MC1193410 Medium
(Updated) Automatic Windows event auditing configuration availability for unified sensors (V3.x)
Summary AI-generated
Admins can soon opt in to automatic Windows event-auditing configuration for Defender for Identity unified sensors (v3.x), simplifying deployment and policy enforcement. Rollout starts mid-January 2026.
Suggested actions AI-generated
- Review unified sensor deployment strategy before opting in
- Enable opt-in setting via UI or Graph API if desired
- Communicate changes to IT/security teams
- Update internal documentation on auditing configs
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1187403 (Updated) Automatic Windows event auditing configuration now available for unified sensors (V3.x)
- MC1187390 Unified sensor (v3.x) – new Remote Procedure Call (RPC) configuration health alert for Microsoft Defender for Identity
- MC1461705 Microsoft Defender XDR: Unified identity timeline on the Identity page
- MC1228325 (Public Preview) New built in alert tuning rules for Microsoft Defender for Endpoint in Microsoft Defender XDR
- MC1222979 New Built-in Alert Tuning Rules optimize your incident and alert queues
- MC1455016 New Defender for Identity health issue for missing Windows events from a domain controller
Original post from Microsoft
Updated January 6, 2026: We have updated the timeline. Thank you for your patience.
[Introduction]
We’re introducing a new opt-in feature for automatic event-auditing configuration in Microsoft Defender for Identity unified sensors (v3.x). This enhancement simplifies deployment by automatically applying the required Windows event-auditing settings on sensors, reducing manual post-deployment steps and ensuring consistent policy enforcement across all onboarded sensors.
[When this will happen:]
- General Availability (Worldwide, GCC, GCCH, and DoD): The auditing opt-in feature will be available starting mid-January 2026 (previously early January), with rollout expected to complete by end of January 2026 (previously mid-January). Until then, it will remain disabled in the portal.
- Related auditing health alerts will also roll out gradually starting mid-January 2026 (previously early January), completing by end of January 2026 (previously mid-January).
[How this affects your organization:]
Who is affected: Admins managing Defender for Identity unified sensors (v3.x) in Microsoft 365 tenants.
What will happen:
- A new opt-in setting will be available in both the UI and via Graph API.
- In the UI, this option will appear under Defender for Identity Settings → Advanced features.
- Once enabled, the automatic configuration feature will:
- For new sensor activations: Automatically apply all required Windows event-auditing settings during activation.
- For existing onboarded sensors: Automatically apply Windows event-auditing settings only if misconfigured and dismiss related health issues.
- After enabling the toggle, the automatic configuration process may take up to 24 hours to apply across all applicable Identity Unified sensors (v3.x).
- This feature is not enabled by default and requires admin action. No changes will occur unless admins choose to enable the feature.
Relevant auditing configurations health issues covered:
- NTLM auditing is not enabled
- Directory Services Advanced Auditing is not enabled as required
- Directory Services Object Auditing is not enabled as required
- Auditing on the Configuration container is not enabled as required
- Auditing on the ADFS container is not enabled as required
[What you can do to prepare:]
No action is required unless you choose to enable the feature.
If you plan to opt in:
- Review your unified sensor deployment strategy.
- Enable the opt-in setting via the UI or Graph API.
- Communicate the change to relevant IT and security teams.
- Update internal documentation if you track auditing configurations.
Learn more:
- Auditing health alerts documentation
- Configure Windows event auditing
- Configure audit policies for Windows event logs
[Compliance considerations:]
No compliance considerations identified, review as appropriate for your organization.
Additional details from Microsoft
- Summary
- Microsoft Defender for Identity unified sensors (v3.x) will offer an opt-in feature from mid-January 2026 to automatically configure Windows event-auditing settings, simplifying deployment and ensuring consistent policy enforcement. Admins must enable it via UI or Graph API; rollout completes by end of January 2026.