Fixing Microsoft Defender for Identity Sensor Installation and Health Issues

Explore Our Microsoft Cloud Security Training →

Fixing Microsoft Defender for Identity (MDI) Sensor Installation and Health Issues

Security engineers deploying MDI on domain controllers often encounter issues during sensor installation or health monitoring. In this blog post, we’ll discuss common pitfalls and provide solutions to help you overcome these challenges.

Sensor Installation Prerequisites

For a successful MDI sensor installation, ensure your domain controller meets the following prerequisites: .NET Framework 4.7+, minimum 6 GB RAM with 100 MB free, port mirroring or ETW for traffic capture.

Common Installation Failure Causes

Common failures include insufficient permissions for the gMSA Directory Services Account, blocked outbound HTTPS to *.atp.azure.com, or missing RBAC roles. Performance impact is minimal (~5 percent CPU).

Network Requirements

Ensure sensor-to-cloud communication by verifying network requirements and allowing traffic on required ports.

Sensor Health Monitoring

Monitor sensor health at Settings > Identities > Sensors in the Defender XDR portal to quickly identify and address any issues.

Conclusion

By understanding the prerequisites, network requirements, common failures, and performance impact of Microsoft Defender for Identity (MDI) sensor installation on domain controllers, you can improve your MDI deployment. Learn more about Microsoft Cloud Security at Microsoft Cloud Security Training.

Explore Our Microsoft Cloud Security Training →

Written by Mohammed Akhter

Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →