High - Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Entra ID - Microsoft primary source
Microsoft Defender for Identity - New Features and Updates from March to August 2026
Microsoft Defender for Identity introduced significant updates including expanded automatic Windows event auditing for AD CS, AD FS, and Entra Connect servers, general availability of sensor v3.x migration support and domain controller support for Windows Server 2025, new security alerts targeting Entra ID, Active Directory, and other identity providers, enhanced identity risk scoring, increased sensor capacity per workspace, and improved identity investigation and correlation capabilities.
What changed
- Automatic Windows event auditing expanded to AD FS, AD CS, and Entra Connect servers - Defender for Identity sensor v3.x migration moved to general availability, including support for Windows Server 2025 domain controllers - New security alerts added covering a comprehensive range of identity-related risks in Entra ID, Active Directory, and third-party identity providers - Identity risk scoring became generally available with detailed risk factor insights - Increased sensor count limit to 1,000 per workspace - Introduction of Identity Explorer for visualizing identity attack paths - Custom account correlation rules introduced in preview - Automatic configuration of RPC auditing on domain controllers after sensor upgrade - Expanded SaaS app support for Password protection including integrations with Defender for Cloud Apps
Why it matters operationally
Organizations using Microsoft Defender for Identity should plan sensor migrations to v3.x where supported, particularly updating domain controllers including Windows Server 2025 after support is available. They should monitor and investigate new security alerts across Entra ID, Active Directory, and other identity providers. The expanded automatic auditing reduces deployment effort but requires validation. Increased sensor capacity allows scaling in large environments. Newly available features like Identity Explorer and custom account correlation rules enable better identity risk and attack path investigations. Overall, these updates enhance detection and security posture while requiring some operational attention for upgrades and configuration verification.
What the SOC should check
Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.
Recommended actions
- Review and plan migration to Defender for Identity sensor v3.x on supported servers, including Windows Server 2025 domain controllers when supported.
- Enable and verify automatic Windows event auditing and RPC auditing configurations post sensor upgrade.
- Monitor and investigate new and updated security alerts for Entra ID, Active Directory, and third-party identity providers.
- Utilize the Identity Explorer feature (with Microsoft Sentinel Data Lake license) to visualize and analyze identity attack paths.
- Apply custom account correlation rules to improve identification of linked accounts.
- Review and increase sensor capacity in workspace as needed, contacting support for over 1000 sensors.
- Integrate SaaS app password protection insights via Defender for Cloud Apps connectors where applicable.
KQL hunting context
New security alerts and features provide enhanced detection and investigation capabilities that can be leveraged with KQL queries for hunting and monitoring.
Source links
https://learn.microsoft.com/en-us/defender-for-identity/whats-new