Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1073068

Microsoft Defender for Identity: We will disable collection of local administrators' group members (using SAM-R)

Plan for Change

Message ID

MC1073068
View in Admin Center

Services

Microsoft Defender XDR

Summary

Microsoft Defender for Identity will disable the remote collection of local administrators' group members using SAM-R queries starting early May 2025. This change will impact the ability to map potential lateral movement paths. No admin action is required unless NTLM is disabled and you need the feature reenabled.

Details

Updated July 18, 2025: We have updated the content. Thank you for your patience.

In Microsoft Defender for Identity, we have started to disable the remote collection of local administrators' group members on endpoints (using SAM-R queries). We started disabling the feature in early May 2025 and expect to complete by mid-May 2025.This change is part of our ongoing efforts to enhance security and improve the overall performance of our services.

How this will affect your organization:

This feature performs remote queries to identify local administrators on the remote machines contacting the servers where the Defender for Identity sensor is installed. The details collected are used to build the potential lateral movement paths map.

Disabling this feature will impact the ability to map potential lateral movement paths (using SAM-R queries) because the data used to calculate potential lateral movement paths will no longer be collected by the Defender for Identity sensor.

What you need to do to prepare:

This change will happen automatically by the specified dates. No admin action is required.

Timeline

📅
Published
May 13, 2025
Message published to Message Center
✏️
Updated
Jul 18, 2025
Message content updated
🏁
End Date
Aug 29, 2025
Message timeline ends

Tags

#Updated message#Feature update#Admin impact

Category

📋Plan for Change

Related Messages

Similar updates

MC1057719

MDE Mobile: Open Wi-Fi and Certificate Detections will be logged as Events

Apr 18, 2025
MC1052160●

Microsoft Defender XDR services: Changes to the IdentityInfo table in Advanced Hunting

Apr 10, 2025
MC1042926

Microsoft Defender for Office 365: Platform migration for enhanced data storage and performance

Mar 28, 2025
MC1036568

Updates to App Governance Pre-Defined Policies in Defender for Cloud Apps

Mar 19, 2025
MC1023484

Microsoft Defender for Identity: New recommendations for Microsoft Secure Score

Mar 5, 2025