Zum Inhalt springen

Microsoft Defender for Identity Updates & Release Notes

5 Einträge aus 1 Quelle.

Folge Microsoft Defender for Identity, um die Release Notes in deinen Feed zu holen.

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

Microsoft Defender for Identity von Microsoft

Sensor-Update 2.255.19347.63719 mit Sicherheitsverbesserungen

Das Sensor-Update 2.255.19347.63719 enthält Sicherheitsverbesserungen, und die automatische Windows-Ereignisüberwachung konfiguriert nun auch Auditing für AD FS, AD CS und Microsoft Entra Connect auf allen geeigneten Servern mit Sensor v3.x, auch wenn diese keine Domänencontroller sind.

Expanded automatic auditing support for AD CS, AD FS, and Entra Connect servers

Automatic Windows event auditing now configures auditing for AD FS, AD CS, and Microsoft Entra Connect. Auditing is configured automatically on any eligible server that runs Defender for Identity sensor v3.x, including servers that aren't domain controllers. For more information, see Configure Defender for Identity to collect Windows events automatically.

July 2026

Defender for Identity sensor updates

Version number Updates

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

Microsoft Defender for Identity von Microsoft

Sensor-Update 2.255.19295.47272 und Migration auf Sensor v3.x

Das Sensor-Update 2.255.19295.47272 unterstützt einen neuen Event-Tracing-for-Windows-(ETW)-Provider, die Migration von Sensor v2.x auf v3.x ist allgemein verfügbar, Windows-Server-2025-Domänencontroller lassen sich migrieren, und die Sensors-Seite zeigt per Tooltip die Gründe für den Status „Not ready for migration“.

Sensor v2.x to v3.x migration is now generally available

Migration of Defender for Identity sensors from v2.x to v3.x is now generally available. For more information, see Migrate to Defender for Identity sensor v3.x.

Migrate Windows Server 2025 domain controllers to sensor v3.x

You can now migrate domain controllers running Windows Server 2025 from sensor v2.x to sensor v3.x. For more information, see Migrate to Defender for Identity sensor v3.x.

Migration readiness reasons on the Sensors page

When a server is marked Not ready for migration on the Sensors page, you can now hover over the status to see a tooltip that lists the specific reasons the server doesn't meet the migration prerequisites. For more information, see Troubleshoot "Not ready for migration" status.

Expanded SaaS app support in Password protection (Preview) …

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

Microsoft Defender for Identity von Microsoft

Version 3.0.8: RPC-Auditing wird automatisch aktiviert

Beim Upgrade auf Sensor-Version 3.0.8 oder höher aktiviert Defender for Identity das RPC-Auditing auf Domänencontrollern automatisch, ohne dass manuell ein Tag gesetzt werden muss; außerdem ist der Identity risk score nun allgemein verfügbar und es gibt neue Sicherheitswarnungen zu Entra ID.

June 2026

Identity risk score is now generally available

The identity risk score is now generally available. The score ranges from 0 to 100 and reflects how likely an identity is to be compromised and how much damage a compromise could cause, based on the identity's criticality level and privileged role assignments. The Risk score tab on the Identity page provides a detailed breakdown of risk factors, percentile comparison, and risk trends.

New Defender for Identity security alerts

These new alerts were added to the Defender for Identity security alerts:

New alerts related to Entra ID:

  • Anomalous activity following Global Administrator elevation
  • Reciprocal Temporary Access Pass creation between users
  • Suspicious service principal sign-in following credential addition
  • Suspicious bulk user deletion via scripted activity
  • Suspicious removal of privileged app role assignment through Graph API …

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

Microsoft Defender for Identity von Microsoft

Sensor-Update 2.255.19247.44775 und Neuerungen im April 2026

Das Sensor-Update 2.255.19247.44775 ergänzt Eigenschaften bei der Group-Policy-(GPO)-Ereigniserfassung und enthält Fehlerbehebungen, zudem gibt es in der Preview den Identity Explorer sowie benutzerdefinierte Account-Korrelationsregeln.

April 2026

Identity Explorer (Preview)

The Identity page now includes the Identity Explorer tab for customers with a Microsoft Sentinel Data Lake license. This tab uses the hunting graph to visualize identity attack paths and exposure scenarios as interactive graphs. Use predefined identity scenarios to discover lateral movement paths, privilege escalation routes, and credential-access risks. For more information, see Investigate an identity.

Custom account correlation rules (Preview)

Custom account correlation rules let you link accounts that belong to the same identity, such as privileged accounts with unique naming conventions. You can correlate accounts that don't share strong identifiers such as account ID, SID, object ID, or UPN by defining rules based on UPN prefix, UPN suffix, or domain UPN. For more information, see Create custom account correlation rules.

Automatic Windows event auditing configuration for sensors v3.x is now generally available …

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

Microsoft Defender for Identity von Microsoft

Sensor-Update 2.255.19201.14651 mit Migration auf v3.x

Das Sensor-Update 2.255.19201.14651 enthält Fehlerbehebungen, und Sensoren lassen sich nun direkt im Microsoft Defender Portal ohne Ausfallzeit von v2.x auf v3.x migrieren, zudem gibt es ein Identity-Security-Dashboard in der Preview.

Migrate Defender for Identity sensors from v2.x to v3.x

You can now migrate Defender for Identity sensors from v2.x to v3.x directly from the Microsoft Defender portal. The v2.x sensor continues running during the migration until the v3.x sensor is ready, so there's no downtime. Eligible servers appear as Ready for migration on the Sensors page, and migration takes up to 20 minutes. For more information, see Migrate to Defender for Identity sensor v3.x.

Identity security enhancements

New identity security capabilities help you monitor and manage identity security for human and non-human identities:

  • Identity Security dashboard (Preview): The Identity Security dashboard provides summary cards for identity providers, on-premises identities, SaaS identities, PAM and IGA integrations, and non-human identities. Widgets show deployment status, highly privileged identities, users at risk, and domains with unsecured configurations. For more information, see The Identity Security dashboard.

    The Identity Security dashboard is being rolled out gradually to customers, and might not yet be available in your organization. …

Originalquelle(öffnet in neuem Tab)Problem melden