Your AD DS domain has three domain controllers (DC1, DC2, DC3). You connect Microsoft Defender for Identity to the domain. To onboard all domain controllers to Defender for Identity, which installer should you run on each domain controller?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure ATP Sensor Setup.exe.
Why this is the answer
To onboard domain controllers to Microsoft Defender for Identity (formerly Azure Advanced Threat Protection or Azure ATP), you must install the Defender for Identity sensor. The correct installer for this purpose is Azure ATP Sensor Setup.exe. This executable installs the necessary components on the domain controller to monitor network traffic and Windows events for suspicious activities, sending this data to the Defender for Identity cloud service. AzureConnectedMachineAgent.msi is used to install the Azure Connected Machine agent (Azure Arc agent) for managing servers outside of Azure. MARSAgentInstaller.exe is the Microsoft Azure Recovery Services (MARS) agent installer, used for backing up files and folders to Azure. MMASetup-AMD64.exe is the Microsoft Monitoring Agent (MMA) installer, used for connecting to Azure Log Analytics workspaces or System Center Operations Manager, which is not directly used for Defender for Identity sensor deployment.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed