A security solution that detects identity-based threats and suspicious activities in on-premises Active Directory environments
Microsoft Defender for Identity (MDI) is licensed per protected user, not per server or sensor.
From the documented requirements, deploying Defender for Identity requires that protected users have one of the following:
- Enterprise Mobility + Security E5 (EMS E5/A5)
- Microsoft 365 E5/A5/G5 or Microsoft 365 E5/A5/G5/F5 Security
- Microsoft 365 F5 Security + Compliance (with the noted prerequisites)
- A standalone Defender for Identity license
Since 90% of users already have Microsoft 365 E5, those users are already covered for MDI and do not need additional standalone MDI licenses.
For the remaining users, standalone MDI licenses are needed only for identities that are in scope for protection (that is, human users whose activities and identities are being monitored/protected by Defender for Identity). The documentation does not call out separate licensing for:
- Service accounts
- Disabled accounts retained only for compliance
Licensing guidance is framed around per-user subscription rights, so service accounts and disabled accounts kept purely for historical/compliance purposes are not separately listed as requiring MDI licenses.
If more precise tenant-level or edge-case licensing interpretation is needed (for example, special treatment of certain non-human accounts), the detailed licensing guidance referenced in the docs and the Product Terms should be consulted, or the Microsoft account team should be engaged.
References: