Published Dec 9, 2025
Microsoft Defender for Identity unified sensors (v3.x) will offer an opt-in feature from mid-January 2026 to automatically configure Windows event-auditing settings, simplifying deployment and ensuring consistent policy enforcement. Admins must enable it via UI or Graph API; rollout completes by end of January 2026.
Updated January 6, 2026: We have updated the timeline. Thank you for your patience.
Introduction
We’re introducing a new opt-in feature for automatic event-auditing configuration in Microsoft Defender for Identity unified sensors (v3.x). This enhancement simplifies deployment by automatically applying the required Windows event-auditing settings on sensors, reducing manual post-deployment steps and ensuring consistent policy enforcement across all onboarded sensors.
When this will happen:
How this affects your organization:
Who is affected: Admins managing Defender for Identity unified sensors (v3.x) in Microsoft 365 tenants.
What will happen:
Relevant auditing configurations health issues covered:
What you can do to prepare:
No action is required unless you choose to enable the feature.
If you plan to opt in:
Learn more:
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.