MC1193410 – (Updated) Automatic Windows event auditing configuration availability for unified sensors (V3.x) (archived)

cloudscout.one Icon

check before: 2026-01-15

Product:

Defender, Defender for Identity, Defender XDR, Entra, Microsoft Graph, Purview Audit (Premium), Windows

Platform:

Developer, Online, US Instances, World tenant

Status:

Change type:

Admin impact, Feature update, Updated message

Links:

Details:

Summary:
Microsoft Defender for Identity unified sensors (v3.x) will offer an opt-in feature from mid-January 2026 to automatically configure Windows event-auditing settings, simplifying deployment and ensuring consistent policy enforcement. Admins must enable it via UI or Graph API; rollout completes by end of January 2026.

Details:
Updated January 6, 2026: We have updated the timeline. Thank you for your patience.
[Introduction]
We're introducing a new opt-in feature for automatic event-auditing configuration in Microsoft Defender for Identity unified sensors (v3.x). This enhancement simplifies deployment by automatically applying the required Windows event-auditing settings on sensors, reducing manual post-deployment steps and ensuring consistent policy enforcement across all onboarded sensors.
[When this will happen:]
General Availability (Worldwide, GCC, GCCH, and DoD): The auditing opt-in feature will be available starting mid-January 2026 (previously early January), with rollout expected to complete by end of January 2026 (previously mid-January). Until then, it will remain disabled in the portal.
Related auditing health alerts will also roll out gradually starting mid-January 2026 (previously early January), completing by end of January 2026 (previously mid-January).

Change Category:
XXXXXXX ... free basic plan only

Scope:
XXXXXXX ... free basic plan only

Release Phase:

Created:
2025-12-09

updated:
2026-01-07

Task Type

XXXXXXX ... free basic plan only

Docu to Check

XXXXXXX ... free basic plan only

MS How does it affect me

XXXXXXX ... free basic plan only

MS Preperations

XXXXXXX ... free basic plan only

MS Urgency

XXXXXXX ... free basic plan only

MS workload name

XXXXXXX ... free basic plan only

summary for non-techies**

Microsoft Defender for Identity is introducing a feature that automatically configures Windows event-auditing settings for new sensors and checks existing ones for compliance, reducing manual work for IT admins, but requires opt-in and may take up to 24 hours to apply changes.

Direct effects for Operations**

Automatic Configuration of Windows Event Auditing
If the automatic configuration feature is enabled without proper preparation, it may lead to misconfigured auditing settings, resulting in potential security gaps and compliance issues.
   - roles: IT Admin, Security Analyst
   - references: https://learn.microsoft.com/defender-for-identity/deploy/configure-windows-event-collection, https://learn.microsoft.com/defender-for-identity/deploy/prerequisites-sensor-version-3#configure-windows-event-auditing

Delayed Application of Auditing Settings
The automatic configuration process may take up to 24 hours to apply, which could leave systems vulnerable during this period if the feature is enabled without prior assessment.
   - roles: IT Admin, Compliance Officer
   - references: https://learn.microsoft.com/defender-for-identity/deploy/configure-windows-event-collection, https://learn.microsoft.com/defender-for-identity/health-alerts

Configutation Options**

XXXXXXX ... paid membership only

Data Protection**

XXXXXXX ... paid membership only

IT Security**

XXXXXXX ... paid membership only

explanation for non-techies**

XXXXXXX ... free basic plan only

** AI generated content. This information must be reviewed before use.

a free basic plan is required to see more details. Sign up here


A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.



change history

DatePropertyoldnew
2026-01-07MC MessageTagNamesFeature update, Admin impactUpdated message, Feature update, Admin impact
2026-01-07MC SummaryStarting January 2026, Microsoft Defender for Identity unified sensors (v3.x) will offer an opt-in feature for automatic Windows event-auditing configuration, simplifying deployment by auto-applying required settings on new and misconfigured existing sensors. Admins must enable this feature via UI or Graph API.Microsoft Defender for Identity unified sensors (v3.x) will offer an opt-in feature from mid-January 2026 to automatically configure Windows event-auditing settings, simplifying deployment and ensuring consistent policy enforcement. Admins must enable it via UI or Graph API; rollout completes by end of January 2026.
2026-01-07MC Last Updated12/09/2025 01:14:042026-01-06T18:31:48Z
2026-01-07MC Messages[Introduction]
We're introducing a new opt-in feature for automatic event-auditing configuration in Microsoft Defender for Identity unified sensors (v3.x). This enhancement simplifies deployment by automatically applying the required Windows event-auditing settings on sensors, reducing manual post-deployment steps and ensuring consistent policy enforcement across all onboarded sensors.
[When this will happen:]
General Availability (Worldwide, GCC, GCCH, and DoD): The auditing opt-in feature will be available starting early January 2026, with rollout expected to complete by mid-January 2026. Until then, it will remain disabled in the portal.
Related auditing health alerts will also roll out gradually starting early January 2026, completing by mid-January 2026.
Updated January 6, 2026: We have updated the timeline. Thank you for your patience.
[Introduction]
We're introducing a new opt-in feature for automatic event-auditing configuration in Microsoft Defender for Identity unified sensors (v3.x). This enhancement simplifies deployment by automatically applying the required Windows event-auditing settings on sensors, reducing manual post-deployment steps and ensuring consistent policy enforcement across all onboarded sensors.
[When this will happen:]
General Availability (Worldwide, GCC, GCCH, and DoD): The auditing opt-in feature will be available starting mid-January 2026 (previously early January), with rollout expected to complete by end of January 2026 (previously mid-January). Until then, it will remain disabled in the portal.
Related auditing health alerts will also roll out gradually starting mid-January 2026 (previously early January), completing by end of January 2026 (previously mid-January).
2026-01-07MC TitleAutomatic Windows event auditing configuration availability for unified sensors (V3.x)(Updated) Automatic Windows event auditing configuration availability for unified sensors (V3.x)
2026-01-07MC End Time02/23/2026 09:00:002026-03-02T09:00:00Z

Last updated 2 weeks ago ago

Leave a Reply

Share to MS Teams

Login to your account

Welcome Back, We Missed You!