How to configure Entra ID for the MDI monitoring and alerting?

EnterpriseArchitect 6,301 Reputation points
2025-06-17T05:01:04.39+00:00

How to configure Entra ID for the MDI monitoring and alerting?

Do I have to follow the steps in this article: https://v4.hkg1.meaqua.org/en-us/azure/sentinel/connect-azure-active-directory, or is this not the correct one, as it is for Sentinel SIEM?

My goal is to fully utilise Microsoft Defender for Identity for all Entra ID-related events monitoring and alerting.

All of the AD Domain Controllers have been installed with C:\Program Files\Azure Advanced Threat Protection Sensor\2.243.18758.45417 for now.

Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 2,695 Reputation points Microsoft Employee
    2025-11-25T07:54:05.7133333+00:00

    Hi EnterpriseArchitect,

    The article Connect Azure Active Directory to Microsoft Sentinel is specific to SIEM integration for log ingestion into Sentinel. For MDI, you do not need Sentinel unless you want to forward alerts to a SIEM. MDI natively integrates with Microsoft Defender XDR and Entra ID Protection for identity threat detection.

    Below are some guidance steps and documentation on Entra ID for MDI Monitoring

    1. Install MDI Sensors
    2. Enable Event Collection
      • MDI relies on Windows Event Logs and network traffic from domain controllers.
      • For Entra Connect servers, ensure auditing is configured for required events (e.g., 4624 logon events).
      • Reference: Event collection overview [v4.hkg1.meaqua.org]
    3. Integrate with Entra ID Protection
    4. Monitor and Alert

    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.