First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft Defender for Identity Implementation
Security and Protection

Microsoft Defender for Identity Installation

IT Partner deploys Microsoft Defender for Identity in your environment: sensors installed on your domain controllers and AD FS/AD CS servers, configuration in the unified Microsoft Defender portal, detection validation, and a handover briefing. Fixed price $3,950 per project, about 1 week. Requires eligible licensing (Microsoft Defender for Identity standalone, EMS E5, or Microsoft 365 E5/A5/G5).

Timeline 7 daysService owner Roman SotnikManaged Services

What this engagement is

Microsoft Defender for Identity helps protect IT infrastructure from information threats and cyberattacks by identifying three main types of threats: cyberattacks, abnormal activities and problems, and security risks. Defender for Identity technologies can detect suspicious activity at different stages of an attack, including infrastructure reconnaissance, malware implementation through software vulnerabilities or unsafe settings, and domain management activity where an attacker collects information to resume an attack using different credentials, entry points, and vulnerabilities. The objective of this service is to plan, design, and implement Microsoft Defender for Identity service.

Success criteria

01Microsoft Defender for Identity sensors installed successfully on in-scope domain controllers
02The administrator may use the Microsoft Defender portal to view reports and notifications

What you receive

Customer infrastructure research for developing appropriate architecture solution
Defender for Identity architecture design
Preparation of the environment for the Defender for Identity installation
Installation and configuration of the Defender for Identity service
Basic administrator introduction to working with Defender for Identity in the Microsoft Defender portal

How the work unfolds

Kickoff meeting

Confirm scope, stakeholders, target schedule, change windows, access requirements, licensing status, and customer responsibilities. Review the intended Defender for Identity deployment approach and agree how issues and approvals will be handled during the 1 week engagement.

Infrastructure research

Review the Active Directory environment, domain controller placement, network topology, expected traffic visibility, server readiness, and security constraints that may affect Defender for Identity component placement. Identify prerequisites, access needs, and any customer-controlled network changes required before installation.

Preparation of the environment

Validate or prepare required servers, operating system readiness, service accounts, domain permissions, DNS and time synchronization, firewall rules, and network traffic visibility as applicable to the approved Defender for Identity architecture. Confirm that required licenses and installation media are available.

Defender for Identity installation and configuration

Install and configure the required Defender for Identity components according to the agreed design. Connect Defender for Identity to the Active Directory environment, configure initial collection and monitoring settings, and verify that the Microsoft Defender portal is accessible to authorized administrators.

Verifying and fixing issues

Validate Defender for Identity services, console access, component connectivity, domain data collection, and the ability to view reports and notifications in the Microsoft Defender portal. Resolve installation or configuration issues within the agreed scope and provide a basic administrator introduction to working with Defender for Identity in the Microsoft Defender portal.

Prerequisites

Confirm that an existing on-premises or hybrid Active Directory Domain Services environment is available and ready for Defender for Identity integration.
Confirm that required Microsoft Defender for Identity licensing is available or can be provided before installation begins.
Customer provides administrative access required to assess Active Directory, prepare the Defender for Identity servers, install Defender for Identity components, and configure required service accounts or permissions.
Confirm that servers or virtual machines for the selected Defender for Identity architecture are available with supported operating system, storage, CPU, memory, and network connectivity.
Confirm that network connectivity, firewall rules, name resolution, and time synchronization are in place between Defender for Identity components, domain controllers, and administrator workstations.
Confirm that required traffic visibility is available for Defender for Identity components, including port mirroring or equivalent network configuration where dedicated network traffic monitoring is used.
Customer change approvals, maintenance windows, and internal security approvals are completed before production installation work begins.

Who does what

IT Partner

  • Customer infrastructure research for developing appropriate architecture solution
  • Defender for Identity architecture design
  • Preparation of the environment for the Defender for Identity installation
  • Installation and configuration of the Defender for Identity service
  • Basic administrator introduction to working with Defender for Identity in the Microsoft Defender portal

Your team

  • Coordinate Client resources and staff schedules
  • Provide a dedicated point of contact responsible for working with IT Partner
  • Coordinate any outside vendor resources and schedules
  • Configure all networking equipment, such as load balancers, routers, firewalls, and switches
  • Review and approve engagement deliverables in a timely manner

What's not included

Microsoft Defender for Identity licensing
On-premises or hybrid Active Directory domain
24/7 support, continuous monitoring, and ongoing maintenance are not included by default; they are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.

Limitations & technical notes

!The plan may vary depending on your needs.
!This service deploys the current Microsoft Defender for Identity sensor. The legacy Advanced Threat Analytics (ATA) product is out of mainstream support and is not what this service installs.
!This installation service enables Defender for Identity deployment and administrator access to Defender for Identity reports and notifications; it does not guarantee detection of every attack technique or replace ongoing security operations, incident response, or identity security hardening.
!Defender for Identity detection quality depends on Active Directory health, correct component placement, network traffic visibility, time synchronization, and the completeness of collected domain controller activity.
!Customer-controlled network device configuration, such as switch port mirroring, firewall rules, router changes, and load balancer changes, remains the client responsibility unless separately scoped.

Frequently asked questions

What is included in IT Partner’s Microsoft Defender for Identity Installation service?

The service includes infrastructure research, Defender for Identity architecture design, environment preparation, installation and configuration of the Defender for Identity service — with sensors on in-scope domain controllers and AD FS/AD CS servers — and a basic administrator introduction to working with Defender for Identity in the Microsoft Defender portal.

How long does the Microsoft Defender for Identity Installation engagement take?

The stated duration is 1 week. The plan may vary depending on the customer’s needs and environment, so any schedule dependencies are confirmed with IT Partner during scoping or kickoff.

How much does the Microsoft Defender for Identity Installation service cost?

The service is a fixed price of $3,950 per project for the stated 1-week implementation scope. Any items outside the published scope are confirmed with IT Partner before the engagement starts.

What is the main objective of this service?

The objective is to plan, design, and implement Microsoft Defender for Identity for the customer environment. Defender for Identity helps identify cyberattacks, abnormal activities and problems, and security risks across on-premises Active Directory identity infrastructure.

What types of threats can Microsoft Defender for Identity help identify after installation?

Microsoft Defender for Identity helps identify three main categories of threats: cyberattacks, abnormal activities and problems, and security risks. It can detect suspicious activity at different attack stages, including infrastructure reconnaissance, malware implementation through vulnerabilities or unsafe settings, and suspicious domain management activity.

What are the success criteria for this service?

The stated success criteria are that Microsoft Defender for Identity sensors are installed successfully on in-scope domain controllers and that the administrator can use the Microsoft Defender portal to view reports and notifications. Completion is defined around installation and administrator access to Defender for Identity reporting, not a guaranteed threat-detection outcome.

Is the Microsoft Defender for Identity license included in the service price?

No — Microsoft Defender for Identity licensing is not included. Eligible licensing (Defender for Identity standalone, EMS E5, or Microsoft 365 E5/A5/G5) must be in place or planned before installation begins; confirm procurement responsibilities with IT Partner.

Does this service include creating or providing an on-premises or hybrid Active Directory domain?

No, an on-premises or hybrid Active Directory domain is not included in the service. If your environment does not already have the required domain configuration, confirm with IT Partner whether additional work is needed before Defender for Identity can be installed.

Are there any prerequisites for the Microsoft Defender for Identity Installation service?

Yes: an existing on-premises or hybrid Active Directory Domain Services environment, eligible Defender for Identity licensing, administrative access for assessment and installation, supported servers with adequate capacity, working network connectivity, name resolution and time synchronization between components, required traffic visibility (such as port mirroring where used), and completed change approvals and maintenance windows.

What responsibilities does the customer have during the Defender for Identity installation?

The customer coordinates internal resources and staff schedules, provides a dedicated point of contact, coordinates outside vendor resources, configures networking equipment such as load balancers, routers, firewalls, and switches, and reviews and approves deliverables in a timely manner.

Does this service include remediation of threats found by Defender for Identity?

No, threat remediation is not an included deliverable. The engagement focuses on planning, designing, installing, and configuring Defender for Identity so administrators can view reports and notifications in the Microsoft Defender portal.

What happens after the Microsoft Defender for Identity installation is complete?

After completion, the administrator can use the Microsoft Defender portal to view reports and notifications, and IT Partner provides a basic administrator introduction to working with Defender for Identity. Ongoing monitoring, 24/7 support, and ongoing maintenance are not included by default, but are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$3,950 per project
7 days
Book a meeting