Microsoft Defender for Identity Updates & Release Notes

Follow

16 updates curated from 1 source by the Releasebot Team. Last updated: Sep 1, 2026

Get this feed:
  • August 2026
    • Date parsed from source:
      Aug 1, 2026
    • First seen by Releasebot:
      Sep 1, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Sensor v2.x installation restriction for new workspaces

    Microsoft Defender for Identity restricts sensor v2.x installs in new workspaces to Windows Server 2016 or earlier.

    In new Defender for Identity workspaces, you can install sensor v2.x only on servers running Windows Server 2016 or earlier. This restriction applies to all server roles. Existing workspaces aren't affected. For more information, see Select your deployment method.

    Original source
  • August 2026
    • Date parsed from source:
      Aug 1, 2026
    • First seen by Releasebot:
      Aug 11, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Script to find GPO conflicts that revert auditing

    Microsoft Defender for Identity adds a read-only PowerShell script to find GPO conflicts that override automatic auditing settings.

    The new read-only Find-MdiAuditingGpoConflicts.ps1 PowerShell script identifies GPOs that override automatic auditing settings on a domain controller.

    You can use the results to update or unlink the conflicting GPOs.

    For more information, see Find GPO conflicts that revert automatic auditing.

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Microsoft and hundreds of other software products.

    Create account
  • August 2026
    • Date parsed from source:
      Aug 1, 2026
    • First seen by Releasebot:
      Aug 11, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Sensor v3.x support for AD FS, AD CS, and Microsoft Entra Connect servers

    Microsoft Defender for Identity now supports sensor v3.x deployment on AD FS, AD CS, and Microsoft Entra Connect servers.

    You can now deploy Defender for Identity sensor v3.x on servers that run Active Directory Federation Services (AD FS), Active Directory Certificate Services (AD CS), or Microsoft Entra Connect. These servers can be domain controllers or standalone servers. For more information, see Deploy the Defender for Identity sensor v3.x.

    Original source
  • August 2026
    • Date parsed from source:
      Aug 1, 2026
    • First seen by Releasebot:
      Aug 11, 2026
    • Modified by Releasebot:
      Aug 25, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Expanded automatic auditing for AD CS, AD FS and Entra Connect servers

    Microsoft Defender for Identity now automates Windows event auditing for AD FS, AD CS, and Entra Connect on eligible servers.

    Automatic Windows event auditing now configures auditing for AD FS, AD CS, and Microsoft Entra Connect.

    Auditing is configured automatically on any eligible server that runs Defender for Identity sensor v3.x, including servers that aren't domain controllers.

    For more information, see Configure Defender for Identity to collect Windows events automatically.

    Original source
  • August 2026
    • Date parsed from source:
      Aug 1, 2026
    • First seen by Releasebot:
      Jul 21, 2026
    • Modified by Releasebot:
      Aug 11, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    New health alert for reverted auditing configuration

    Microsoft Defender for Identity adds a health alert for conflicting policies that keep reverting required sensor v3.x auditing settings.

    A new Defender for Identity health alert notifies you when a conflicting policy, such as a Group Policy Object (GPO), repeatedly reverts the auditing configuration required by sensor v3.x on a domain controller. For more information, see Microsoft Defender for Identity health issues.

    Original source
  • Similar to Microsoft Defender for Identity with recent updates:

  • July 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Aug 11, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Defender for Identity sensor updates

    Microsoft Defender for Identity adds ETW provider support and other sensor improvements.

    This sensor update adds support for a new Event Tracing for Windows (ETW) provider and includes other improvements.

    Original source
  • July 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Jul 22, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Migrate Windows Server 2025 domain controllers to sensor v3.x

    Microsoft Defender for Identity now supports migrating Windows Server 2025 domain controllers from sensor v2.x to v3.x.

    You can now migrate domain controllers running Windows Server 2025 from sensor v2.x to sensor v3.x. For more information, see Migrate to Defender for Identity sensor v3.x.

    Original source
  • July 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Jul 22, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Migration readiness reasons on the Sensors page

    Microsoft Defender for Identity adds tooltips for Not ready for migration status to explain missing migration prerequisites.

    When a server is marked Not ready for migration on the Sensors page, you can now hover over the status to see a tooltip that lists the specific reasons the server doesn't meet the migration prerequisites. For more information, see Troubleshoot "Not ready for migration" status.

    Original source
  • July 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Sensor v2.x to v3.x migration is now generally available

    Microsoft Defender for Identity now supports migrating sensors from v2.x to v3.x with general availability.

    Migration of Defender for Identity sensors from v2.x to v3.x is now generally available. For more information, see Migrate to Defender for Identity sensor v3.x.

    Original source
  • July 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Expanded SaaS app support in Password protection (Preview)

    Microsoft Defender for Identity expands Password protection with SaaS app risks from Defender for Cloud Apps.

    The Password protection page now includes password risks from SaaS apps connected through Microsoft Defender for Cloud Apps, in addition to Active Directory, Microsoft Entra ID, and Okta. SaaS apps that support SaaS Security Posture Management (SSPM), such as Salesforce and ServiceNow, appear on the Password Hygiene and Password Policies tabs. Each SaaS app requires a Defender for Cloud Apps app connector. For more information, see Investigate identity password protection.

    Original source
  • July 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    • Modified by Releasebot:
      Sep 2, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    The Domain investigation page is now generally available

    Microsoft Defender for Identity launches the Domain investigation page for deeper Active Directory domain security insights.

    The Domain investigation page is now generally available.

    The Domain investigation page allows you to investigate an Active Directory domain. It shows Active Directory domain security, including domain properties, deployment health, identity summary, service account breakdown, sensitive entities, active recommendations, group policies, and trust relationships. For more information, see Investigate a domain.

    Original source
  • July 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Automatic RPC auditing on domain controllers

    Microsoft Defender for Identity now automatically enables RPC auditing on domain controllers after sensor version 3.0.8 upgrades.

    Defender for Identity now automatically enables RPC auditing on domain controllers when you upgrade to sensor version 3.0.8 or later.

    You no longer need to apply a tag manually to enable RPC auditing.

    For more information, see Configure RPC auditing.

    Original source
  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    Identity risk score is now generally available

    Microsoft Defender for Identity introduces a generally available identity risk score with breakdowns, percentile comparisons, and trends.

    The identity risk score is now generally available.

    The score ranges from 0 to 100 and reflects how likely an identity is to be compromised and how much damage a compromise could cause, based on the identity's criticality level and privileged role assignments.

    The Risk score tab on the Identity page provides a detailed breakdown of risk factors, percentile comparison, and risk trends.

    Original source
  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    New Defender for Identity security alerts

    Microsoft Defender for Identity adds new security alerts across Entra ID, Active Directory, and other identity providers, including detections for suspicious sign-ins, bulk deletion activity, DCSync attacks, Entra Connect authentication, and SailPoint ISC brute-force attempts.

    These new alerts were added to the Defender for Identity security alerts:

    New alerts related to Entra ID:

    • Anomalous activity following Global Administrator elevation
    • Reciprocal Temporary Access Pass creation between users
    • Suspicious service principal sign-in following credential addition
    • Suspicious bulk user deletion via scripted activity
    • Suspicious removal of privileged app role assignment through Graph API
    • Suspicious sign-in by a user exhibiting a spike in account update activity
    • User exhibiting spike in distinct application-resource access combinations

    New alerts related to Active Directory:

    • DCSync attack (replication of directory services)
    • Suspicious Entra Connect account authentication

    New alerts related to other identity providers:

    • SailPoint ISC suspected brute-force attack
    Original source
  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender for Identity by Microsoft

    NHI inventory enhancements (Preview)

    Microsoft Defender for Identity expands Entra ID inventory and shows Microsoft Entra roles in the Permissions tab.

    • Expanded Entra ID inventory: The non-human identity inventory now includes all Microsoft Entra service principals, not just those with API permissions. For more information, see View the Identity inventory.

    • Microsoft Entra roles visibility: The Permissions tab now shows assigned Microsoft Entra roles alongside API permissions. For more information, see View your app details with app governance.

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.