Implementing Defender for Identity
Microsoft Defender for Identity offers additional alerts, reports, and hunting capabilities for Active Directory forests. This recipe shows how to deploy the Defender for Identity sensor on your domain controllers.
Getting ready
To complete this recipe, sign in to the Microsoft 365 Defender portal with an account that has the Global administrator or Security administrator role assigned to it. If the organization uses the Azure AD PIM feature, activate the Global administrator or Security administrator role in advance.
Microsoft Defender for Identity requires at least one EMS E5 or Microsoft 365 license.
To install the Defender for Identity sensor on your domain controllers, sign in with an account that has local administrator privileges on the domain controllers. By default, members of the Administrators, Domain Admins, and Enterprise Admins security groups in Active Directory have these privileges.
How to do it…
Implementing...