DefenderTroubleshooting

Defender for Endpoint onboarding failures: SENSE event IDs, script errors and what they mean

A field guide to Defender for Endpoint onboarding failures: onboarding script error codes, SENSE Operational event IDs, Intune error codes, and the registry and service checks that show where it broke.

An onboarding failure in Defender for Endpoint rarely tells you what went wrong in one place. The deployment tool reports one thing, the SENSE sensor writes another to its own event log, and the device simply never appears in the portal. In this post I'll map the whole chain: the registry values and service state to check first, the documented event IDs and error codes with what each one means, the Intune-specific failures, and how to offboard and re-onboard without making things worse.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (7 steps: Find out which link broke; Read the onboarding script events; Read the SENSE Operational log; Decode the Intune-specific codes; Fix connectivity; and 2 more). 4. Verify the fix. 5. Prevent it next time. Toolbox: 0x87D1FDE8, 0x87D101A9, Event ID 15, DISM.EXE, netsh.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttime1Find out whichlink broke2Read theonboarding s…3Read theSENSE Opera…4Decode theIntune-specifi…5Fixconnectivity+2 moreTOOLBOX0x87D1FDE80x87D101A9Event ID 15DISM.EXEnetshHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (7 steps: Find out which link broke; Read the onboarding script events; Read the SENSE Operational log; Decode the Intune-specific codes; Fix connectivity; and 2 more). 4. Verify the fix. 5. Prevent it next time. Toolbox: 0x87D1FDE8, 0x87D101A9, Event ID 15, DISM.EXE, netsh.1Symptoms2Why it happens3How to fix it1Find out which link broke2Read the onboarding script events3Read the SENSE Operational log4Decode the Intune-specific codes5Fix connectivity+2 more4Verify the fix5Prevent it next timeTOOLBOX0x87D1FDE80x87D101A9Event ID 15DISM.EXEnetsh
At a glance: how this guide is organised · 7 fix steps · 5 key tools

Symptoms#

  • The device isn't in Assets › Devices in the Microsoft Defender portal an hour after onboarding ran.
  • The Intune EDR policy shows an error such as 0x87D1FDE8 or 0x87D101A9, or reports the device as non-compliant on some onboarding settings but not others.
  • The local onboarding script finishes with an error event from the WDATPOnboarding source.
  • The Sense service won't start, or starts and logs connection failures.

Why it happens#

Onboarding is a short chain. The deployment tool (Intune, Group Policy, Configuration Manager or a local script) writes the onboarding blob to HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection. The Sense service starts, reads it, registers with the cloud over WinHTTP, and records the result under HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status, where OnboardingState becomes 1. Failures fall into three groups: the blob never arrived or couldn't be written (permissions, unsupported edition, mismatched package), the service couldn't start (missing SENSE component, Defender Antivirus disabled by policy, Windows setup not finished), or the service started but couldn't reach the service URLs (proxy, firewall, TLS inspection).

How to fix it#

From an elevated PowerShell session on the device:

PowerShell
sc.exe query sense
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status' |
    Select-Object OnboardingState, OrgId
Test-Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection'

If the policy key is missing, the blob never landed: go back to your deployment tool. If the key exists but OnboardingState is missing or 0, the service failed to onboard: read the SENSE log in step 3. If the service is START_PENDING or STOP_PENDING, wait or reboot, then retry. On builds older than Windows 10 1809 or Windows Server 2019, a freshly imaged device also won't onboard until a user signs in after the out-of-box experience.

2. Read the onboarding script events#

When a script (local, Group Policy or Configuration Manager) runs, it logs to Windows Logs › Application under the source WDATPOnboarding. These IDs belong to the script only:

Event IDMeaningWhat to do
5Old offboarding data couldn't be removedCheck permissions on the policy registry key above
10Onboarding data couldn't be written to the registryCheck permissions on the policy key; run the script as administrator
15SENSE service failed to startCheck sc query sense for a pending state and retry. Errors 577 or 1058 mean Defender Antivirus (ELAM) is disabled by policy. On Windows editions where SENSE is a Feature on Demand, confirm it's installed (see below)
30Script timed out waiting for the service to runCheck the SENSE Operational log for the underlying error
35Onboarding status value not found in the registryThe service hasn't written OnboardingState; check the SENSE log
40Onboarding status isn't 1Service failed to onboard; check the SENSE log
65Insufficient privilegesRun with administrator rights
70Offboarding script is for a different organisationDownload the offboarding package from the tenant the device belongs to

For event 15, check the SENSE Feature on Demand with DISM.EXE /Online /Get-CapabilityInfo /CapabilityName:Microsoft.Windows.Sense.Client~~~~; if the state isn't Installed, add the capability and onboard again. For errors 577 and 1058, look under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender for DisableAntiSpyware or DisableAntiVirus and clear them (this only affects devices without the August 2020 Defender Antivirus platform update or later).

3. Read the SENSE Operational log#

Open Applications and Services Logs › Microsoft › Windows › SENSE › Operational and filter on Critical, Warning and Error. These are the IDs Microsoft documents for onboarding problems:

Event IDMeaningWhat to do
5Service failed to connect to the serverFix internet or proxy access (step 5)
6Not onboarded and no onboarding parameters foundRun onboarding again; the blob isn't on the device
7Failed to read the onboarding parametersConfirm connectivity, then run the whole onboarding process again
9Failed to change the service start typeReboot and rerun onboarding; if it happened during offboarding, contact support
10Failed to persist the onboarding informationRerun onboarding; contact support if it persists
15Can't start the command channel with the given URLFix internet or proxy access (step 5)
17Failed to change the Connected User Experiences and Telemetry service locationRerun onboarding; contact support if it persists
25Failed to reset health status in the registryContact support
27Failed to enable Defender for Endpoint mode in Windows DefenderContact support
29Failed to read the offboarding parametersConfirm connectivity, then run offboarding again
32Service failed to stop itself after offboardingConfirm the start type is Manual and reboot
55Failed to create the secure ETW autologgerReboot
63, 68A dependent service's start type was changed or is unexpectedFind what changed it (often Group Policy or a hardening script) and restore the expected start type
64, 69A dependent service is stoppedStart the named service; contact support if it keeps recurring

4. Decode the Intune-specific codes#

CodeMeaningTypical causes
0x87D1FDE8Remediation failedWrong blob (bad signature or missing PreviousOrgIds field); the policy registry key doesn't exist or the MDM client can't write it; Intune trying to remediate a read-only node such as OnboardingState, OrgId or SenseIsRunning; an unsupported edition
0x87D101A9SyncML 425: insufficient access control permissionsUnsupported SKU or platform. Intune onboarding supports Enterprise, Education and Professional editions

Three compliance patterns are documented too. If SenseIsRunning is compliant but OrgId, Onboarding and OnboardingState aren't, Windows setup (OOBE) hasn't finished: wait. If it's the reverse, the service is set to delayed start and Intune evaluated too early: it resolves itself within 24 hours. If everything is non-compliant, check that an onboarding and an offboarding policy aren't both targeting the device. For MDM-side failures, the log Microsoft › Windows › DeviceManagement-Enterprise-Diagnostics-Provider › Admin event 1819 ("Failed to Set Node's Value") points to a missing cumulative update on Windows 10 1607.

In Intune, the Endpoint security › Endpoint detection and response › EDR Onboarding Status tab shows every device with its Onboarding status (Onboarded, Not onboarded or Pending), Defender sensor state (Active, Inactive or Impaired), how it's managed and its last check-in. Filter to Not onboarded and Pending to build your work list.

5. Fix connectivity#

Events 5 and 15 mean the sensor reached the point of calling home and failed. The sensor uses WinHTTP in the system context, so netsh winhttp show proxy is the proxy that matters, not the user's browser settings. Run the MDE Client Analyzer on the device to test each service URL through the available proxy methods, and remember that an authenticated proxy or TLS inspection on these destinations breaks the connection.

6. Onboarded, but no data#

If OnboardingState is 1 and the device shows in the portal but stays Inactive or Misconfigured, the problem is no longer onboarding. Check that the Windows diagnostic data service starts automatically (sc qc diagtrack; since Windows 10 1809 the sensor no longer strictly depends on it, but Microsoft still recommends it runs), re-check the proxy, and follow my earlier post on Inactive and No sensor data devices.

7. Offboard and re-onboard properly#

Download the offboarding package from Settings › Endpoints › Device management › Offboarding. It expires seven days after download (the date is in the file name) and expired packages are rejected. Never target a device with onboarding and offboarding at the same time: when re-onboarding through Intune, remove the device from the offboarding assignment first, confirm a clean sync, then assign the onboarding policy. An offboarded device turns Inactive after seven days and its profile stays in the inventory for up to 180 days, so a re-onboarded device may appear as a new record beside the old one.

Verify the fix#

On the device, sc query sense should report RUNNING and OnboardingState should be 1, with no new errors in the SENSE Operational log. In the Defender portal the device should appear in Assets › Devices as Onboarded with an Active sensor, usually within an hour. Run Microsoft's detection test from the onboarding documentation and confirm an alert arrives for the device.

Prevent it next time#

  • Pilot every onboarding change on a device group first and check the EDR Onboarding Status tab before widening the assignment.
  • Keep the Defender for Endpoint URLs excluded from TLS inspection and authenticated proxy rules, and re-test with the Client Analyzer after network changes.
  • Never change the start type of the Sense service or the Defender Antivirus services (WdBoot, WdFilter, WdNisDrv, WdNisSvc, WinDefend); Microsoft treats that as unsupported.
  • Treat offboarding as a planned operation with a fresh package, and record which devices it targeted.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)