Published Nov 17, 2025
An opt-in feature for automatic Windows event-auditing configuration in Defender for Identity unified sensors (V3.x) will be available mid-December 2025. It simplifies deployment by auto-applying required settings, affects all sensors in a tenant, requires admin activation, and addresses specific auditing health issues.
Updated November 19, 2025: We have updated the timeline. Thank you for your patience.
Introduction
We’re introducing a new opt-in feature for automatic event-auditing configuration in Defender for Identity unified sensors (V3.x). This enhancement simplifies deployment by allowing admins to automatically apply the required Windows event-auditing settings on their sensors. It reduces manual post-deployment steps and ensures consistent policy enforcement across all onboarded sensors.
When this will happen:
General Availability (Worldwide, GCC, GCCH, and DoD): The auditing opt-in feature will be available starting mid-December 2025 (previously mid-November), with rollout expected to complete within the same timeframe.
General Availability (Worldwide, GCC, GCCH, and DoD): The related auditing health alerts will be released gradually by mid-January 2026 (previously mid-December).
How this affects your organization:
Who is affected:
Admins managing Defender for Identity unified sensors (V3.x) in Microsoft 365 tenants.
What will happen:
What you can do to prepare:
No action is required unless you choose to enable the feature.
If you plan to opt in:
To review the required auditing configurations for Defender for Identity unified sensors (V3.x)
For details about the relevant auditing health issues
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.