Microsoft Defender for Identity introduces a new opt-in post-deployment configuration for unified sensors (v3.x) enabling RPC monitoring via the Unified Sensor RPC Audit tag. Rollout starts late September 2025, enhancing advanced identity detections with visibility in device inventory. No action needed unless enabling the feature.
Introduction
We’re introducing a new post-deployment configuration option for unified sensors (V3.x) in Microsoft Defender for Identity (preview). This update enhances security and enables advanced identity detections by allowing admins to apply the new Unified Sensor RPC Audit tag to domain controllers onboarded with the unified sensor (v3.x). This tag activates Remote Procedure Call (RPC) monitoring using the Windows Filtering Platform (WFP), which is required for advanced identity detections.When this will happen:
Preview (Worldwide): Rollout will begin in late September 2025 and is expected to complete by mid-October 2025.Preview (GCC, GCCH, and DoD): Rollout will begin in late September 2025 and is expected to complete in late October 2025.
How this affects your organization:
What you can do to prepare:
Learn more: Microsoft Defender for Identity sensor v3.x prerequisites (Preview)
Compliance considerations:No compliance considerations identified, review as appropriate for your organization.