{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/",
        "slug": "add-sensor-onboarding-test-mdiconfiguration-identity-reviews",
        "url": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/"
        },
        "title": "Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews",
        "summary": "Use Quarterly or ad-hoc operational guide for Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-27T12:14:32+00:00",
        "modified_at": "2026-08-27T12:58:58+00:00",
        "reviewed_on": "2026-08-26",
        "reading_minutes": 3,
        "word_count": 549,
        "potentially_affected": "Teams, systems, services, or facilities within the stated scope of Quarterly or ad-hoc operational guide for Microsoft Defender for Identity",
        "dse_recommendation": "Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.",
        "primary_source": {
            "name": "Quarterly or ad-hoc operational guide for Microsoft Defender for Identity",
            "url": "https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-quarterly",
            "published_on": "2026-07-02",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p>Use this document to connect an official requirement or behavior to observable evidence: Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews. Only the official source and traced locations below supply facts. Confirm applicability before acting.</p>\n<h2>Source fact:</h2>\n<p>The official <a href=\"https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-quarterly\" target=\"_blank\" rel=\"noopener noreferrer\">Quarterly or ad-hoc operational guide for Microsoft Defender for Identity</a> from Microsoft supports the following bounded statements:</p>\n<ul>\n<li>Microsoft recommends periodically verifying that the server setup process installs Defender for Identity sensors on new domain controllers, AD CS servers, and AD FS servers. The research record locates this support at <strong>Review server setup process to include sensors</strong>.</li>\n<li>Microsoft recommends periodically running Test-MDIConfiguration to check domain-controller audit policy settings because incorrect settings can create Event Log gaps and reduce Defender for Identity coverage. The research record locates this support at <strong>Check domain configuration via PowerShell</strong>.</li>\n</ul>\n<p>Keep the evidence boundary at these traced claims. They support a review of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows; they do not support conclusions outside the source&#8217;s stated conditions.</p>\n<h2>What the source does not establish</h2>\n<p>The source is a quarterly or ad-hoc guide; local cadence, supported server roles, permissions, and remediation ownership still require an environment-specific operating procedure. Do not read the source as proof of implementation or permission to change production. Its guidance remains conditional on Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing and the environment&#8217;s recorded constraints.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>For source statement 1 at <strong>Review server setup process to include sensors</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 2 at <strong>Check domain configuration via PowerShell</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>What inventory proves which parts of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows are in and out of scope?</li>\n<li>Which condition in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing must be healthy before evidence is trustworthy?</li>\n<li>What result would disprove the working assumption and return the issue to the owner?</li>\n</ul>\n<h2>DSE recommendation:</h2>\n<p>DSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.</p>\n<p>If the review warrants change, use a bounded implementation with prerequisites, test population, monitoring, abort criteria, and a rehearsed reversal. Sequence checks for Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing and sanitize protected material before retention.</p>\n<h2>Verification and evidence</h2>\n<p>A reviewer should be able to retrace the decision from <strong>Review server setup process to include sensors</strong>; <strong>Check domain configuration via PowerShell</strong> through alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure. Record what was collected, where, when, by whom, and which system or role it represents.</p>\n<p>Record the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-quarterly\" target=\"_blank\" rel=\"noopener noreferrer\">Quarterly or ad-hoc operational guide for Microsoft Defender for Identity</a> — Microsoft</li>\n</ul>",
        "content_text": "Use this document to connect an official requirement or behavior to observable evidence: Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Quarterly or ad-hoc operational guide for Microsoft Defender for Identity from Microsoft supports the following bounded statements:\n\nMicrosoft recommends periodically verifying that the server setup process installs Defender for Identity sensors on new domain controllers, AD CS servers, and AD FS servers. The research record locates this support at Review server setup process to include sensors.\nMicrosoft recommends periodically running Test-MDIConfiguration to check domain-controller audit policy settings because incorrect settings can create Event Log gaps and reduce Defender for Identity coverage. The research record locates this support at Check domain configuration via PowerShell.\n\nKeep the evidence boundary at these traced claims. They support a review of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows; they do not support conclusions outside the source’s stated conditions.\nWhat the source does not establish\nThe source is a quarterly or ad-hoc guide; local cadence, supported server roles, permissions, and remediation ownership still require an environment-specific operating procedure. Do not read the source as proof of implementation or permission to change production. Its guidance remains conditional on Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing and the environment’s recorded constraints.\nApplicability questions\n\nFor source statement 1 at Review server setup process to include sensors, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Check domain configuration via PowerShell, which observable configuration, record, or test can confirm applicability here?\nWhat inventory proves which parts of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows are in and out of scope?\nWhich condition in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing must be healthy before evidence is trustworthy?\nWhat result would disprove the working assumption and return the issue to the owner?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.\nIf the review warrants change, use a bounded implementation with prerequisites, test population, monitoring, abort criteria, and a rehearsed reversal. Sequence checks for Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing and sanitize protected material before retention.\nVerification and evidence\nA reviewer should be able to retrace the decision from Review server setup process to include sensors; Check domain configuration via PowerShell through alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure. Record what was collected, where, when, by whom, and which system or role it represents.\nRecord the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.\nOfficial references\n\nQuarterly or ad-hoc operational guide for Microsoft Defender for Identity — Microsoft",
        "content_markdown": "Use this document to connect an official requirement or behavior to observable evidence: Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews. Only the official source and traced locations below supply facts. Confirm applicability before acting.\n\n## Source fact:\n\nThe official [Quarterly or ad-hoc operational guide for Microsoft Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-quarterly) from Microsoft supports the following bounded statements:\n\n- Microsoft recommends periodically verifying that the server setup process installs Defender for Identity sensors on new domain controllers, AD CS servers, and AD FS servers. The research record locates this support at Review server setup process to include sensors.\n\n- Microsoft recommends periodically running Test-MDIConfiguration to check domain-controller audit policy settings because incorrect settings can create Event Log gaps and reduce Defender for Identity coverage. The research record locates this support at Check domain configuration via PowerShell.\n\nKeep the evidence boundary at these traced claims. They support a review of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows; they do not support conclusions outside the source’s stated conditions.\n\n## What the source does not establish\n\nThe source is a quarterly or ad-hoc guide; local cadence, supported server roles, permissions, and remediation ownership still require an environment-specific operating procedure. Do not read the source as proof of implementation or permission to change production. Its guidance remains conditional on Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing and the environment’s recorded constraints.\n\n## Applicability questions\n\n- For source statement 1 at Review server setup process to include sensors, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 2 at Check domain configuration via PowerShell, which observable configuration, record, or test can confirm applicability here?\n\n- What inventory proves which parts of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows are in and out of scope?\n\n- Which condition in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing must be healthy before evidence is trustworthy?\n\n- What result would disprove the working assumption and return the issue to the owner?\n\n## DSE recommendation:\n\nDSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.\n\nIf the review warrants change, use a bounded implementation with prerequisites, test population, monitoring, abort criteria, and a rehearsed reversal. Sequence checks for Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing and sanitize protected material before retention.\n\n## Verification and evidence\n\nA reviewer should be able to retrace the decision from Review server setup process to include sensors; Check domain configuration via PowerShell through alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure. Record what was collected, where, when, by whom, and which system or role it represents.\n\nRecord the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.\n\n## Official references\n\n- [Quarterly or ad-hoc operational guide for Microsoft Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-quarterly) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/",
                "url": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-26"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews",
                        "item": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/#article",
                "identifier": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/",
                "url": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/",
                "headline": "Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews",
                "description": "Use Quarterly or ad-hoc operational guide for Microsoft Defender for Identity to review this narrow operational decision without extending the source…",
                "abstract": "Use Quarterly or ad-hoc operational guide for Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.",
                "articleBody": "Use this document to connect an official requirement or behavior to observable evidence: Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Quarterly or ad-hoc operational guide for Microsoft Defender for Identity from Microsoft supports the following bounded statements:\n\nMicrosoft recommends periodically verifying that the server setup process installs Defender for Identity sensors on new domain controllers, AD CS servers, and AD FS servers. The research record locates this support at Review server setup process to include sensors.\nMicrosoft recommends periodically running Test-MDIConfiguration to check domain-controller audit policy settings because incorrect settings can create Event Log gaps and reduce Defender for Identity coverage. The research record locates this support at Check domain configuration via PowerShell.\n\nKeep the evidence boundary at these traced claims. They support a review of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows; they do not support conclusions outside the source’s stated conditions.\nWhat the source does not establish\nThe source is a quarterly or ad-hoc guide; local cadence, supported server roles, permissions, and remediation ownership still require an environment-specific operating procedure. Do not read the source as proof of implementation or permission to change production. Its guidance remains conditional on Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing and the environment’s recorded constraints.\nApplicability questions\n\nFor source statement 1 at Review server setup process to include sensors, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Check domain configuration via PowerShell, which observable configuration, record, or test can confirm applicability here?\nWhat inventory proves which parts of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows are in and out of scope?\nWhich condition in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing must be healthy before evidence is trustworthy?\nWhat result would disprove the working assumption and return the issue to the owner?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.\nIf the review warrants change, use a bounded implementation with prerequisites, test population, monitoring, abort criteria, and a rehearsed reversal. Sequence checks for Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing and sanitize protected material before retention.\nVerification and evidence\nA reviewer should be able to retrace the decision from Review server setup process to include sensors; Check domain configuration via PowerShell through alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure. Record what was collected, where, when, by whom, and which system or role it represents.\nRecord the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.\nOfficial references\n\nQuarterly or ad-hoc operational guide for Microsoft Defender for Identity — Microsoft",
                "datePublished": "2026-08-27T12:14:32+00:00",
                "dateModified": "2026-08-27T12:58:58+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 549,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Quarterly or ad-hoc operational guide for Microsoft Defender for Identity",
                    "url": "https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-quarterly",
                    "datePublished": "2026-07-02"
                }
            }
        ]
    }
}