Skip to main content
πŸ¦‰
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
πŸ¦‰
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❀️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center β€’ Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1193410

Automatic Windows event auditing configuration availability for unified sensors (V3.x)

Informational

Message ID

MC1193410
View in Admin Center

Services

Microsoft Defender XDR

Summary

Microsoft Defender for Identity unified sensors (v3.x) will offer an opt-in feature from mid-January 2026 to automatically configure Windows event-auditing settings, simplifying deployment and ensuring consistent policy enforcement. Admins must enable it via UI or Graph API; rollout completes by end of January 2026.

Details

Updated January 6, 2026: We have updated the timeline. Thank you for your patience. 

Introduction

WeÒ€ℒre introducing a new opt-in feature for automatic event-auditing configuration in Microsoft Defender for Identity unified sensors (v3.x). This enhancement simplifies deployment by automatically applying the required Windows event-auditing settings on sensors, reducing manual post-deployment steps and ensuring consistent policy enforcement across all onboarded sensors.

When this will happen:

  • General Availability (Worldwide, GCC, GCCH, and DoD): The auditing opt-in feature will be available starting mid-January 2026 (previously early January), with rollout expected to complete by end of January 2026 (previously mid-January). Until then, it will remain disabled in the portal.
  • Related auditing health alerts will also roll out gradually starting mid-January 2026 (previously early January), completing by end of January 2026 (previously mid-January).

How this affects your organization:

Who is affected: Admins managing Defender for Identity unified sensors (v3.x) in Microsoft 365 tenants.

What will happen:

  • A new opt-in setting will be available in both the UI and via Graph API.
  • In the UI, this option will appear under Defender for Identity Settings Ò†’ Advanced features.
  • Once enabled, the automatic configuration feature will:
    • For new sensor activations: Automatically apply all required Windows event-auditing settings during activation.
    • For existing onboarded sensors: Automatically apply Windows event-auditing settings only if misconfigured and dismiss related health issues.
  • After enabling the toggle, the automatic configuration process may take up to 24 hours to apply across all applicable Identity Unified sensors (v3.x).
  • This feature is not enabled by default and requires admin action. No changes will occur unless admins choose to enable the feature.

Relevant auditing configurations health issues covered:

  • NTLM auditing is not enabled
  • Directory Services Advanced Auditing is not enabled as required
  • Directory Services Object Auditing is not enabled as required
  • Auditing on the Configuration container is not enabled as required
  • Auditing on the ADFS container is not enabled as required

What you can do to prepare:

No action is required unless you choose to enable the feature.

If you plan to opt in:

  • Review your unified sensor deployment strategy.
  • Enable the opt-in setting via the UI or Graph API.
  • Communicate the change to relevant IT and security teams.
  • Update internal documentation if you track auditing configurations.

Learn more:

  • Auditing health alerts documentation
  • Configure Windows event auditing
  • Configure audit policies for Windows event logs

Compliance considerations:

No compliance considerations identified, review as appropriate for your organization.

Timeline

πŸ“…
Published
Dec 9, 2025
Message published to Message Center
✏️
Updated
Jan 6, 2026
Message content updated
🏁
End Date
Mar 2, 2026
Message timeline ends

Tags

#Updated message#Feature update#Admin impact

Category

πŸ“–Stay Informed

Related Messages

Similar updates

MC1192257●

Microsoft Defender Threat Intelligence: Convergence with Microsoft Defender and Microsoft Sentinel

Dec 5, 2025
MC1171845

Microsoft Defender for Office 365: Enhancing the quarantine experience for administrators

Oct 13, 2025
MC1166867

Microsoft Defender for Office 365: Enhancing the quarantine email preview experience

Oct 6, 2025
MC1155429

Microsoft Defender for Identity: New recommendations added to Microsoft Secure Score

Sep 18, 2025
MC1200058

Microsoft Defender for Office 365: Admins can block external users in Microsoft Teams from Defender Portal

Dec 19, 2025