Skip to content

Commit 4fc8f15

Browse files
Merge branch 'main' into WI344597-remove-mandatory-nss
2 parents d1ac1eb + ff4d799 commit 4fc8f15

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

defender-for-identity/deploy/prerequisites-sensor-version-3.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,6 @@ For more information, see [Licensing and privacy FAQs](/defender-for-identity/te
3434
- You must either be a [Security Administrator](/entra/identity/role-based-access-control/permissions-reference), or have the following [Unified RBAC](../role-groups.md#unified-role-based-access-control-rbac) permissions:
3535
- `System settings (Read and manage)`
3636
- `Security setting (All permissions)`
37-
- We recommend using at least one Directory Service account, with read access to all objects in the monitored domains. For more information, see [Configure a Directory Service account for Microsoft Defender for Identity](directory-service-accounts.md).
3837

3938
## Sensor requirements and recommendations
4039

@@ -49,6 +48,7 @@ The following table summarizes the server requirements and recommendations for t
4948
|Connectivity|Requires a Microsoft Defender for Endpoint deployment. If Microsoft Defender for Endpoint is installed on the domain controller, there are no additional connectivity requirements. |
5049
|Server time synchronization|The servers and domain controllers onto which the sensor is installed must have time synchronized to within five minutes of each other.|
5150
|ExpressRoute|This version of the sensor doesn't support ExpressRoute. If your environment uses ExpressRoute, we recommend [deploying the Defender for Identity sensor v2.x](install-sensor.md).|
51+
|Identity and response actions|The sensor doesn't require credentials to be provided in the portal. Even if credentials are entered, the sensor uses the **Local System identity** on the server to query Active Directory and perform response actions. If a **Group Managed Service Account (gMSA)** is configured for response actions, the response actions are disabled. |
5252

5353
### Dynamic memory requirements
5454

0 commit comments

Comments
 (0)