Microsoft Defender for Identity Installation
IT Partner deploys Microsoft Defender for Identity in your environment: sensors installed on your domain controllers and AD FS/AD CS servers, configuration in the unified Microsoft Defender portal, detection validation, and a handover briefing. Fixed price $3,950 per project, about 1 week. Requires eligible licensing (Microsoft Defender for Identity standalone, EMS E5, or Microsoft 365 E5/A5/G5).
What this engagement is
Microsoft Defender for Identity helps protect IT infrastructure from information threats and cyberattacks by identifying three main types of threats: cyberattacks, abnormal activities and problems, and security risks. Defender for Identity technologies can detect suspicious activity at different stages of an attack, including infrastructure reconnaissance, malware implementation through software vulnerabilities or unsafe settings, and domain management activity where an attacker collects information to resume an attack using different credentials, entry points, and vulnerabilities. The objective of this service is to plan, design, and implement Microsoft Defender for Identity service.
Success criteria
What you receive
How the work unfolds
Confirm scope, stakeholders, target schedule, change windows, access requirements, licensing status, and customer responsibilities. Review the intended Defender for Identity deployment approach and agree how issues and approvals will be handled during the 1 week engagement.
Review the Active Directory environment, domain controller placement, network topology, expected traffic visibility, server readiness, and security constraints that may affect Defender for Identity component placement. Identify prerequisites, access needs, and any customer-controlled network changes required before installation.
Validate or prepare required servers, operating system readiness, service accounts, domain permissions, DNS and time synchronization, firewall rules, and network traffic visibility as applicable to the approved Defender for Identity architecture. Confirm that required licenses and installation media are available.
Install and configure the required Defender for Identity components according to the agreed design. Connect Defender for Identity to the Active Directory environment, configure initial collection and monitoring settings, and verify that the Microsoft Defender portal is accessible to authorized administrators.
Validate Defender for Identity services, console access, component connectivity, domain data collection, and the ability to view reports and notifications in the Microsoft Defender portal. Resolve installation or configuration issues within the agreed scope and provide a basic administrator introduction to working with Defender for Identity in the Microsoft Defender portal.
Prerequisites
Who does what
IT Partner
- Customer infrastructure research for developing appropriate architecture solution
- Defender for Identity architecture design
- Preparation of the environment for the Defender for Identity installation
- Installation and configuration of the Defender for Identity service
- Basic administrator introduction to working with Defender for Identity in the Microsoft Defender portal
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner
- Coordinate any outside vendor resources and schedules
- Configure all networking equipment, such as load balancers, routers, firewalls, and switches
- Review and approve engagement deliverables in a timely manner
What's not included
Limitations & technical notes
Frequently asked questions
What is included in IT Partner’s Microsoft Defender for Identity Installation service?
The service includes infrastructure research, Defender for Identity architecture design, environment preparation, installation and configuration of the Defender for Identity service — with sensors on in-scope domain controllers and AD FS/AD CS servers — and a basic administrator introduction to working with Defender for Identity in the Microsoft Defender portal.
How long does the Microsoft Defender for Identity Installation engagement take?
The stated duration is 1 week. The plan may vary depending on the customer’s needs and environment, so any schedule dependencies are confirmed with IT Partner during scoping or kickoff.
How much does the Microsoft Defender for Identity Installation service cost?
The service is a fixed price of $3,950 per project for the stated 1-week implementation scope. Any items outside the published scope are confirmed with IT Partner before the engagement starts.
What is the main objective of this service?
The objective is to plan, design, and implement Microsoft Defender for Identity for the customer environment. Defender for Identity helps identify cyberattacks, abnormal activities and problems, and security risks across on-premises Active Directory identity infrastructure.
What types of threats can Microsoft Defender for Identity help identify after installation?
Microsoft Defender for Identity helps identify three main categories of threats: cyberattacks, abnormal activities and problems, and security risks. It can detect suspicious activity at different attack stages, including infrastructure reconnaissance, malware implementation through vulnerabilities or unsafe settings, and suspicious domain management activity.
What are the success criteria for this service?
The stated success criteria are that Microsoft Defender for Identity sensors are installed successfully on in-scope domain controllers and that the administrator can use the Microsoft Defender portal to view reports and notifications. Completion is defined around installation and administrator access to Defender for Identity reporting, not a guaranteed threat-detection outcome.
Is the Microsoft Defender for Identity license included in the service price?
No — Microsoft Defender for Identity licensing is not included. Eligible licensing (Defender for Identity standalone, EMS E5, or Microsoft 365 E5/A5/G5) must be in place or planned before installation begins; confirm procurement responsibilities with IT Partner.
Does this service include creating or providing an on-premises or hybrid Active Directory domain?
No, an on-premises or hybrid Active Directory domain is not included in the service. If your environment does not already have the required domain configuration, confirm with IT Partner whether additional work is needed before Defender for Identity can be installed.
Are there any prerequisites for the Microsoft Defender for Identity Installation service?
Yes: an existing on-premises or hybrid Active Directory Domain Services environment, eligible Defender for Identity licensing, administrative access for assessment and installation, supported servers with adequate capacity, working network connectivity, name resolution and time synchronization between components, required traffic visibility (such as port mirroring where used), and completed change approvals and maintenance windows.
What responsibilities does the customer have during the Defender for Identity installation?
The customer coordinates internal resources and staff schedules, provides a dedicated point of contact, coordinates outside vendor resources, configures networking equipment such as load balancers, routers, firewalls, and switches, and reviews and approves deliverables in a timely manner.
Does this service include remediation of threats found by Defender for Identity?
No, threat remediation is not an included deliverable. The engagement focuses on planning, designing, installing, and configuring Defender for Identity so administrators can view reports and notifications in the Microsoft Defender portal.
What happens after the Microsoft Defender for Identity installation is complete?
After completion, the administrator can use the Microsoft Defender portal to view reports and notifications, and IT Partner provides a basic administrator introduction to working with Defender for Identity. Ongoing monitoring, 24/7 support, and ongoing maintenance are not included by default, but are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.