Defender for Identity Sensors
Defender for Identity sensors collect signals from domain controllers, AD FS, AD CS, and related identity infrastructure for identity threat detection and investigation.
capabilitiesCurrent
Relationships
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Supported | Reference |
| REST API | Gap | Sensor deployment and directory service account setup are host/tenant operations, not a public Defender REST configuration resource. |
| Graph | Supported | Reference |
| ARM | Gap | No ARM resource is recorded for this capability. |
| Bicep | Gap | No Bicep resource is recorded for this capability. |
| Terraform | Gap | Sensor deployment and directory service account configuration have no ARM/Terraform/Graph desired-state surface. Treat as manual/scripted PowerShell plus host configuration, not tenant IaC. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |