IntuneTroubleshooting

Windows 11 24H2 won't onboard to Defender for Endpoint: the missing Sense client (KB5043950)

Some Windows 11 24H2 devices ship without the Sense client, so Intune's EDR policy errors and the device never reaches Defender. How to detect it at scale with Remediations and add the capability.

You assign the EDR onboarding policy, the device syncs, and nothing happens: Intune reports an error, the device never appears in the Defender inventory, and if Conditional Access requires compliance the user is locked out. On Windows 11 24H2 the cause is often not your policy at all. The Defender for Endpoint sensor component may simply not be installed. In this post I'll show how to confirm it, fix it at scale with Remediations, and stop it recurring.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (4 steps: Confirm on one device; Install the capability; Detect and fix at scale with Remediations; Let onboarding complete). 4. Verify the fix. 5. Prevent it next time. Toolbox: Event ID 40, DISM /Online, Add-WindowsCapability, …\Windows Advanced Threat Protection\Status, Assets › Devices.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttime1Confirm on one device2Install the capability3Detect and fix at scalewith Remediations4Let onboarding completeTOOLBOXEvent ID 40DISM /OnlineAdd-WindowsCapability…\Windows Advanced Threat Protect…Assets › DevicesHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (4 steps: Confirm on one device; Install the capability; Detect and fix at scale with Remediations; Let onboarding complete). 4. Verify the fix. 5. Prevent it next time. Toolbox: Event ID 40, DISM /Online, Add-WindowsCapability, …\Windows Advanced Threat Protection\Status, Assets › Devices.1Symptoms2Why it happens3How to fix it1Confirm on one device2Install the capability3Detect and fix at scale with Remediations4Let onboarding complete4Verify the fix5Prevent it next timeTOOLBOXEvent ID 40DISM /OnlineAdd-WindowsCapability…\Windows Advanced Threat Protection\StatusAssets › Devices
At a glance: how this guide is organised · 4 fix steps · 5 key tools

Status (October 2026): Microsoft documented this in KB5043950 (published 2024) for Windows 11, version 24H2 on all supported architectures. It is documented behaviour rather than a bug awaiting a fix: Defender for Endpoint was removed from the 24H2 base image and the Sense client is a Feature on Demand that some devices lack. The DISM workaround in the KB remains the resolution. Re-check the KB and the Features on Demand page, because Microsoft updates both.

Symptoms#

  • The Endpoint detection and response policy shows an error for the device in Endpoint security › Endpoint detection and response, and the device never reaches "Successfully onboarded" on the EDR Onboarding Status tab.
  • The device is absent from Assets › Devices in the Microsoft Defender portal and receives none of the expected protection.
  • If your compliance policy requires a Defender risk level and Conditional Access requires compliance, the user cannot reach corporate resources. The compliance state is visible in the Intune device compliance dashboard.
  • On the device, Get-Service Sense fails because the service doesn't exist, and the Microsoft › Windows › SENSE › Operational event log is empty or missing.

Why it happens#

KB5043950 describes two scenarios on new Windows 11 24H2 devices:

  • A device bought with the Home edition, which doesn't support Defender for Endpoint, is upgraded to Pro with a product key. That edition change (Microsoft calls it "transmog") doesn't install Defender for Endpoint, by design, so the agent never enrols with the service and the device isn't protected.
  • A device bought with the Pro edition where the OEM didn't install the required feature.

Microsoft states that Defender for Endpoint has been removed from the base image for Windows 11, version 24H2 and must be installed manually whenever a device goes from Home to Pro. The component is the Feature on Demand SENSE Client for Microsoft Defender for Endpoint, capability name Microsoft.Windows.Sense.Client~~~~. The Features on Demand page adds the details that matter for admins: it is supported on editions above Home (Pro, Enterprise, Education), devices without it cannot onboard, it is about 47 MB, it is listed as available for Windows 11 24H2 and later, and once installed it cannot be uninstalled and won't show in the Optional features list in Settings.

The Defender onboarding troubleshooting guide points at the same cause when the Sense service fails to start: check the capability with DISM /Online /Get-CapabilityInfo, and if the state isn't Installed, install the FoD.

How to fix it#

1. Confirm on one device#

Command Prompt
DISM /online /Get-CapabilityInfo /CapabilityName:Microsoft.Windows.Sense.Client~~~~

A state of Installed means the component is there and your problem lies elsewhere (start with the onboarding troubleshooting guide). An error or Not Present confirms this issue.

2. Install the capability#

From an elevated command prompt, exactly as the KB documents:

Command Prompt
DISM /online /Add-Capability /CapabilityName:Microsoft.Windows.Sense.Client~~~~

Without a /Source, DISM downloads the package from Windows Update, so the device needs internet access. Devices that get updates from WSUS or Configuration Manager often block Feature on Demand downloads; the DISM documentation notes that FoD content can't be hosted on WSUS, so either allow optional-component downloads directly from Windows Update by policy or point /Source at a share containing the Languages and Optional Features media for your build.

3. Detect and fix at scale with Remediations#

Create a script package under Devices › Scripts and remediations › Remediations, run it as SYSTEM with Run script in 64-bit PowerShell set to Yes (the DISM module needs the 64-bit host), and target your Windows 11 device group. Detection:

PowerShell
$cap = Get-WindowsCapability -Online | Where-Object Name -like 'Microsoft.Windows.Sense.Client*'
if ($cap -and $cap.State -eq 'Installed') {
    Write-Output 'Sense client present'
    exit 0
}
Write-Output "Sense client missing (state: $($cap.State))"
exit 1

Remediation:

PowerShell
try {
    $result = Add-WindowsCapability -Online -Name 'Microsoft.Windows.Sense.Client~~~~'
    if ($result.RestartNeeded) { Write-Output 'Installed, restart needed' } else { Write-Output 'Installed' }
    exit 0
}
catch {
    Write-Output "Install failed: $($_.Exception.Message)"
    exit 1
}

Keep the schedule daily during the clean-up and move it to weekly afterwards. Remember that Home edition devices can't be fixed this way; they need a proper edition upgrade first, and the FoD still has to be added afterwards.

4. Let onboarding complete#

Trigger a Sync from the device record so the EDR policy re-applies. The KB doesn't require a restart, but if the policy stays in error after a sync, restart the device and sync again before digging deeper.

Verify the fix#

  • On the device, Get-Service Sense returns Running, and OnboardingState under HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status is 1. The onboarding guide describes the Sense service writing this value on first start, and event ID 40 in the SENSE log if it never reaches 1.
  • In Intune, the EDR policy reports success for the device and the EDR Onboarding Status tab shows it as onboarded.
  • Within 15–30 minutes the device appears under Assets › Devices in the Defender portal; Microsoft's guidance treats a device still missing after an hour as an onboarding or connectivity problem.
  • If you require a Defender risk level in compliance, the device becomes compliant at its next check-in and Conditional Access lets the user back in.

Prevent it next time#

  • Buy devices with Pro, Enterprise or Education preinstalled from OEMs that include the Sense FoD; Microsoft strongly recommends OEMs preinstall it on those editions.
  • If you build your own images, add the capability offline with Add-WindowsCapability -Path and a -Source pointing at the Languages and Optional Features media, so the component is present before Autopilot runs.
  • If you use Intune's Edition upgrade profile to move Home devices to Pro, plan the FoD installation as a follow-up step; the edition change alone won't add it.
  • Keep the detection script running as a Remediation so new devices are caught at first sign-in, and review EDR Onboarding Status weekly.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)