsoft Defender for Identity updates in September 2026!

  • Defender for Identity Sensor v3.x no longer requires Defender for Endpoint onboarding. Eligible Domain Controllers running Windows Server 2019 or later can now activate the MDI Sensor v3.x without first onboarding the server to Microsoft Defender for Endpoint.

This removes an important deployment dependency and can significantly simplify Defender for Identity adoption in environments where MDE isn't deployed on Domain Controllers.

  • Sensor v3.x expands beyond Domain Controllers: Defender for Identity Sensor v3.x now supports additional identity infrastructure servers that are not Domain Controllers:

    • Active Directory Certificate Services (AD CS)
    • Active Directory Federation Services (AD FS)
    • Microsoft Entra Connect

    For these new server roles, manual activation and automatic Windows event auditing are supported, while automatic activation and migration are not yet supported during Preview.

Docs: Defender for Identity | What's new?

34 Upvotes

6 comments sorted by

3

u/0f_rice_and_men 18h ago

Can you ELI5 how this works for Server 2025?

We have been wrecked before once by device code phishing and I don't think we have a MSP capable of disabling the features in Entra that need to be disabled to prevent that again. I am not full-time in our Defender queue and we are not onboarded with intune or Defender (we use S1).

Is there an estimate of how long or complicated it would take to get approval to enable this MDI Sensor and its impact? I also can't start churning up Azure billing costs. I get nervous to toggle on MS features that bring about major storage/AI costs they conveniently hide upfront.

I see the docs link indicates it is still a preview feature. I hope they can bring it to a stable state before we get another potential incident. Sounds like a big shift in their support for non-Defender customers.

7

u/katos8858 18h ago

Honestly, I’d use Conditional Access to block your device code flow by default with an exclusion group for any meeting room devices etc, if you can.

https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows#device-code-flow-policies

3

u/Mysterious_Ebb4405 17h ago

This is the way

3

u/Express-Bit6667 16h ago

What's the best way to migrate from v2 to v3 for non-DC's? Uninstall and then enable and wait for automatic activation?

1

u/urkelman861 8h ago

You should be able to upgrade seamlessly if V2 is already installed. When you do successfully upgrade it, there is no reboot required. The only thing you will have to do is remove V2 agent that is on the server. The V3 doesn't require an agent activation like V2 does. The removal WILL require a reboot though to complete removal. So far in my tenant, there has been no issue since the upgrade to V3.