First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Microsoft Defender for Identity Implementation
Security and Protection

Microsoft Defender for Identity Installation

IT Partner deploys Microsoft Defender for Identity (the successor to Advanced Threat Analytics) in your environment: sensors installed on your domain controllers and AD FS/AD CS servers, portal configuration in Microsoft Defender XDR, detection validation, and a handover briefing. Fixed price $1,950, about 1 week. Requires eligible licensing (Microsoft Defender for Identity standalone, EMS E5, or Microsoft 365 E5/A5/G5).

Timeline 1 weekService owner Roman SotnikManaged Services

What this engagement is

Microsoft Defender for Identity helps protect IT infrastructure from information threats and cyberattacks by identifying three main types of threats: cyberattacks, abnormal activities and problems, and security risks. Defender for Identity technologies can detect suspicious activity at different stages of an attack, including infrastructure reconnaissance, malware implementation through software vulnerabilities or unsafe settings, and domain management activity where an attacker collects information to resume an attack using different credentials, entry points, and vulnerabilities. The objective of this service is to plan, design, and implement Microsoft Defender for Identity service. Service metadata: SKU ITPWW330IMPOT; price 1950; duration 1 week; manager Roman Sotnik; date 2019-05-15; products Managed Services; type Security and Protection.

Success criteria

01Advanced Threats Analytics installed successfully
02The administrator may use the Microsoft Defender portal to view reports and notifications

What you receive

Customer infrastructure research for developing appropriate architecture solution
Defender for Identity architecture design
Preparation of the environment for the Defender for Identity installation
Installation and configuration of the Defender for Identity service
Basic introduction of working with ATA

How the work unfolds

Kickoff meeting

Confirm scope, stakeholders, target schedule, change windows, access requirements, licensing status, and customer responsibilities. Review the intended Defender for Identity deployment approach and agree how issues and approvals will be handled during the 1 week engagement.

Infrastructure research

Review the Active Directory environment, domain controller placement, network topology, expected traffic visibility, server readiness, and security constraints that may affect Defender for Identity component placement. Identify prerequisites, access needs, and any customer-controlled network changes required before installation.

Preparation of the environment

Validate or prepare required servers, operating system readiness, service accounts, domain permissions, DNS and time synchronization, firewall rules, and network traffic visibility as applicable to the approved Defender for Identity architecture. Confirm that required licenses and installation media are available.

Defender for Identity installation and configuration

Install and configure the required Defender for Identity components according to the agreed design. Connect Defender for Identity to the Active Directory environment, configure initial collection and monitoring settings, and verify that the Microsoft Defender portal is accessible to authorized administrators.

Verifying and fixing issues

Validate Defender for Identity services, console access, component connectivity, domain data collection, and the ability to view reports and notifications in the Microsoft Defender portal. Resolve installation or configuration issues within the agreed scope and provide a basic administrator introduction to working with ATA.

Prerequisites

Confirm that an existing on-premises or hybrid Active Directory Domain Services environment is available and ready for Defender for Identity integration.
Confirm that required Microsoft Defender for Identity licensing is available or can be provided before installation begins.
Customer provides administrative access required to assess Active Directory, prepare the Defender for Identity servers, install Defender for Identity components, and configure required service accounts or permissions.
Confirm that servers or virtual machines for the selected Defender for Identity architecture are available with supported operating system, storage, CPU, memory, and network connectivity.
Confirm that network connectivity, firewall rules, name resolution, and time synchronization are in place between Defender for Identity components, domain controllers, and administrator workstations.
Confirm that required traffic visibility is available for Defender for Identity components, including port mirroring or equivalent network configuration where dedicated network traffic monitoring is used.
Customer change approvals, maintenance windows, and internal security approvals are completed before production installation work begins.

Who does what

IT Partner

  • Customer infrastructure research for developing appropriate architecture solution
  • Defender for Identity architecture design
  • Preparation of the environment for the Defender for Identity installation
  • Installation and configuration of the Defender for Identity service
  • Basic introduction of working with ATA

Your team

  • Coordinate Client resources and staff schedules
  • Provide a dedicated point of contact responsible for working with IT Partner
  • Coordinate any outside vendor resources and schedules
  • Configure all networking equipment, such as load balancers, routers, firewalls, and switches
  • Review and approve engagement deliverables in a timely manner

What's not included

Advanced Threats Analytics license
On-premises or hybrid Active Directory domain
24/7 support, continuous monitoring, and ongoing maintenance are not included by default; they are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.

Limitations & technical notes

!The plan may vary depending on your needs.
!If this service refers to Microsoft Microsoft Defender for Identity, product lifecycle, version support, and migration considerations should be confirmed before deployment, especially where Microsoft Defender for Identity may be the preferred current Microsoft security service.
!This installation service enables Defender for Identity deployment and administrator access to Defender for Identity reports and notifications; it does not guarantee detection of every attack technique or replace ongoing security operations, incident response, or identity security hardening.
!Defender for Identity detection quality depends on Active Directory health, correct component placement, network traffic visibility, time synchronization, and the completeness of collected domain controller activity.
!Customer-controlled network device configuration, such as switch port mirroring, firewall rules, router changes, and load balancer changes, remains the client responsibility unless separately scoped.

Frequently asked questions

What is included in IT Partner’s Microsoft Defender for Identity Installation service?

IT Partner’s Microsoft Defender for Identity Installation service includes infrastructure research, Defender for Identity architecture design, environment preparation, installation and configuration of the Defender for Identity service, and a basic introduction to working with ATA. The engagement is intended to plan, design, and implement Defender for Identity so the organization can begin using the Microsoft Defender portal for reports and notifications.

How long does the Microsoft Defender for Identity Installation engagement take?

The stated duration for the Microsoft Defender for Identity Installation service is 1 week. The plan may vary depending on the customer’s needs and environment, so any schedule dependencies should be confirmed with IT Partner during scoping or kickoff.

How much does the Microsoft Defender for Identity Installation service cost?

The listed price for the Microsoft Defender for Identity Installation service is 1950. This price applies to the stated 1 week implementation scope, and any items outside the published scope should be confirmed with IT Partner before the engagement starts.

What is the main objective of the Microsoft Defender for Identity Installation service?

The objective of the service is to plan, design, and implement Microsoft Defender for Identity for the customer environment. Defender for Identity is used to help identify cyberattacks, abnormal activities and problems, and security risks in IT infrastructure.

What types of threats can Microsoft Defender for Identity help identify after installation?

Microsoft Defender for Identity helps identify three main categories of threats: cyberattacks, abnormal activities and problems, and security risks. The service description notes that Defender for Identity can detect suspicious activity at different attack stages, including infrastructure reconnaissance, malware implementation through vulnerabilities or unsafe settings, and suspicious domain management activity.

What are the key milestones during the Defender for Identity installation engagement?

The implementation plan includes a kickoff meeting, infrastructure research, preparation of the environment, Defender for Identity installation and configuration, and verifying and fixing issues. The source service description lists milestone names only, so detailed milestone activities should be confirmed with IT Partner if you need a more granular project plan.

What are the success criteria for this service?

The stated success criteria are that Microsoft Defender for Identity is installed successfully and that the administrator can use the Microsoft Defender portal to view reports and notifications. These criteria define completion around installation and administrator access to Defender for Identity reporting, not around a guaranteed threat-detection outcome.

Is the Microsoft Defender for Identity license included in the service price?

No, the Advanced Threats Analytics license is listed as not included in this service. Customers should confirm licensing requirements and procurement responsibilities with IT Partner before the installation begins.

Does this service include creating or providing an on-premises or hybrid Active Directory domain?

No, an on-premises or hybrid Active Directory domain is listed as not included in the service. If your environment does not already have the required domain configuration, you should confirm with IT Partner whether additional work is needed before Defender for Identity can be installed.

Are there any prerequisites for the Microsoft Defender for Identity Installation service?

The provided service scope does not list explicit prerequisites. However, because the Defender for Identity license and an on-premises or hybrid Active Directory domain are marked as not included, customers should confirm with IT Partner whether these are required readiness items, additional cost items, or both.

What does IT Partner handle during the engagement?

IT Partner is responsible for customer infrastructure research, Defender for Identity architecture design, preparation of the environment for Defender for Identity installation, installation and configuration of the Defender for Identity service, and a basic introduction to working with ATA. These responsibilities align with the service deliverables and define IT Partner’s implementation scope.

What responsibilities does the customer have during the Defender for Identity installation?

The customer is responsible for coordinating internal resources and staff schedules, providing a dedicated point of contact, coordinating outside vendor resources and schedules, configuring networking equipment such as load balancers, routers, firewalls, and switches, and reviewing and approving deliverables in a timely manner. These responsibilities matter because the installation depends on access, scheduling, and customer-controlled network configuration.

Does IT Partner configure firewalls, routers, switches, or load balancers as part of this service?

No, the customer is responsible for configuring networking equipment such as load balancers, routers, firewalls, and switches. IT Partner’s scope covers Defender for Identity planning, design, environment preparation, installation, configuration, and basic introduction, while customer-controlled network devices remain the client’s responsibility.

Will there be downtime or business impact during the Defender for Identity installation?

The service description does not specify expected downtime or business impact. Because environment preparation, network dependencies, and Defender for Identity configuration can vary by customer, downtime assumptions should be confirmed with IT Partner during kickoff or infrastructure research.

What access or staff involvement does IT Partner need from the customer?

The customer must provide a dedicated point of contact and coordinate client resources, staff schedules, and any outside vendor resources. This involvement is required because IT Partner needs timely access, approvals, and coordination to research the infrastructure, prepare the environment, and complete the Defender for Identity installation.

What happens after the Microsoft Defender for Identity installation is complete?

After completion, the administrator should be able to use the Microsoft Defender portal to view reports and notifications. IT Partner also provides a basic introduction to working with ATA. Ongoing monitoring, 24/7 support, and ongoing maintenance are not included by default, but are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.

Does this service include training for administrators?

The service includes a basic introduction to working with ATA. It does not list formal administrator training, advanced security operations training, or custom runbooks, so those needs should be discussed separately with IT Partner.

Does this service include remediation of threats found by ATA?

Threat remediation is not listed as an included deliverable. The engagement focuses on planning, designing, installing, and configuring Defender for Identity so administrators can view reports and notifications in the Microsoft Defender portal.

Can the Defender for Identity architecture be tailored to our environment?

Yes, the service includes customer infrastructure research for developing an appropriate architecture solution and Defender for Identity architecture design. The plan may vary depending on customer needs, so IT Partner should confirm the final design approach after reviewing the environment.

What is the service SKU for Microsoft Defender for Identity Installation?

The service SKU is ITPWW330IMPOT. This SKU refers to the Microsoft Defender for Identity Installation service with the published 1 week duration and listed price of 1950.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

$1,950
1 week
Book a meeting