Skip to content

Commit 7148383

Browse files
committed
Learn Editor: Update activate-capabilities.md
1 parent 7266751 commit 7148383

File tree

4 files changed

+9
-5
lines changed

4 files changed

+9
-5
lines changed

ATPDocs/deploy/activate-capabilities.md

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -88,20 +88,23 @@ Activate the Defender for Identity from the [Microsoft Defender portal](https://
8888

8989
The Activation page lists servers discovered in Device Inventory and identified as eligible domain controllers.
9090

91-
2. Select the domain controller where you want to activate the Defender for Identity capabilities and then select **Activate**. Confirm your selection when prompted.
91+
1. Select the domain controller where you want to activate the Defender for Identity capabilities and then select **Activate**. Confirm your selection when prompted.
9292

93-
> [!NOTE]
93+
![Activation Defensor.](media/activate-capabilities/1.png)
94+
95+
> [!NOTE]
9496
> You can choose to activate eligible domain controllers either automatically, where Defender for Identity activates them as soon as they are discovered, or manually, where you select specific domain controllers from the list of eligible servers.
9597
96-
3. When the activation is complete, a green success banner shows. In the banner, select **Click here to see the onboarded servers** to jump to the **Settings > Identities > Sensors** page, where you can check your sensor health.
98+
1. When the activation is complete, a green success banner shows. In the banner, select **Click here to see the onboarded servers** to jump to the **Settings > Identities > Sensors** page, where you can check your sensor health.
99+
![Sensors page.](media/activate-capabilities/2.png)
97100

98101
## Onboarding Confirmation
99102

100103
To confirm the sensor has been onboarded:
101104

102105
1. Navigate to **System** > **Settings** > **Identities** > **Sensors**.
103106

104-
2. Check that the onboarded domain controller is listed.
107+
1. Check that the onboarded domain controller is listed.
105108

106109
> [!NOTE]
107110
> The first time you activate Defender for Identity capabilities on your domain controller, it may take up to an hour for the first sensor to show as **Running** on the **Sensors** page. Subsequent activations are shown within five minutes.
@@ -216,7 +219,8 @@ For more information, see [Remediation actions in Microsoft Defender for Identit
216219
If you want to deactivate Defender for Identity capabilities on your domain controller, delete it from the **Sensors** page:
217220
218221
1. In the Defender portal, select **Settings > Identities > Sensors**.
219-
1. Select the domain controller where you want to deactivate Defender for Identity capabilities, select **Delete**, and confirm your selection.
222+
1. Select the domain controller where you want to deactivate Defender for Identity capabilities, select **Delete**, and confirm your selection.
223+
![Offboarding defensor.](media/activate-capabilities/3.png)
220224
221225
Deactivating Defender for Identity capabilities from your domain controller doesn't remove the domain controller from Defender for Endpoint. For more information, see [Defender for Endpoint documentation](/microsoft-365/security/defender-endpoint/).
222226
55 KB
Loading
49.7 KB
Loading
37.7 KB
Loading

0 commit comments

Comments
 (0)