Forum Widgets
Latest Discussions
Domain controller showing "Not ready for migration"
I want to get the MDI sensor upgraded to v3 on our domain controllers. When I go into Settings > Sensors, two of our DCs are listed as "Ready for migration", but the third says "Not ready for migration". As far as I can tell, this DC meets all the prerequisites listed at Migrate from sensor v2.x to sensor v3.x - Microsoft Defender for Identity | Microsoft Learn. In the Troubleshooting section of that article, it says "hover over the status on the Sensors page to see a tooltip that lists the reasons the server doesn't meet the migration prerequisites", but I see no such tooltip, no matter where I hover. I tried opening a support request with Microsoft 365 Support, only to be told that I have to contact Azure support. We don't currently have an Azure support plan, so I guess we don't qualify for support. Anyone got any suggestions for things I can try?SolvedRyanSteele-CoVAug 05, 2026Steel Contributor42Views0likes2CommentsPermission required to see the Exposed Entities in Secure Score's MDI items
The documentation here suggests to see the full details of Microsoft Defender for Identity items in Secure Score, I would need the following permission: Security operations/Security data /Security data basics (Read) However, when even with those permissions, I don't have access to the Exposed Entities tab. What permission would I need to be able to have read access to those?AndrewPiskaiJun 24, 2026Microsoft1.2KViews0likes1CommentKQL Query Pass Hash Sync Status
Hi Community, Are there any KQL queries to find the status of Pass Hash Sync status on all users, I was able to find some queries through co-pilot but none of them are valid since the Table name doesn't exists. Thanks VishwaWishwahvijayaJun 02, 2026Copper Contributor170Views0likes2CommentsVPN Integration not persistent
Hello, We tried to configure https://learn.microsoft.com/en-us/defender-for-identity/vpn-integration from supported Cisco VPN GW. We established the RADIUS Accounting logs to be sent to DC with MDI sensors installed. Yet when we enabled this in Defender Portal (Settings > Identities > VPN) by checking the box and inserting the shared secret, the configuration is not persistent. We hit save, and we are presented with the success green message, but once we refresh the page or go elsewhere in the portal, the checkbox is not checked. Has anyone encountered the same issue? Thanks, SimonschimpanzeApr 16, 2026Copper Contributor98Views1like1CommentClarification over "dormant" account status
I was looking today at our list of "Remove dormant accounts from sensitive groups" within Microsoft Defender for Identity, and one service account has caused a bit of discussion. The account would only be used on-premise and would never be carrying out authentications out of our estate. In this case would Defender for Identity still see the account as being "dormant", or is the reason because it's not carried out any of those off-estate authentications? Apologies if this is a simple question, but it would be very helpful to know the answer.jasonbourne5379Apr 15, 2026Copper Contributor221Views0likes1CommentIdentityLogonEvents - IsNtlmV1
Hi, I cannot find documentation on how the IdentityLogonEvents table's AdditionalFields.IsNtlmV1 populated. In a demo environment, I intentionally "enforced" NTLMv1 and made an NTLMv1 connection to a domain controller. On the DC's Security log, event ID 4624 shows correct info: Detailed Authentication Information: Logon Process: NtLmSsp Authentication Package: NTLM Transited Services: - Package Name (NTLM only): NTLM V1 Key Length: 128 On MDI side however it looks like this: (using the following KQL to display relevant info here: IdentityLogonEvents | where ReportId == @"f70dbd37-af8e-4e4e-a77d-b4250f9e0d0b" | extend todynamic(AdditionalFields) | project TimeGenerated, ActionType, Application, LogonType, Protocol,IsNtlmV1 = AdditionalFields.IsNtlmV1 ) TimeGenerated ActionType Application LogonType Protocol IsNtlmV1 Nov 28, 2025 10:43:05 PM LogonSuccess Active Directory Credentials validation Ntlm false Can someone please explain, under which circumstances will the IsNtlmV1 property become "true"? Thank you in advancekuglidaniFeb 27, 2026Tin Contributor613Views0likes8CommentsDefender for Identity health issues - Not Closing
We have old issues and they're not being "Closed" as reported. Are we missing something or is this "Microsoft Defender for Identity" Health Issues process broken? Thanks! Closed: A health issue is automatically marked as Closed when Microsoft Defender for Identity detects that the underlying issue is resolved. If you have the Azure ATP (workspace name) Administrator role, you can also manually close a health issue.MPH2Feb 06, 2026Copper Contributor544Views0likes2CommentsChange password for krbtgt account
What is the criteria that MDI uses to determine whether the https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/accounts#change-password-for-krbtgt-account recommendation has been completed? I'm working with an org where the passwordLastSet attribute on the krbtgt account says "never", yet this recommendation is showing "Completed".SolvedrgsteeleJan 23, 2026Tin Contributor369Views1like6CommentsVery High Increase in CPU activity after Update Microsoft Defender for Identity sensor
All our servers that are running this sensor (DCs, Certificate servers, AD Connect servers) showed a massive increase in average CPU utilization from virtually straight after the sensor was automatically updated to version 2.254.19112.470 (late night UK time). Two of our DCs are sitting on 100% CPU today and we can't find anything to resolve it. Has anyone else seen this since running this version and if so what actions did you take ? How would we go back to rolling back to the previous version when it appears it will just be automatically updated soon after ? This is our monitoring of CPU utilization from one of the majorly affected DCs but every server with the sensor had the exact same graph showing a major increase in CPU at the same date and time i.e. just after the sensor was updated.SolvedTomHazJan 21, 2026Tin Contributor1.3KViews4likes7Comments
Tags
- Sensor52 Topics
- microsoft 365 defender45 Topics
- identity protection36 Topics
- alerts17 Topics
- security posture17 Topics
- logging14 Topics
- azure active directory11 Topics
- updates10 Topics
- Investigations8 Topics
- requirements8 Topics