Summary
- Microsoft Defender for Identity will automatically enable auto-activation and auto-auditing for eligible tenants using sensor v3.x.
- The change affects security admins managing Defender for Identity sensors and Microsoft Defender XDR settings, especially for servers already onboarded to Microsoft Defender for Endpoint.
- A banner will appear in the Microsoft Defender portal before enablement so admins can review the change and opt out during the limited opt-out period.
- After rollout begins, admins can still change the toggle manually in Settings > Advanced features if needed.
- Review current sensor activation and Windows event auditing setup and update any internal guidance that still assumes manual configuration.
Primary Service: Defender XDR
Admin Impact: Medium
User Impact: Low
Release Start: 31 Oct 2026
Release End: 31 Oct 2026
Services: Defender, Defender XDR, Security
Category: Plan for change
Tags: Admin Action, New Feature
History
9/30/2026 Item Added to Message Center
Microsoft Message
Microsoft Defender for Identity will automatically enable auto-activation and auto-auditing for eligible tenants using Defender for Identity sensor v3.x. Auto-activation helps activate eligible servers that are already onboarded to Microsoft Defender for Endpoint, and auto-auditing helps configure the required Windows event auditing.
This update supports enterprise-ready security operations by helping organizations complete Defender for Identity sensor activation and auditing setup with less manual configuration.
Rollout Schedule
- General Availability, Worldwide: We will begin rolling out in late October 2026 and will roll out gradually.
- Before enablement begins, a banner will appear in the Microsoft Defender portal under Settings > Identities > Sensor management.
Impact on Your Organization
Who is affected
- Organizations using Microsoft Defender for Identity sensor v3.x.
- Security administrators who manage Microsoft Defender for Identity sensors and Microsoft Defender XDR settings.
- Servers already onboarded to Microsoft Defender for Endpoint that are eligible for Defender for Identity sensor activation.
Platforms/Services
- Microsoft Defender for Identity.
- Microsoft Defender XDR portal.
- Microsoft Defender for Endpoint.
What will happen
- Auto-activation will help activate eligible servers that are already onboarded to Microsoft Defender for Endpoint.
- Auto-auditing will help configure the required Windows event auditing for Defender for Identity.
- A banner will be shown in the Microsoft Defender portal before enablement starts.
- Admins can use the banner to opt out during the limited opt-out period.
- After the opt-out period ends and rollout starts, admins can still manually change the toggle status at any time in Settings > Advanced features.
Action Required/Recommendations
- Review the banner in the Microsoft Defender portal if your organization wants to opt out before gradual rollout starts.
- Review your current Defender for Identity sensor activation and Windows event auditing configuration.
- Update internal security operations or deployment guidance if it references manual activation or auditing steps for Defender for Identity sensor v3.x.
- For special cases related to the feature or opt-out, contact the Defender for Identity support team.
- Learn more about sensor activation: https://learn.microsoft.com/en-us/defender-for-identity/deploy/activate-sensor.
- Learn more about automatic Windows event auditing: https://learn.microsoft.com/en-us/defender-for-identity/deploy/configure-windows-event-collection.
Compliance considerations
Does the change include an admin control and, can it be controlled through Entra ID group membership?
The feature includes or affects admin controls, policies, permissions, roles, authentication, or management settings as described in this message. Review the linked documentation or admin center controls for group-based configuration support.