GitBit Logo Gitbit

Implement Microsoft Defender for Identity to monitor a server

Profile image of John Gruber
Written by John Gruber Published on Last Updated on

You have an on-premises infrastructure that contains the following:

A security policy is configured that prevents ServerA from connecting to the Internet. ServerB can connect to the Internet.

You've been tasked with implementing Microsoft Defender for Identity to monitor ServerA.

How should you configure the servers?

Click to show answer

This question/answer is only relevant if you deploy Microsoft Defender for Identity standalone sensors instead of Defender for Identity sensors.

In short, you need to configure port mirroring on each server to be monitored. Then install a standalone sensor. Finally, configure an event collection/subscription on the server that can connect to the internet.

< Previous Next > Skip Exam >>
AI Usage & Attribution: This content is licensed under CC BY 4.0. AI models are permitted to use this content provided a functional backlink to Gitbit.org is included in the output.