You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: ATPDocs/deploy/activate-capabilities.md
+8-8Lines changed: 8 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -88,7 +88,7 @@ Activate the Defender for Identity from the [Microsoft Defender portal](https://
88
88
1. Select the domain controller where you want to activate the Defender for Identity capabilities and then select **Activate**. Confirm your selection when prompted.
89
89
90
90
:::image type="content" source="media/activate-capabilities/1.jpg" lightbox="media/activate-capabilities/1.jpg" alt-text="Screenshot that shows how to activate the new sensor.":::
91
-
91
+
92
92
> [!NOTE]
93
93
> You can choose to activate eligible domain controllers either automatically, where Defender for Identity activates them as soon as they're discovered, or manually, where you select specific domain controllers from the list of eligible servers.
94
94
@@ -112,11 +112,11 @@ Download the Defender for Identity onboarding package from the [Microsoft Defend
112
112
113
113
1. Select Download onboarding package and save the file in a location you can access from your domain controller.
114
114
115
-
:::image type="content" source="media/activate-capabilities/screenshot-that-shows-how-to-onboard-the-new-sensor..png" alt-text="Screenshot that shows how to onboard the new sensor" lightbox="media/activate-capabilities/screenshot-that-shows-how-to-onboard-the-new-sensor..png":::
115
+
:::image type="content" source="media/activate-capabilities/screenshot-that-shows-how-to-onboard-the-new-sensor.png" alt-text="Screenshot that shows how to onboard the new sensor" lightbox="media/activate-capabilities/screenshot-that-shows-how-to-onboard-the-new-sensor.png":::
116
116
117
117
1. From the domain controller, extract the zip file you downloaded from the Microsoft Defender portal, and run the `DefenderForIdentityOnlyOnboardingScript.cmd` script as an Administrator.
118
118
119
-
:::image type="content" source="media/activate-capabilities/screenshot-that-shows-the-script..png" alt-text="Screenshot that shows the script." lightbox="media/activate-capabilities/screenshot-that-shows-the-script..png":::
119
+
:::image type="content" source="media/activate-capabilities/screenshot-that-shows-the-script.png" alt-text="Screenshot that shows the script." lightbox="media/activate-capabilities/screenshot-that-shows-the-script.png":::
120
120
121
121
## Onboarding Confirmation
122
122
@@ -131,7 +131,7 @@ To confirm the sensor has been onboarded:
131
131
132
132
To check the onboarding on the local server you can also review the event log under **Applications and Services Logs** > **Microsoft** > **Windows** > **Sense** > **Operational**. You should receive an onboarding event:
133
133
134
-
:::image type="content" source="media/activate-capabilities/screenshot-that-shows-the-eventlog..png" alt-text="Screenshot that shows the eventlog" lightbox="media/activate-capabilities/screenshot-that-shows-the-eventlog..png":::
134
+
:::image type="content" source="media/activate-capabilities/screenshot-that-shows-the-eventlog.png" alt-text="Screenshot that shows the eventlog" lightbox="media/activate-capabilities/screenshot-that-shows-the-eventlog.png":::
135
135
136
136
**Test activated capabilities**
137
137
@@ -245,23 +245,23 @@ If you want to deactivate Defender for Identity capabilities on your domain cont
245
245
1. Navigate to **Settings** > **Identities** > **Sensors**.
246
246
1. Select the domain controller where you want to deactivate Defender for Identity capabilities, select **Delete**, and confirm your selection.
247
247
248
-

248
+

249
249
250
250
Deactivating Defender for Identity capabilities from your domain controller doesn't remove the domain controller from Defender for Endpoint. For more information, see [Defender for Endpoint documentation](/microsoft-365/security/defender-endpoint/).
251
251
252
252
### Customers without domain controllers onboarded to Defender for Endpoint
253
253
254
254
### Offboard Defender for Identity capabilities on your domain controller
255
-
Download the Defender for Identity offboarding package from the [Microsoft Defender portal](https://security.microsoft.com).
255
+
Download the Defender for Identity offboarding package from the [Microsoft Defender portal](https://security.microsoft.com).
256
256
257
257
1. Navigate to **Settings** > **Identities** > **Activation**
258
258
259
259
1. Select Download offboarding package and save the file in a location you can access from your domain controller.
260
-

260
+

261
261
1. From the domain controller, extract the zip file you downloaded from the Microsoft Defender portal, and run the `DefenderForIdentityOnlyOffboardingScript_valid_until_YYYY-MM-DD.cmd` script as an Administrator.
262
262
1. To fully remove the sensor, navigate to **Settings** > **Identities** > **Sensors**, select the server and click **Delete**.
263
263
264
-
:::image type="content" source="media/activate-capabilities/screenshot-that-shows-how-to-delete-a-sensor..png" alt-text="Screenshot that shows how to delete a sensor" lightbox="media/activate-capabilities/screenshot-that-shows-how-to-delete-a-sensor..png":::
264
+
:::image type="content" source="media/activate-capabilities/screenshot-that-shows-how-to-delete-a-sensor.png" alt-text="Screenshot that shows how to delete a sensor" lightbox="media/activate-capabilities/screenshot-that-shows-how-to-delete-a-sensor.png":::
0 commit comments