Skip to content

Commit 4629941

Browse files
Merge pull request #5037 from MicrosoftDocs/main
[AutoPublish] main to live - 09/14 22:31 PDT | 09/15 11:01 IST
2 parents eb617d9 + cb5b854 commit 4629941

File tree

2 files changed

+2
-5
lines changed

2 files changed

+2
-5
lines changed

defender-for-identity/deploy/prerequisites-sensor-version-3.md

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -41,17 +41,14 @@ The following table summarizes the server requirements and recommendations for t
4141

4242
|Prerequisite / Recommendation |Description |
4343
|---------|---------|
44-
|Operating System|The domain controller must have both:<br> - Windows Server 2019 or later<br> - [March 2024 Cumulative Update](https://support.microsoft.com/topic/march-12-2024-kb5035857-os-build-20348-2340-a7953024-bae2-4b1a-8fc1-74a17c68203c) or later.|
44+
|Operating System|The domain controller must have both:<br> - Windows Server 2019 or later<br> - [June 2025 Cumulative Update](https://support.microsoft.com/en-us/topic/june-10-2025-kb5060526-os-build-20348-3807-4e9453c4-6602-48ea-b349-689cd66dfdb9) or later.|
4545
|Specifications| A domain controller server with a minimum of:<br> - two cores<br>- 6 GB of RAM|
4646
|Performance| For optimal performance, set the **Power Option** of the machine running the Defender for Identity sensor to **High Performance**. |
4747
|Connectivity|Requires a Microsoft Defender for Endpoint deployment. If Microsoft Defender for Endpoint is installed on the domain controller, there are no additional connectivity requirements. |
4848
|Previous installations| Before activating the sensor on a domain controller, make sure that the domain controller doesn't have another Defender for Identity sensor already deployed.|
4949
|Server time synchronization|The servers and domain controllers onto which the sensor is installed must have time synchronized to within five minutes of each other.|
5050
|ExpressRoute|This version of the sensor doesn't support ExpressRoute. If your environment uses ExpressRoute, we recommend [deploying the Defender for Identity sensor v2.x](install-sensor.md).|
5151

52-
> [!NOTE]
53-
> After the March 2024 Cumulative Update is installed, LSASS might experience a memory leak on domain controllers during on-premises and cloud-based Active Directory Domain Controllers service Kerberos authentication requests. [This out-of-band update: KB5037422](https://support.microsoft.com/en-gb/topic/march-22-2024-kb5037422-os-build-20348-2342-out-of-band-e8f5bf56-c7cb-4051-bd5c-cc35963b18f3) addresses this issue.
54-
5552
### Dynamic memory requirements
5653

5754
The following table describes memory requirements on the server used for the Defender for Identity sensor, depending on the type of virtualization you're using:

defender-for-identity/deploy/test-connectivity.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ For more information, see [Required ports](../prerequisites.md#ports).
2929
> [!IMPORTANT]
3030
> You must specify `HTTPS`, not `HTTP`, to properly test connectivity.
3131
32-
**Result**: You should get an *Ok* message displayed (HTTP status 200) and the latest sensor version number, which indicates you were successfully able to route to the Defender for Identity HTTPS endpoint. This is the desired result.
32+
**Result**: You should get the latest sensor version number, which indicates you were successfully able to route to the Defender for Identity HTTPS endpoint. This is the desired result.
3333

3434
For some older workspaces, the message returned could be *Error 503 The service is unavailable*. This is a temporary state that still indicates success. For example:
3535

0 commit comments

Comments
 (0)