|
| 1 | +--- |
| 2 | +title: Activate the Defender for Identity sensor v3.x on a domain controller |
| 3 | +description: Learn about how to activate the Microsoft Defender for Identity sensor on domain controllers. |
| 4 | +ms.date: 06/30/2025 |
| 5 | +ms.topic: how-to |
| 6 | +ms.reviewer: rlitinsky |
| 7 | +--- |
| 8 | + |
| 9 | +# Activate the Defender for Identity sensor v3.x on a domain controller (Preview) |
| 10 | + |
| 11 | +For complete protection of your on-premises deployment, we recommend activating the Defender for Identity sensor on all applicable servers. This article describes onboarding for new domain controllers running Windows Server 2019 or later. For domain controllers running older operating systems, we recommend [deploying the classic Defender for Identity sensor](install-sensor.md). |
| 12 | + |
| 13 | +## Prerequisites |
| 14 | +See [Microsoft Defender for Identity sensor v3.x prerequisites](prerequisites-sensor-version-3.md) for all system requirements before proceeding with activating the sensor. |
| 15 | + |
| 16 | +## The Activation page |
| 17 | + |
| 18 | +The **Activation** page displays all servers from your device inventory. Defender for Identity detects all of your servers and their configuration. The server's activation state lets you know what you need to do to onboard the domain controller to Defender for Identity. |
| 19 | + |
| 20 | +You can choose to activate eligible domain controllers either automatically, where Defender for Identity activates them as soon as they're discovered, or manually, by selecting specific domain controllers from the list of eligible servers. |
| 21 | + |
| 22 | + [](media/activate-capabilities/activation-page.png#lightbox) |
| 23 | + |
| 24 | +|Activation State |Next steps | |
| 25 | +|---------|---------| |
| 26 | +|Activate new sensor |The domain controller is already onboarded to Defender for Endpoint. [Activate the sensor](#activate-the-defender-for-identity-sensor).| |
| 27 | +|Install classic sensor|[Deploy the classic Defender for Identity sensor](install-sensor.md) from the **Sensors page**.| |
| 28 | +|OS update is required |This domain controller is running an unsupported operating system version for the new sensor. Update the server to Windows Server 2019 or later to use the new sensor. | |
| 29 | + |
| 30 | +<!--|Download onboarding package |[Onboard the domain controller to Defender for Endpoint](#onboard-the-domain-controller).|--> |
| 31 | + |
| 32 | +<!--## The Activation process |
| 33 | +The process for activating the sensor depends on your configuration. |
| 34 | +- If you have a Defender for Endpoint deployment, simply [activate the sensor](#activate-the-defender-for-identity-sensor). |
| 35 | +- If the domain controller is not onboarded to Defender for Endpoint, [onboard the domain controller](#onboard-the-domain-controller) by configuring Defender for Endpoint streamlined URLs, and then downloading and running the onboarding package.--> |
| 36 | + |
| 37 | +## Activate the Defender for Identity sensor |
| 38 | + |
| 39 | +1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **System** > **Settings** > **Identities** > **Activation**. |
| 40 | +1. Select the domain controller where you want to activate Defender for Identity, and select **Activate**. Confirm your selection when prompted. |
| 41 | + |
| 42 | + [](media/activate-capabilities/activate.png#lightbox) |
| 43 | + |
| 44 | +1. When the activation is complete, a green success banner shows. In the banner, select **Click here to see the onboarded servers**. This takes you to the **Sensors** page, where you can check your sensor health. |
| 45 | + |
| 46 | + [](media/activate-capabilities/successfully-activated.png#lightbox) |
| 47 | + |
| 48 | +<!--## Onboard the domain controller |
| 49 | +
|
| 50 | +If the domain controller has not been onboarded to Defender for Endpoint for Servers, follow these steps to activate the sensor. |
| 51 | +
|
| 52 | +1. [Configure your network environment to ensure connectivity with Defender for Endpoint](/microsoft-365/security/defender-endpoint/configure-environment##enable-access-to-microsoft-defender-for-endpoint-service-urls-in-the-proxy-server) using [streamlined URLs](/microsoft-365/security/defender-endpoint/configure-device-connectivity#option-1-configure-connectivity-using-the-simplified-domain). |
| 53 | +1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **System** > **Settings** > **Identities** > **Activation**. |
| 54 | +1. Select **Download onboarding package**, and save the file in a location you can access from your domain controller. |
| 55 | +
|
| 56 | + [](media/activate-capabilities/download-on-boarding.png#lightbox) |
| 57 | + |
| 58 | +1. From the domain controller, extract the zip file you downloaded from the Microsoft Defender portal. |
| 59 | +1. Run the `DefenderForIdentityOnlyOnboardingScript.cmd` script as an administrator. |
| 60 | +
|
| 61 | + [](media/activate-capabilities/screenshot-2025-06-04-170500.png#lightbox) |
| 62 | +
|
| 63 | +!--> |
| 64 | + |
| 65 | +## Confirm sensor activation |
| 66 | + |
| 67 | +To confirm the sensor is working: |
| 68 | + |
| 69 | +1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **System** > **Settings** > **Identities** > **Sensors**. |
| 70 | +1. Check that the activated domain controller is listed. |
| 71 | + |
| 72 | +> [!NOTE] |
| 73 | +> The first time you activate the Defender for Identity sensor on your domain controller, it might take up to an hour for the first sensor to show as **Running** on the **Sensors** page. Subsequent activations are shown within five minutes. The activation doesn't require a restart/reboot. |
| 74 | +
|
| 75 | +## Next steps |
| 76 | +- [Manage and update Microsoft Defender for Identity sensors](../sensor-settings.md). |
0 commit comments