Skip to content

Commit ad7ed83

Browse files
Merge pull request #5605 from rlitinsky/patch-97
Update whats-new.md
2 parents 30ea365 + d98b070 commit ad7ed83

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

defender-for-identity/whats-new.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,14 @@ For updates about versions and features released six months ago or earlier, see
2525

2626
## November 2025
2727

28+
Defender for Identity now offers an opt-in automatic event-auditing configuration for unified sensors (V3.x). This feature streamlines deployment by automatically applying required Windows auditing settings to new sensors and fixing misconfigurations on existing ones. Admins can enable the option in the Defender for Identity Settings -> Advanced Features or via Graph API. The capability and its related health alerts will roll out globally beginning mid-November 2025.
29+
**Releated Health alerts:**
30+
- NTLM Auditing is not enabled
31+
- Directory Services Advanced Auditing is not enabled as required
32+
- Directory Services Object Auditing is not enabled as required
33+
- Auditing on the Configuration container is not enabled as required
34+
- Auditing on the ADFS container is not enabled as required
35+
2836
### New security posture assessment: Change password for on-prem account with potentially leaked credentials (Preview)
2937

3038
The new security posture assessment lists users whose valid credentials have been leaked. For more information, see: [Change password for on-prem account with potentially leaked credentials (Preview)](/defender-for-identity/security-posture-assessments/accounts#change-password-for-on-prem-account-with-potentially-leaked-credentials-preview)

0 commit comments

Comments
 (0)