# Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews

> Use Quarterly or ad-hoc operational guide for Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.

- Canonical URL: https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-27T12:14:32+00:00
- Modified: 2026-08-27T12:58:58+00:00
- Last reviewed by DSE: 2026-08-26
- Resource type: Guide
- DSE priority: Advisory
- Topics: Cybersecurity, IT, Microsoft 365 & Identity
- Reading time: 3 minutes

## What you need to know

Use Quarterly or ad-hoc operational guide for Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.

## Potentially affected

Teams, systems, services, or facilities within the stated scope of Quarterly or ad-hoc operational guide for Microsoft Defender for Identity

## DSE recommendation

Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.

## Article

Use this document to connect an official requirement or behavior to observable evidence: Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews. Only the official source and traced locations below supply facts. Confirm applicability before acting.

## Source fact:

The official [Quarterly or ad-hoc operational guide for Microsoft Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-quarterly) from Microsoft supports the following bounded statements:

- Microsoft recommends periodically verifying that the server setup process installs Defender for Identity sensors on new domain controllers, AD CS servers, and AD FS servers. The research record locates this support at Review server setup process to include sensors.

- Microsoft recommends periodically running Test-MDIConfiguration to check domain-controller audit policy settings because incorrect settings can create Event Log gaps and reduce Defender for Identity coverage. The research record locates this support at Check domain configuration via PowerShell.

Keep the evidence boundary at these traced claims. They support a review of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows; they do not support conclusions outside the source’s stated conditions.

## What the source does not establish

The source is a quarterly or ad-hoc guide; local cadence, supported server roles, permissions, and remediation ownership still require an environment-specific operating procedure. Do not read the source as proof of implementation or permission to change production. Its guidance remains conditional on Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing and the environment’s recorded constraints.

## Applicability questions

- For source statement 1 at Review server setup process to include sensors, which observable configuration, record, or test can confirm applicability here?

- For source statement 2 at Check domain configuration via PowerShell, which observable configuration, record, or test can confirm applicability here?

- What inventory proves which parts of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows are in and out of scope?

- Which condition in Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing must be healthy before evidence is trustworthy?

- What result would disprove the working assumption and return the issue to the owner?

## DSE recommendation:

DSE recommends using the cited source as the evidence anchor for this decision. Anchor the review in the cited section and keep observation separate from interpretation. Record the source location, examined part of identity alerts, investigations, remediation roles, evidence retention, escalation, exclusions, and incident workflows, observed and expected states, owner, and reason for deviation.

If the review warrants change, use a bounded implementation with prerequisites, test population, monitoring, abort criteria, and a rehearsed reversal. Sequence checks for Active Directory, Windows DNS, time, cloud portals, endpoint data, network telemetry, privileged access, and response staffing and sanitize protected material before retention.

## Verification and evidence

A reviewer should be able to retrace the decision from Review server setup process to include sensors; Check domain configuration via PowerShell through alert records, investigation timelines, analyst actions, tuning or exclusion approvals, remediation results, and case closure. Record what was collected, where, when, by whom, and which system or role it represents.

Record the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.

## Official references

- [Quarterly or ad-hoc operational guide for Microsoft Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-quarterly) — Microsoft

## Primary reference

- Name: Quarterly or ad-hoc operational guide for Microsoft Defender for Identity
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-for-identity/ops-guide/ops-guide-quarterly
- Source publication date: 2026-07-02

## Citation and use

Preferred citation: “Add sensor onboarding and Test-MDIConfiguration to identity-platform reviews,” DSE Security, https://update.dsesecurity.com/updates/add-sensor-onboarding-test-mdiconfiguration-identity-reviews/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
