You assign the EDR onboarding policy, the device syncs, and nothing happens: Intune reports an error, the device never appears in the Defender inventory, and if Conditional Access requires compliance the user is locked out. On Windows 11 24H2 the cause is often not your policy at all. The Defender for Endpoint sensor component may simply not be installed. In this post I'll show how to confirm it, fix it at scale with Remediations, and stop it recurring.
Status (October 2026): Microsoft documented this in KB5043950 (published 2024) for Windows 11, version 24H2 on all supported architectures. It is documented behaviour rather than a bug awaiting a fix: Defender for Endpoint was removed from the 24H2 base image and the Sense client is a Feature on Demand that some devices lack. The DISM workaround in the KB remains the resolution. Re-check the KB and the Features on Demand page, because Microsoft updates both.
Symptoms#
- The Endpoint detection and response policy shows an error for the device in Endpoint security › Endpoint detection and response, and the device never reaches "Successfully onboarded" on the EDR Onboarding Status tab.
- The device is absent from Assets › Devices in the Microsoft Defender portal and receives none of the expected protection.
- If your compliance policy requires a Defender risk level and Conditional Access requires compliance, the user cannot reach corporate resources. The compliance state is visible in the Intune device compliance dashboard.
- On the device,
Get-Service Sensefails because the service doesn't exist, and the Microsoft › Windows › SENSE › Operational event log is empty or missing.
Why it happens#
KB5043950 describes two scenarios on new Windows 11 24H2 devices:
- A device bought with the Home edition, which doesn't support Defender for Endpoint, is upgraded to Pro with a product key. That edition change (Microsoft calls it "transmog") doesn't install Defender for Endpoint, by design, so the agent never enrols with the service and the device isn't protected.
- A device bought with the Pro edition where the OEM didn't install the required feature.
Microsoft states that Defender for Endpoint has been removed from the base image for Windows 11, version 24H2 and must be installed manually whenever a device goes from Home to Pro. The component is the Feature on Demand SENSE Client for Microsoft Defender for Endpoint, capability name Microsoft.Windows.Sense.Client~~~~. The Features on Demand page adds the details that matter for admins: it is supported on editions above Home (Pro, Enterprise, Education), devices without it cannot onboard, it is about 47 MB, it is listed as available for Windows 11 24H2 and later, and once installed it cannot be uninstalled and won't show in the Optional features list in Settings.
The Defender onboarding troubleshooting guide points at the same cause when the Sense service fails to start: check the capability with DISM /Online /Get-CapabilityInfo, and if the state isn't Installed, install the FoD.
How to fix it#
1. Confirm on one device#
DISM /online /Get-CapabilityInfo /CapabilityName:Microsoft.Windows.Sense.Client~~~~A state of Installed means the component is there and your problem lies elsewhere (start with the onboarding troubleshooting guide). An error or Not Present confirms this issue.
2. Install the capability#
From an elevated command prompt, exactly as the KB documents:
DISM /online /Add-Capability /CapabilityName:Microsoft.Windows.Sense.Client~~~~Without a /Source, DISM downloads the package from Windows Update, so the device needs internet access. Devices that get updates from WSUS or Configuration Manager often block Feature on Demand downloads; the DISM documentation notes that FoD content can't be hosted on WSUS, so either allow optional-component downloads directly from Windows Update by policy or point /Source at a share containing the Languages and Optional Features media for your build.
3. Detect and fix at scale with Remediations#
Create a script package under Devices › Scripts and remediations › Remediations, run it as SYSTEM with Run script in 64-bit PowerShell set to Yes (the DISM module needs the 64-bit host), and target your Windows 11 device group. Detection:
$cap = Get-WindowsCapability -Online | Where-Object Name -like 'Microsoft.Windows.Sense.Client*'
if ($cap -and $cap.State -eq 'Installed') {
Write-Output 'Sense client present'
exit 0
}
Write-Output "Sense client missing (state: $($cap.State))"
exit 1Remediation:
try {
$result = Add-WindowsCapability -Online -Name 'Microsoft.Windows.Sense.Client~~~~'
if ($result.RestartNeeded) { Write-Output 'Installed, restart needed' } else { Write-Output 'Installed' }
exit 0
}
catch {
Write-Output "Install failed: $($_.Exception.Message)"
exit 1
}Keep the schedule daily during the clean-up and move it to weekly afterwards. Remember that Home edition devices can't be fixed this way; they need a proper edition upgrade first, and the FoD still has to be added afterwards.
4. Let onboarding complete#
Trigger a Sync from the device record so the EDR policy re-applies. The KB doesn't require a restart, but if the policy stays in error after a sync, restart the device and sync again before digging deeper.
Verify the fix#
- On the device,
Get-Service Sensereturns Running, andOnboardingStateunderHKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Statusis1. The onboarding guide describes the Sense service writing this value on first start, and event ID 40 in the SENSE log if it never reaches 1. - In Intune, the EDR policy reports success for the device and the EDR Onboarding Status tab shows it as onboarded.
- Within 15–30 minutes the device appears under Assets › Devices in the Defender portal; Microsoft's guidance treats a device still missing after an hour as an onboarding or connectivity problem.
- If you require a Defender risk level in compliance, the device becomes compliant at its next check-in and Conditional Access lets the user back in.
Prevent it next time#
- Buy devices with Pro, Enterprise or Education preinstalled from OEMs that include the Sense FoD; Microsoft strongly recommends OEMs preinstall it on those editions.
- If you build your own images, add the capability offline with
Add-WindowsCapability -Pathand a-Sourcepointing at the Languages and Optional Features media, so the component is present before Autopilot runs. - If you use Intune's Edition upgrade profile to move Home devices to Pro, plan the FoD installation as a follow-up step; the edition change alone won't add it.
- Keep the detection script running as a Remediation so new devices are caught at first sign-in, and review EDR Onboarding Status weekly.