Microsoft Defender for Identity Implementation — AD Threat Detection
Microsoft Defender for Identity Implementation is a 14-day service for organizations deploying Defender for Identity to protect their on-premises Active Directory identities. IT Partner assesses the tenant, plans sensor capacity, activates the Defender for Identity workspace in the Microsoft Defender portal, configures its settings, connects it to Windows Server Active Directory, installs sensors on in-scope domain controllers (and AD FS/AD CS servers where in scope), and sets up monitoring protocols to support threat detection and incident response — with alerts and identity threat detection surfacing in the unified Microsoft Defender portal.
What this engagement is
This service deploys Microsoft Defender for Identity within the organization's infrastructure. Defender for Identity provides visibility into user and entity activities across the network by analyzing authentication and authorization signals to identify potential threats and suspicious behaviors. IT Partner performs an assessment, configures Defender for Identity based on the environment, connects it to Windows Server Active Directory, installs sensors on in-scope domain controllers (and AD FS/AD CS servers where applicable), configures settings and preferences in the unified Microsoft Defender portal, and implements monitoring protocols for threats identified by Defender for Identity.
Success criteria
What you receive
How the work unfolds
Plan capacity requirements for Defender for Identity sensors based on domain controller load and the in-scope identity infrastructure.
Activate the Defender for Identity workspace, which is provisioned in the Microsoft Defender portal.
Connect Defender for Identity to Windows Server Active Directory with the required directory service accounts and permissions.
Install Defender for Identity sensors on in-scope domain controllers and, where applicable, AD FS/AD CS servers.
Configure Defender for Identity settings, notifications, and preferences in the Microsoft Defender portal.
Prerequisites
Who does what
IT Partner
- Perform a detailed assessment of the tenant and determine what resources you need for your Microsoft Defender for Identity sensors.
- Configure Defender for Identity settings based on the assessment, ensuring optimal alignment with the organization's environment.
- Implement monitoring protocols to detect and respond to potential threats identified by Defender for Identity.
Your team
- Grant necessary access and permissions to the IT Partner for the deployment process.
- Collaborate with the IT Partner during the configuration phase, providing insights into specific environment requirements.
What's not included
Limitations & technical notes
Frequently asked questions
What is included in the Microsoft Defender for Identity Implementation service?
The service includes tenant assessment, capacity planning for Defender for Identity sensors, activation of the Defender for Identity workspace in the Microsoft Defender portal, connection to Windows Server Active Directory, sensor installation on in-scope domain controllers, configuration of settings and preferences, and monitoring protocol setup. IT Partner configures Defender for Identity based on the organization’s environment to support threat detection and incident response.
How long does the Microsoft Defender for Identity Implementation take?
Microsoft Defender for Identity Implementation is a 14-day service. The timeline covers assessment, planning, workspace activation, Active Directory connection, sensor installation, portal configuration, and monitoring protocol setup within the stated project scope.
How much does the Microsoft Defender for Identity Implementation cost?
The Microsoft Defender for Identity Implementation service is priced at $2,900 per project, quoted fixed-price in writing before work begins.
What is Microsoft Defender for Identity used for in this implementation?
Microsoft Defender for Identity protects on-premises identities in Windows Server Active Directory — including AD FS and AD CS where in scope — by analyzing authentication and authorization signals to surface suspicious behavior. Alerts and identity threat detection appear in the unified Microsoft Defender portal, where IT Partner configures the service so the organization can detect threats and support incident response.
What prerequisites are required before starting the Defender for Identity implementation?
The organization must have eligible licensing, such as Enterprise Mobility + Security E5/A5, Microsoft 365 E5/A5/G5, Microsoft 365 E5/A5/G5 Security, or standalone Defender for Identity licenses. Licensing requirements should be confirmed against Microsoft’s Defender for Identity licensing documentation before the engagement begins.
Does this service include Defender for Identity licensing?
No. Licensing is a prerequisite and is not included in the $2,900 project price. Customers should confirm licensing status with IT Partner before the project starts, because Defender for Identity requires eligible Microsoft licensing or standalone Defender for Identity licenses.
Are Defender for Identity sensors installed as part of the service?
Yes. IT Partner installs the current Microsoft Defender for Identity sensor on in-scope domain controllers — and AD FS/AD CS servers where in scope — after planning the required capacity and resources. Sensor installation is one of the defined milestones and deliverables of the engagement.
What configuration is performed in the Microsoft Defender portal?
IT Partner configures Defender for Identity settings, notifications, and preferences in the unified Microsoft Defender portal, where Defender for Identity is managed. The configuration is based on the assessment and aligned with the organization’s environment and monitoring needs.
What monitoring setup is included after Defender for Identity is deployed?
IT Partner implements monitoring protocols to detect and respond to potential threats identified by Microsoft Defender for Identity. Continuous monitoring, 24/7 support, 24x7 alert triage, and ongoing maintenance after project completion are not included by default; these may be available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
What responsibilities does the customer have during the Defender for Identity implementation?
The customer must grant the necessary access and permissions for IT Partner to perform the deployment, and collaborate during configuration by providing information about environment-specific requirements.
Is downtime expected during the Defender for Identity implementation?
Sensor installation is planned to minimize business impact. Prerequisite installation, server condition, security software conflicts, or required maintenance windows can affect scheduling and could require server restarts in some environments, so change windows are agreed with the customer in advance.
What is not included in the Microsoft Defender for Identity Implementation service?
The service does not include Defender for Identity licensing, Microsoft 365 licensing, Azure consumption, remediation of security findings, Active Directory hardening, domain controller upgrades, broader Microsoft security workload configuration, third-party integrations, or ongoing managed monitoring by default. Continuous monitoring, 24/7 support, and incident response retainers may be available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.