September 11, 2026
In BriefDefender for Identity Sensor v3 Upgrade: Proceed with Caution
There’s a new version of the Microsoft Defender for Identity sensor software for use on identity servers, and it promises significant enhancements—including easier migration—in the future. For the present, however, significant limitations with this new version mean that customers can’t deploy it broadly and should instead wait for future iterative releases. The Defender for Identity Sensor software allows Active Directory (AD) and Entra Connect servers running on premises to connect with Microsoft’s hosted Defender for Identity service, enabling AD activity and security events to be analyzed and reported on by the service.
Using the Microsoft Defender portal, servers running the earlier v2 sensor can be easily upgraded in place to the new v3 sensor software without a reboot, but only if they meet a specific set of prerequisites. For example, in the current v3 release, only servers that are domain controllers running Windows Server 2019 or newer (with the July 2026 or newer cumulative update) can be upgraded automatically, even if those servers are also running AD FS, AD CS, or Microsoft Entra Connect.
Atlas Members have full access
Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.
Membership OptionsAlready have an account? Login Now
Not a member but want to see the full content? Contact us.