Security & identity

Onboard Windows devices to Defender for Endpoint with Intune step by step

Connect Microsoft Intune to Defender for Endpoint, deploy an EDR onboarding policy to Windows devices, and verify sensor health on the device, in the Defender portal and with advanced hunting.

11 min read
On this page

To onboard Windows devices to Microsoft Defender for Endpoint with Intune, turn on Intune connection under System > Settings > Endpoints > General > Advanced features in the Defender portal, confirm the connection shows Enabled under Endpoint security > Defender for Endpoint in Intune, and then create an Endpoint detection and response policy with the package type set to Auto from connector and assign it to device groups. Verify each device by checking that the SENSE service is running, that it appears as active in Device inventory, and that a detection test produces an alert.

Who this is for and what you will have

This guide is for endpoint and security administrators who manage Windows 10 and Windows 11 devices with Intune and want every device reporting to Defender for Endpoint, with a way to prove it.

At the end you will have:

  • A service-to-service connection between Intune and Defender for Endpoint.
  • An EDR onboarding policy targeted at the right device groups.
  • Device-side checks for the SENSE service, registry state and event log.
  • A tenant-wide view of onboarding and sensor health, plus a list of devices that need attention.

Once devices report their risk level, you can require healthy devices in Conditional Access, which is a core building block of a zero trust remote access architecture. Servers that run identity roles have a related task: deploying Defender for Identity sensors on domain controllers and AD CS, which builds on Defender for Endpoint onboarding.

How the integration works

Intune and Defender for Endpoint connect once per tenant. After the connection is made, Defender for Endpoint gives Intune an onboarding configuration package. An EDR policy in Intune then delivers that package to devices over MDM, the SENSE service on the device starts, and the device begins reporting.

On supported Windows editions the sensor (the SENSE service) is part of the operating system, so what Intune deploys is configuration rather than an agent.

PartWhere it's configuredPurpose
Intune connectionDefender portal, Advanced featuresLets Intune receive the onboarding package and risk signals
Compliance policy evaluation togglesIntune, Endpoint security, Defender for EndpointSends device risk to Intune compliance
EDR policyIntune, Endpoint security, Endpoint detection and responseOnboards the device and sets sample sharing
Compliance policyIntune, Devices, ComplianceMarks devices above a risk level noncompliant

Prerequisites

Licensing and supported devices

  • A license that includes Microsoft Defender for Endpoint (Plan 1 or Plan 2, or a suite that includes it). These plans don't include server licenses.
  • Windows 10 or Windows 11 Enterprise, Education, Pro, Pro Education or IoT Enterprise, enrolled in Intune. Microsoft notes that Windows 10 reached end of support on October 14, 2025; it remains an allowed version in Intune but functionality isn't guaranteed.
  • Internet access from the device, directly or through a proxy that WinHTTP can discover, to the Defender for Endpoint service URLs.

Roles

TaskRole
Turn on the Intune connection in the Defender portalSecurity Administrator in Microsoft Entra ID, or Manage security settings in Windows Security Center in Defender for Endpoint
Check the connection and configure toggles in IntuneEndpoint Security Manager, or a custom role with Read and Modify on Mobile Threat Defense
Create and assign EDR policiesEndpoint Security Manager, or a custom role with Assign, Create, Delete, Read, Update and View Reports on Endpoint Detection and Response
View the EDR Onboarding Status reportRead on Microsoft Defender Advanced Threat Protection in Intune RBAC

Microsoft Defender Antivirus must not be disabled

The Defender for Endpoint agent depends on Microsoft Defender Antivirus to scan files. If another antimalware product is primary, Defender Antivirus goes into passive mode, but it must not be turned off by policy, and its Early Launch Antimalware (ELAM) driver must stay enabled. If your organization turns off Defender Antivirus through Group Policy, exclude onboarded devices from that policy.

Step 1: Connect Intune and Defender for Endpoint

  1. In the Microsoft Intune admin center, open Endpoint security > Defender for Endpoint and check Connection status. If it shows Enabled, skip to Step 2.
  2. If it shows Unavailable, select Open the Defender Security Center at the bottom of the page, or go to https://security.microsoft.com.
  3. In the Defender portal, go to System > Settings > Endpoints > General > Advanced features.
  4. Turn Intune connection to On and select Save preferences.
  5. Return to Intune. Connection status should change to Enabled; Microsoft says this can take up to 15 minutes.

Step 2: Turn on compliance evaluation for Windows

Still under Endpoint security > Defender for Endpoint, set Connect Windows devices to Defender for Endpoint to On under Compliance policy evaluation, then select Save. This connects your current and future Intune-managed Windows devices for compliance evaluation. It doesn't onboard them; Step 3 does that.

Step 3: Deploy the EDR onboarding policy

You have two options in Endpoint security > Endpoint detection and response.

OptionWhen to use itWhat it does
Deploy preconfigured policy (on the EDR Onboarding Status tab)Small tenants or a fast, broad rolloutCreates a policy with the automatic package, default scope tag, assigned to All Devices
Create Policy (on the Summary tab)Rings, scope tags or specific groupsLets you choose settings and assignments

For a staged rollout, use the custom option:

  1. Select Create Policy, choose Platform: Windows and Profile: Endpoint detection and response, then Create.
  2. On Basics, name it, for example MDE EDR Onboarding - Ring 1.
  3. On Configuration settings:
    • Defender for Endpoint client configuration package type: Auto from connector. If you only see options to paste onboard and offboard blobs, the connection from Step 1 isn't in place.
    • Sample Sharing: All to let devices send suspicious file samples for analysis, or None to disable it. Microsoft notes that None can reduce detection capabilities.
    • Ignore Telemetry Reporting Frequency; it's deprecated and doesn't affect new devices.
  4. Add scope tags if you use them.
  5. On Assignments, select device groups. Microsoft recommends device groups because user-group assignments wait for the user to sign in.
  6. Select Create.

Start with a pilot group of IT devices, then widen the assignment. Avoid having two EDR policies that configure the same settings for the same device, and never deploy onboarding and offboarding to the same device at the same time; Microsoft lists that as a cause of noncompliance.

Step 4: Verify on a device

After the policy shows as applied under Endpoint detection and response > your policy > Device status, check a pilot device locally in an elevated prompt:

# The SENSE service should be RUNNING
sc.exe query sense
 
# 1 means the device is onboarded
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status' |
    Select-Object OnboardingState

Then open Event Viewer > Applications and Services Logs > Microsoft > Windows > SENSE > Operational and filter for Critical, Warning and Error. A clean log is a good sign.

Finally, run Microsoft's detection test from an elevated Command Prompt. It simulates a download-and-execute pattern so the service raises a test alert:

powershell.exe -NoExit -ExecutionPolicy Bypass -WindowStyle Hidden $ErrorActionPreference = 'silentlycontinue';(New-Object System.Net.WebClient).DownloadFile('http://127.0.0.1/1.exe', 'C:\\test-MDATP-test\\invoice.exe');Start-Process 'C:\\test-MDATP-test\\invoice.exe'

The window closes on its own, and a new alert for the device should appear in the Defender portal in about 10 minutes.

Step 5: Verify sensor health at scale

Intune report

In Intune, open Endpoint security > Endpoint detection and response > EDR Onboarding Status. Devices that worked show as successfully onboarded.

Defender portal

Open Device inventory (https://security.microsoft.com/machines?category=all-devices), search for the devices and confirm the sensor health state is Active. The two unhealthy states mean different things:

StateMeaningFirst thing to check
InactiveNo signals for more than seven days; also used for offboarded, reinstalled or renamed devicesWhether the device still exists under a new name
Misconfigured: Impaired communicationsLimited communication with the serviceProxy and WinHTTP connectivity to the service URLs
Misconfigured: No sensor dataThe device communicates but sends partial sensor dataDiagnostic data service, connectivity, Defender Antivirus not disabled

Advanced hunting

The DeviceInfo table includes OnboardingStatus and SensorHealthState. This query returns the latest record per device and counts devices by state, so you can track progress during the rollout:

DeviceInfo
| where OSPlatform startswith "Windows"
| summarize arg_max(Timestamp, *) by DeviceId
| summarize Devices = count() by OnboardingStatus, SensorHealthState
| order by Devices desc

Remove the second summarize to list individual devices instead, then filter on the SensorHealthState values the first query showed as unhealthy.

Optional: use device risk in compliance and Conditional Access

With devices reporting, create a Windows compliance policy under Devices > Compliance > Create policy, expand Microsoft Defender for Endpoint and set Require the device to be at or under the machine risk score. Microsoft recommends Low as the balance between security and productivity for most organizations. Then create a Conditional Access policy that requires a compliant device, start it in Report-only, review the sign-in logs, and exclude your emergency access accounts before you switch it on.

Troubleshooting

Intune reports an error

ErrorMeaningFix
0x87D1FDE8 (Remediation failed)Wrong onboarding blob, missing or unwritable policy registry key, or an unsupported SKUCheck SENSE event IDs, confirm HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection exists, check the Windows edition
0x87D101A9 (SyncML 425)Deployment to an unsupported SKU or platformTarget only Enterprise, Education and Pro editions

Microsoft also documents noncompliance cases: a device compliant on SenseIsRunning but not on OnboardingState usually hasn't finished OOBE; a device compliant on onboarding but not on SenseIsRunning often has a delayed-start SENSE service and corrects itself within 24 hours.

SENSE operational log events

Event IDMessage (abridged)Fix
5Service failed to connect to the serverRestore internet or proxy access
6Service isn't onboarded and no onboarding parameters were foundRe-deliver the onboarding policy
7Service failed to read the onboarding parametersCheck connectivity, then rerun onboarding
15Can't start command channel with URLRestore internet or proxy access

For MDM-side failures, check the Microsoft\Windows\DeviceManagement-EnterpriseDiagnostics-Provider Admin log.

Connectivity

Download the Microsoft Defender for Endpoint Client Analyzer, extract it and run MDEClientAnalyzer.cmd from an elevated prompt. Open MDEClientAnalyzerResult.txt; for each service URL, any connection method that returns (200) works. If your attack surface reduction rules include Block process creations originating from PSExec and WMI commands, temporarily exclude the analyzer, because the cloud connectivity checks conflict with that rule.

Service won't start

If SENSE fails with system error 577 or 1058 on a device that hasn't received the August 2020 (4.18.2007.8) Defender Antivirus platform update, Defender Antivirus or its ELAM driver has been disabled by policy. Clear DisableAntiSpyware and DisableAntiVirus under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender, then onboard again. Leave the WdBoot, WdFilter, WdNisDrv, WdNisSvc and WinDefend services at their default start types; Microsoft says changing them is unsupported. Windows 11 24H2 Home devices upgraded to a supported edition might need the SENSE capability added first:

DISM /online /Add-Capability /CapabilityName:Microsoft.Windows.Sense.Client~~~~

Checklist

  • Intune connection Enabled in Intune and On in the Defender portal.
  • Connect Windows devices to Defender for Endpoint turned on for compliance evaluation.
  • EDR policy with Auto from connector, assigned to device groups in rings.
  • Defender Antivirus active or passive, never disabled by policy.
  • Pilot devices pass the SENSE, registry, event log and detection test checks.
  • EDR Onboarding Status and Device inventory reviewed for every ring.
  • DeviceInfo query run weekly until no devices are inactive or misconfigured.
  • Risk-based compliance and Conditional Access tested in report-only before enforcing.

References

Questions people ask

Do I need to download the onboarding package to onboard devices with Intune?

No. When the Intune connection is enabled in the Defender portal, Intune receives the onboarding configuration automatically. In the EDR policy, set Defender for Endpoint client configuration package type to Auto from connector. Pasting the onboarding blob manually is only needed for disconnected environments.

How long does it take for an Intune-onboarded device to appear in the Defender portal?

Microsoft's Intune guidance says devices should appear under Device inventory after about 15 to 30 minutes. Microsoft's troubleshooting guidance says that a device still missing after an hour might indicate an onboarding or connectivity problem, and its device-side checks include the SENSE operational event log.

Should I assign the EDR onboarding policy to users or devices?

Microsoft recommends device groups for immediate deployment. Policies assigned to user groups only apply after the user signs in to the device.

Can Defender for Endpoint onboard a device during Autopilot OOBE?

Microsoft states that Defender for Endpoint doesn't support onboarding during the Out-of-Box Experience phase. On Windows 10 version 1809 or later the SENSE service no longer waits for the first user sign-in after OOBE, but devices that were turned off before OOBE finished may need attention.

Defender for EndpointIntuneWindowsDefender XDR
  1. Attack surface reduction rules: move from audit mode to block safely

    Roll out Microsoft Defender attack surface reduction rules in rings: audit first, read the data in advanced hunting, add narrow exclusions, then block.

  2. Require compliant devices for Microsoft 365 with Conditional Access

    Build Intune compliance policies for Windows and iOS, mark unassigned devices noncompliant, then require a compliant device in Conditional Access without locking users out.

  3. AADSTS53003 blocked by Conditional Access: find the policy and fix it

    Troubleshoot AADSTS53003 in Microsoft Entra ID: trace the correlation ID to the sign-in log, identify the blocking Conditional Access policy, and fix the user, device or policy without weakening security.