Defender for Identity v3.x Can Now Onboard Without Defender for Endpoint
Microsoft has added a preview option to activate the Defender for Identity v3.x sensor on domain controllers without onboarding them to Defender for Endpoint first, removing a major deployment blocker for MSPs.
A long standing blocker just went away
Since Microsoft rebuilt the Defender for Identity sensor around the Defender for Endpoint (MDE) agent in v3.x, deploying it on a domain controller has meant onboarding that DC to Defender for Endpoint first. For MSPs whose clients run a different EDR on domain controllers, or who simply are not ready to extend full endpoint protection to identity infrastructure, that dependency has been a real obstacle to getting identity threat detection turned on. As of September 2026, Microsoft has removed that requirement, currently in public preview.
The new capability, sensor v3.x onboarding without Microsoft Defender for Endpoint deployment, lets you activate the Defender for Identity sensor directly on eligible domain controllers running Windows Server 2019 or later, without touching Defender for Endpoint at all.
The process runs through the Defender portal:
- On the Sensor management tab of the On-premises page, select Download onboarding package.
- Choose Windows Server 2019 or later, name the package, and generate it.
- Copy the package and access key to the target domain controller.
- Extract the package, keeping the resources subfolder intact.
- From an elevated PowerShell session, run the DefenderForIdentityV3StandaloneOnboardingScript.cmd script and paste in the access key when prompted.
Everything else about v3.x still applies. The domain controller needs the July 2026 or later cumulative update, no existing v2.x sensor, and a qualifying license such as EMS E5, Microsoft 365 E5, a relevant Security add-on, or a standalone Defender for Identity license. Network connectivity requirements are unchanged as well, since the sensor still communicates over the same URIs as Defender for Endpoint even when MDE itself is not onboarded.
If a client later wants full Defender for Endpoint on that DC, Microsoft has documented a supported path: offboard the domain controller, onboard it to Defender for Endpoint, then reactivate the v3.x sensor.
For MSPs juggling tenants at different stages of Microsoft security adoption, this is worth testing now. It remains a preview feature, so pilot it on a non critical domain controller before writing it into a standard baseline. Which of your client tenants have identity coverage sitting idle purely because their domain controllers were never onboarded to Defender for Endpoint?