Loading...

Automatic Windows event auditing configuration availability for unified sensors (V3.x)

Automatic Windows event auditing configuration availability for unified sensors (V3.x)

Starting January 2026, Microsoft Defender for Identity unified sensors (v3.x) will offer an opt-in feature for automatic Windows event-auditing configuration, simplifying deployment by auto-applying required settings on new and misconfigured existing sensors. Admins must enable this feature via UI or Graph API. Introduction We’re introducing a new opt-in feature for automatic event-auditing configuration in Microsoft Defender for Identity unified sensors (v3.x). This enhancement simplifies deployment by automatically applying the required Windows event-auditing settings on sensors, reducing manual post-deployment steps and ensuring consistent policy enforcement across all onboarded sensors. When this will happen: General Availability (Worldwide, GCC, GCCH, and DoD): The auditing opt-in feature will be available starting early January 2026, with rollout expected to complete by mid-January 2026. Until then, it will remain disabled in the portal. Related auditing health alerts will also roll out gradually starting early January 2026, completing by mid-January 2026. How this affects your organization: Who is affected: Admins managing Defender for Identity unified sensors (v3.x) in Microsoft 365 tenants. What will happen: A new opt-in setting will be available in both the UI and via Graph API. In the UI, this option will appear under Defender for Identity Settings → Advanced features. Once enabled, the automatic configuration feature will: For new sensor activations: Automatically apply all required Windows event-auditing settings during activation. For existing onboarded sensors: Automatically apply Windows event-auditing settings only if misconfigured and dismiss related health issues. After enabling the toggle, the automatic configuration process may take up to 24 hours to apply across all applicable Identity Unified sensors (v3.x). This feature is not enabled by default and requires admin action. No changes will occur unless admins choose to enable the feature. Relevant auditing configurations health issues covered: What you can do to prepare: If you plan to opt in: NTLM auditing is not enabled Directory Services Advanced Auditing is not enabled as required Directory Services Object Auditing is not enabled as required Auditing on the Configuration container is not enabled as required Auditing on the ADFS container is not enabled as required No action is required unless you choose to enable the […]

The post Automatic Windows event auditing configuration availability for unified sensors (V3.x) appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Automatic Windows event auditing configuration availability for unified sensors (V3.x)

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Excel: Excel canvas

Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...

2 days ago

Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads

We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...

2 days ago

Microsoft Outlook: Right-click to customize the classic ribbon

Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...

2 days ago

Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs

Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...

2 days ago

Microsoft Entra App Gallery: Self-service onboarding for new applications

Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...

2 days ago

Upgraded call history in Teams Calls app

Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...

2 days ago

Power Automate – Enable Process Intelligence Studio in object-centric process mining

We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...

2 days ago

Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities

We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...

2 days ago

Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center

The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...

2 days ago

Microsoft Teams: Start side conversations during meetings

Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.