[D 3.1] Sensors: One Fleet, Two Generations

You will run two generations of the identity sensor at once, and that is the supported steady state. Which machine belongs to which generation, and why the new one breaks habits carried from the old.

You will run two generations of the identity sensor at once, and that is the supported steady state. Which machine belongs to which generation, and why the new one breaks habits carried from the old.

Defender for Identity is no longer the on-premises member of the suite. It has two ends now, a sensor fleet on the identity fabric and the cloud directory itself, and the licensing carries a question nobody has answered.

The device-risk article took a position: the machine risk score belongs in the access decision only for a small, high-assurance, always-reporting population, carved into its own compliance policy, while the rest of the fleet is gated on the health signals…

The attack-surface article argued the family and sent you to the Intune guide for the audit-to-block ladder itself. This build pins the rules to values, resolves the merge conflict from the attack-surface side, and wires the web-protection substrate that most…

The protection-engine article argued which of these settings are dials rather than switches and where each should land. This pins them. Most are a single deliberate choice made once, and they are gathered here as values with the reason attached.…

The security settings management article argued what this channel is and the one rule that governs it: an Intune-enrolled device ignores it, so it exists to configure the machines Intune deliberately does not manage. This is the build. It is…

The onboarding article mapped the doors a device can take into Defender and argued which one to use for which population. This is the build for the door most estates start with, the Intune channel, taken from an empty connection…

Wiring the Cloud PKI certificate into EAP-TLS Wi-Fi: the vendor-neutral RADIUS checklist, the Wi-Fi profile settings, the per-platform traps, and an end-to-end test that proves a revoked certificate gets refused.