Site icon Windows Active Directory

How to install Microsoft Defender for Identity sensors

Microsoft Defender for Identity (MDI) is a cloud-based security solution designed to shield organizations from advanced threats targeting Active Directory (AD) environments. The MDI sensor, a lightweight agent deployed on domain controllers, monitors user and device activity within your AD infrastructure. This blog explores the installation process for the MDI sensor, highlighting its purpose, functionalities, and relevant use cases.

Purpose and functionalities of the MDI sensor

The MDI sensor acts as the ‘eyes and ears’ for MDI within your on-premises AD environment. Its core functionalities include:

Why install the MDI sensor?

Deploying the MDI sensor offers several benefits:

When to install the MDI sensor?

Here are some key scenarios where installing the MDI sensor is crucial:

Installation scope

Install the MDI sensor on every domain controller in your AD environment to ensure comprehensive monitoring and detection capabilities. You can also deploy MDI sensors on:

How to install the MDI sensor

The MDI sensor installation process is straightforward and can be accomplished using two primary methods:

1. Microsoft Defender for Identity portal:

Steps:

2. Manual installation:

Steps:

Additional considerations

  1. Network connectivity: Ensure domain controllers with MDI sensors can transmit data to the MDI cloud service through a working network connection.
  2. .NET framework: The MDI sensor requires the target domain controllers to have Microsoft .NET Framework 4.7 or a newer version installed. If not installed, the installer will automatically install the necessary version.
  3. Permissions: The user installing the MDI sensor must have local administrator privileges on the target domain controller.

By strategically deploying MDI sensors within their AD environment, organizations can gain important insights into user behavior, enhance security, and ensure compliance with regulatory requirements.

Exit mobile version