To onboard Windows devices to Microsoft Defender for Endpoint with Intune, turn on Intune connection under System > Settings > Endpoints > General > Advanced features in the Defender portal, confirm the connection shows Enabled under Endpoint security > Defender for Endpoint in Intune, and then create an Endpoint detection and response policy with the package type set to Auto from connector and assign it to device groups. Verify each device by checking that the SENSE service is running, that it appears as active in Device inventory, and that a detection test produces an alert.
Who this is for and what you will have
This guide is for endpoint and security administrators who manage Windows 10 and Windows 11 devices with Intune and want every device reporting to Defender for Endpoint, with a way to prove it.
At the end you will have:
- A service-to-service connection between Intune and Defender for Endpoint.
- An EDR onboarding policy targeted at the right device groups.
- Device-side checks for the SENSE service, registry state and event log.
- A tenant-wide view of onboarding and sensor health, plus a list of devices that need attention.
Once devices report their risk level, you can require healthy devices in Conditional Access, which is a core building block of a zero trust remote access architecture. Servers that run identity roles have a related task: deploying Defender for Identity sensors on domain controllers and AD CS, which builds on Defender for Endpoint onboarding.
How the integration works
Intune and Defender for Endpoint connect once per tenant. After the connection is made, Defender for Endpoint gives Intune an onboarding configuration package. An EDR policy in Intune then delivers that package to devices over MDM, the SENSE service on the device starts, and the device begins reporting.
On supported Windows editions the sensor (the SENSE service) is part of the operating system, so what Intune deploys is configuration rather than an agent.
| Part | Where it's configured | Purpose |
|---|---|---|
| Intune connection | Defender portal, Advanced features | Lets Intune receive the onboarding package and risk signals |
| Compliance policy evaluation toggles | Intune, Endpoint security, Defender for Endpoint | Sends device risk to Intune compliance |
| EDR policy | Intune, Endpoint security, Endpoint detection and response | Onboards the device and sets sample sharing |
| Compliance policy | Intune, Devices, Compliance | Marks devices above a risk level noncompliant |
Prerequisites
Licensing and supported devices
- A license that includes Microsoft Defender for Endpoint (Plan 1 or Plan 2, or a suite that includes it). These plans don't include server licenses.
- Windows 10 or Windows 11 Enterprise, Education, Pro, Pro Education or IoT Enterprise, enrolled in Intune. Microsoft notes that Windows 10 reached end of support on October 14, 2025; it remains an allowed version in Intune but functionality isn't guaranteed.
- Internet access from the device, directly or through a proxy that WinHTTP can discover, to the Defender for Endpoint service URLs.
Roles
| Task | Role |
|---|---|
| Turn on the Intune connection in the Defender portal | Security Administrator in Microsoft Entra ID, or Manage security settings in Windows Security Center in Defender for Endpoint |
| Check the connection and configure toggles in Intune | Endpoint Security Manager, or a custom role with Read and Modify on Mobile Threat Defense |
| Create and assign EDR policies | Endpoint Security Manager, or a custom role with Assign, Create, Delete, Read, Update and View Reports on Endpoint Detection and Response |
| View the EDR Onboarding Status report | Read on Microsoft Defender Advanced Threat Protection in Intune RBAC |
Microsoft Defender Antivirus must not be disabled
The Defender for Endpoint agent depends on Microsoft Defender Antivirus to scan files. If another antimalware product is primary, Defender Antivirus goes into passive mode, but it must not be turned off by policy, and its Early Launch Antimalware (ELAM) driver must stay enabled. If your organization turns off Defender Antivirus through Group Policy, exclude onboarded devices from that policy.
Step 1: Connect Intune and Defender for Endpoint
- In the Microsoft Intune admin center, open Endpoint security > Defender for Endpoint and check Connection status. If it shows Enabled, skip to Step 2.
- If it shows Unavailable, select Open the Defender Security Center at the bottom of the page, or go to
https://security.microsoft.com. - In the Defender portal, go to System > Settings > Endpoints > General > Advanced features.
- Turn Intune connection to On and select Save preferences.
- Return to Intune. Connection status should change to Enabled; Microsoft says this can take up to 15 minutes.
Step 2: Turn on compliance evaluation for Windows
Still under Endpoint security > Defender for Endpoint, set Connect Windows devices to Defender for Endpoint to On under Compliance policy evaluation, then select Save. This connects your current and future Intune-managed Windows devices for compliance evaluation. It doesn't onboard them; Step 3 does that.
Step 3: Deploy the EDR onboarding policy
You have two options in Endpoint security > Endpoint detection and response.
| Option | When to use it | What it does |
|---|---|---|
| Deploy preconfigured policy (on the EDR Onboarding Status tab) | Small tenants or a fast, broad rollout | Creates a policy with the automatic package, default scope tag, assigned to All Devices |
| Create Policy (on the Summary tab) | Rings, scope tags or specific groups | Lets you choose settings and assignments |
For a staged rollout, use the custom option:
- Select Create Policy, choose Platform: Windows and Profile: Endpoint detection and response, then Create.
- On Basics, name it, for example
MDE EDR Onboarding - Ring 1. - On Configuration settings:
- Defender for Endpoint client configuration package type: Auto from connector. If you only see options to paste onboard and offboard blobs, the connection from Step 1 isn't in place.
- Sample Sharing: All to let devices send suspicious file samples for analysis, or None to disable it. Microsoft notes that None can reduce detection capabilities.
- Ignore Telemetry Reporting Frequency; it's deprecated and doesn't affect new devices.
- Add scope tags if you use them.
- On Assignments, select device groups. Microsoft recommends device groups because user-group assignments wait for the user to sign in.
- Select Create.
Start with a pilot group of IT devices, then widen the assignment. Avoid having two EDR policies that configure the same settings for the same device, and never deploy onboarding and offboarding to the same device at the same time; Microsoft lists that as a cause of noncompliance.
Step 4: Verify on a device
After the policy shows as applied under Endpoint detection and response > your policy > Device status, check a pilot device locally in an elevated prompt:
# The SENSE service should be RUNNING
sc.exe query sense
# 1 means the device is onboarded
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status' |
Select-Object OnboardingStateThen open Event Viewer > Applications and Services Logs > Microsoft > Windows > SENSE > Operational and filter for Critical, Warning and Error. A clean log is a good sign.
Finally, run Microsoft's detection test from an elevated Command Prompt. It simulates a download-and-execute pattern so the service raises a test alert:
powershell.exe -NoExit -ExecutionPolicy Bypass -WindowStyle Hidden $ErrorActionPreference = 'silentlycontinue';(New-Object System.Net.WebClient).DownloadFile('http://127.0.0.1/1.exe', 'C:\\test-MDATP-test\\invoice.exe');Start-Process 'C:\\test-MDATP-test\\invoice.exe'The window closes on its own, and a new alert for the device should appear in the Defender portal in about 10 minutes.
Step 5: Verify sensor health at scale
Intune report
In Intune, open Endpoint security > Endpoint detection and response > EDR Onboarding Status. Devices that worked show as successfully onboarded.
Defender portal
Open Device inventory (https://security.microsoft.com/machines?category=all-devices), search for the devices and confirm the sensor health state is Active. The two unhealthy states mean different things:
| State | Meaning | First thing to check |
|---|---|---|
| Inactive | No signals for more than seven days; also used for offboarded, reinstalled or renamed devices | Whether the device still exists under a new name |
| Misconfigured: Impaired communications | Limited communication with the service | Proxy and WinHTTP connectivity to the service URLs |
| Misconfigured: No sensor data | The device communicates but sends partial sensor data | Diagnostic data service, connectivity, Defender Antivirus not disabled |
Advanced hunting
The DeviceInfo table includes OnboardingStatus and SensorHealthState. This query returns the latest record per device and counts devices by state, so you can track progress during the rollout:
DeviceInfo
| where OSPlatform startswith "Windows"
| summarize arg_max(Timestamp, *) by DeviceId
| summarize Devices = count() by OnboardingStatus, SensorHealthState
| order by Devices descRemove the second summarize to list individual devices instead, then filter on the SensorHealthState values the first query showed as unhealthy.
Optional: use device risk in compliance and Conditional Access
With devices reporting, create a Windows compliance policy under Devices > Compliance > Create policy, expand Microsoft Defender for Endpoint and set Require the device to be at or under the machine risk score. Microsoft recommends Low as the balance between security and productivity for most organizations. Then create a Conditional Access policy that requires a compliant device, start it in Report-only, review the sign-in logs, and exclude your emergency access accounts before you switch it on.
Troubleshooting
Intune reports an error
| Error | Meaning | Fix |
|---|---|---|
| 0x87D1FDE8 (Remediation failed) | Wrong onboarding blob, missing or unwritable policy registry key, or an unsupported SKU | Check SENSE event IDs, confirm HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection exists, check the Windows edition |
| 0x87D101A9 (SyncML 425) | Deployment to an unsupported SKU or platform | Target only Enterprise, Education and Pro editions |
Microsoft also documents noncompliance cases: a device compliant on SenseIsRunning but not on OnboardingState usually hasn't finished OOBE; a device compliant on onboarding but not on SenseIsRunning often has a delayed-start SENSE service and corrects itself within 24 hours.
SENSE operational log events
| Event ID | Message (abridged) | Fix |
|---|---|---|
| 5 | Service failed to connect to the server | Restore internet or proxy access |
| 6 | Service isn't onboarded and no onboarding parameters were found | Re-deliver the onboarding policy |
| 7 | Service failed to read the onboarding parameters | Check connectivity, then rerun onboarding |
| 15 | Can't start command channel with URL | Restore internet or proxy access |
For MDM-side failures, check the Microsoft\Windows\DeviceManagement-EnterpriseDiagnostics-Provider Admin log.
Connectivity
Download the Microsoft Defender for Endpoint Client Analyzer, extract it and run MDEClientAnalyzer.cmd from an elevated prompt. Open MDEClientAnalyzerResult.txt; for each service URL, any connection method that returns (200) works. If your attack surface reduction rules include Block process creations originating from PSExec and WMI commands, temporarily exclude the analyzer, because the cloud connectivity checks conflict with that rule.
Service won't start
If SENSE fails with system error 577 or 1058 on a device that hasn't received the August 2020 (4.18.2007.8) Defender Antivirus platform update, Defender Antivirus or its ELAM driver has been disabled by policy. Clear DisableAntiSpyware and DisableAntiVirus under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender, then onboard again. Leave the WdBoot, WdFilter, WdNisDrv, WdNisSvc and WinDefend services at their default start types; Microsoft says changing them is unsupported. Windows 11 24H2 Home devices upgraded to a supported edition might need the SENSE capability added first:
DISM /online /Add-Capability /CapabilityName:Microsoft.Windows.Sense.Client~~~~Checklist
- Intune connection Enabled in Intune and On in the Defender portal.
- Connect Windows devices to Defender for Endpoint turned on for compliance evaluation.
- EDR policy with Auto from connector, assigned to device groups in rings.
- Defender Antivirus active or passive, never disabled by policy.
- Pilot devices pass the SENSE, registry, event log and detection test checks.
- EDR Onboarding Status and Device inventory reviewed for every ring.
DeviceInfoquery run weekly until no devices are inactive or misconfigured.- Risk-based compliance and Conditional Access tested in report-only before enforcing.
References
- Configure Microsoft Defender for Endpoint with Intune and onboard devices
- Minimum requirements for Microsoft Defender for Endpoint
- Run a detection test on a newly onboarded device
- Troubleshoot Microsoft Defender for Endpoint onboarding issues
- Fix unhealthy sensors in Microsoft Defender for Endpoint
- Verify client connectivity to Microsoft Defender for Endpoint service URLs
- Onboard Windows devices with Configuration Manager (verification guidance)
- DeviceInfo table in the advanced hunting schema