An onboarding failure in Defender for Endpoint rarely tells you what went wrong in one place. The deployment tool reports one thing, the SENSE sensor writes another to its own event log, and the device simply never appears in the portal. In this post I'll map the whole chain: the registry values and service state to check first, the documented event IDs and error codes with what each one means, the Intune-specific failures, and how to offboard and re-onboard without making things worse.
Symptoms#
- The device isn't in Assets › Devices in the Microsoft Defender portal an hour after onboarding ran.
- The Intune EDR policy shows an error such as
0x87D1FDE8or0x87D101A9, or reports the device as non-compliant on some onboarding settings but not others. - The local onboarding script finishes with an error event from the
WDATPOnboardingsource. - The
Senseservice won't start, or starts and logs connection failures.
Why it happens#
Onboarding is a short chain. The deployment tool (Intune, Group Policy, Configuration Manager or a local script) writes the onboarding blob to HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection. The Sense service starts, reads it, registers with the cloud over WinHTTP, and records the result under HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status, where OnboardingState becomes 1. Failures fall into three groups: the blob never arrived or couldn't be written (permissions, unsupported edition, mismatched package), the service couldn't start (missing SENSE component, Defender Antivirus disabled by policy, Windows setup not finished), or the service started but couldn't reach the service URLs (proxy, firewall, TLS inspection).
How to fix it#
1. Find out which link broke#
From an elevated PowerShell session on the device:
sc.exe query sense
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status' |
Select-Object OnboardingState, OrgId
Test-Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection'If the policy key is missing, the blob never landed: go back to your deployment tool. If the key exists but OnboardingState is missing or 0, the service failed to onboard: read the SENSE log in step 3. If the service is START_PENDING or STOP_PENDING, wait or reboot, then retry. On builds older than Windows 10 1809 or Windows Server 2019, a freshly imaged device also won't onboard until a user signs in after the out-of-box experience.
2. Read the onboarding script events#
When a script (local, Group Policy or Configuration Manager) runs, it logs to Windows Logs › Application under the source WDATPOnboarding. These IDs belong to the script only:
| Event ID | Meaning | What to do |
|---|---|---|
| 5 | Old offboarding data couldn't be removed | Check permissions on the policy registry key above |
| 10 | Onboarding data couldn't be written to the registry | Check permissions on the policy key; run the script as administrator |
| 15 | SENSE service failed to start | Check sc query sense for a pending state and retry. Errors 577 or 1058 mean Defender Antivirus (ELAM) is disabled by policy. On Windows editions where SENSE is a Feature on Demand, confirm it's installed (see below) |
| 30 | Script timed out waiting for the service to run | Check the SENSE Operational log for the underlying error |
| 35 | Onboarding status value not found in the registry | The service hasn't written OnboardingState; check the SENSE log |
| 40 | Onboarding status isn't 1 | Service failed to onboard; check the SENSE log |
| 65 | Insufficient privileges | Run with administrator rights |
| 70 | Offboarding script is for a different organisation | Download the offboarding package from the tenant the device belongs to |
For event 15, check the SENSE Feature on Demand with DISM.EXE /Online /Get-CapabilityInfo /CapabilityName:Microsoft.Windows.Sense.Client~~~~; if the state isn't Installed, add the capability and onboard again. For errors 577 and 1058, look under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender for DisableAntiSpyware or DisableAntiVirus and clear them (this only affects devices without the August 2020 Defender Antivirus platform update or later).
3. Read the SENSE Operational log#
Open Applications and Services Logs › Microsoft › Windows › SENSE › Operational and filter on Critical, Warning and Error. These are the IDs Microsoft documents for onboarding problems:
| Event ID | Meaning | What to do |
|---|---|---|
| 5 | Service failed to connect to the server | Fix internet or proxy access (step 5) |
| 6 | Not onboarded and no onboarding parameters found | Run onboarding again; the blob isn't on the device |
| 7 | Failed to read the onboarding parameters | Confirm connectivity, then run the whole onboarding process again |
| 9 | Failed to change the service start type | Reboot and rerun onboarding; if it happened during offboarding, contact support |
| 10 | Failed to persist the onboarding information | Rerun onboarding; contact support if it persists |
| 15 | Can't start the command channel with the given URL | Fix internet or proxy access (step 5) |
| 17 | Failed to change the Connected User Experiences and Telemetry service location | Rerun onboarding; contact support if it persists |
| 25 | Failed to reset health status in the registry | Contact support |
| 27 | Failed to enable Defender for Endpoint mode in Windows Defender | Contact support |
| 29 | Failed to read the offboarding parameters | Confirm connectivity, then run offboarding again |
| 32 | Service failed to stop itself after offboarding | Confirm the start type is Manual and reboot |
| 55 | Failed to create the secure ETW autologger | Reboot |
| 63, 68 | A dependent service's start type was changed or is unexpected | Find what changed it (often Group Policy or a hardening script) and restore the expected start type |
| 64, 69 | A dependent service is stopped | Start the named service; contact support if it keeps recurring |
4. Decode the Intune-specific codes#
| Code | Meaning | Typical causes |
|---|---|---|
0x87D1FDE8 | Remediation failed | Wrong blob (bad signature or missing PreviousOrgIds field); the policy registry key doesn't exist or the MDM client can't write it; Intune trying to remediate a read-only node such as OnboardingState, OrgId or SenseIsRunning; an unsupported edition |
0x87D101A9 | SyncML 425: insufficient access control permissions | Unsupported SKU or platform. Intune onboarding supports Enterprise, Education and Professional editions |
Three compliance patterns are documented too. If SenseIsRunning is compliant but OrgId, Onboarding and OnboardingState aren't, Windows setup (OOBE) hasn't finished: wait. If it's the reverse, the service is set to delayed start and Intune evaluated too early: it resolves itself within 24 hours. If everything is non-compliant, check that an onboarding and an offboarding policy aren't both targeting the device. For MDM-side failures, the log Microsoft › Windows › DeviceManagement-Enterprise-Diagnostics-Provider › Admin event 1819 ("Failed to Set Node's Value") points to a missing cumulative update on Windows 10 1607.
In Intune, the Endpoint security › Endpoint detection and response › EDR Onboarding Status tab shows every device with its Onboarding status (Onboarded, Not onboarded or Pending), Defender sensor state (Active, Inactive or Impaired), how it's managed and its last check-in. Filter to Not onboarded and Pending to build your work list.
5. Fix connectivity#
Events 5 and 15 mean the sensor reached the point of calling home and failed. The sensor uses WinHTTP in the system context, so netsh winhttp show proxy is the proxy that matters, not the user's browser settings. Run the MDE Client Analyzer on the device to test each service URL through the available proxy methods, and remember that an authenticated proxy or TLS inspection on these destinations breaks the connection.
6. Onboarded, but no data#
If OnboardingState is 1 and the device shows in the portal but stays Inactive or Misconfigured, the problem is no longer onboarding. Check that the Windows diagnostic data service starts automatically (sc qc diagtrack; since Windows 10 1809 the sensor no longer strictly depends on it, but Microsoft still recommends it runs), re-check the proxy, and follow my earlier post on Inactive and No sensor data devices.
7. Offboard and re-onboard properly#
Download the offboarding package from Settings › Endpoints › Device management › Offboarding. It expires seven days after download (the date is in the file name) and expired packages are rejected. Never target a device with onboarding and offboarding at the same time: when re-onboarding through Intune, remove the device from the offboarding assignment first, confirm a clean sync, then assign the onboarding policy. An offboarded device turns Inactive after seven days and its profile stays in the inventory for up to 180 days, so a re-onboarded device may appear as a new record beside the old one.
Verify the fix#
On the device, sc query sense should report RUNNING and OnboardingState should be 1, with no new errors in the SENSE Operational log. In the Defender portal the device should appear in Assets › Devices as Onboarded with an Active sensor, usually within an hour. Run Microsoft's detection test from the onboarding documentation and confirm an alert arrives for the device.
Prevent it next time#
- Pilot every onboarding change on a device group first and check the EDR Onboarding Status tab before widening the assignment.
- Keep the Defender for Endpoint URLs excluded from TLS inspection and authenticated proxy rules, and re-test with the Client Analyzer after network changes.
- Never change the start type of the Sense service or the Defender Antivirus services (
WdBoot,WdFilter,WdNisDrv,WdNisSvc,WinDefend); Microsoft treats that as unsupported. - Treat offboarding as a planned operation with a fresh package, and record which devices it targeted.