Starting January 2026, Microsoft Defender for Identity unified sensors (v3.x) will offer an opt-in feature for automatic Windows event-auditing configuration, simplifying deployment by auto-applying required settings on new and misconfigured existing sensors. Admins must enable this feature via UI or Graph API.
Introduction
We’re introducing a new opt-in feature for automatic event-auditing configuration in Microsoft Defender for Identity unified sensors (v3.x). This enhancement simplifies deployment by automatically applying the required Windows event-auditing settings on sensors, reducing manual post-deployment steps and ensuring consistent policy enforcement across all onboarded sensors.
When this will happen:
How this affects your organization:
Who is affected: Admins managing Defender for Identity unified sensors (v3.x) in Microsoft 365 tenants.
What will happen:
Relevant auditing configurations health issues covered:
What you can do to prepare:
No action is required unless you choose to enable the feature.
If you plan to opt in:
Learn more:
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.