Checklist
Device shows "Inactive" or "No sensor data" in Microsoft Defender: how to troubleshoot
Based on the article: Device shows "Inactive" or "No sensor data" in Microsoft Defender: how to troubleshoot · 4 min read
A device marked Inactive or Misconfigured in the Defender device inventory is either a blind spot, where the sensor isn't sending the telemetry you're paying for, or a stale record cluttering your reports. In this post I'll explain what each sensor health state means, then walk through the checks that tell you whether to fix the device, fix the network, or simply let an old record age out.
Symptoms to confirm
- In Assets › Devices, the Sensor health state column shows Inactive, or Misconfigured with the detail Impaired communications or No sensor data.
- The device timeline has gaps, and alerts you'd expect never appear.
- The same computer name shows up twice: one Active record and one Inactive.
- Intune still reports the EDR onboarding policy as Succeeded.
Likely causes
| State | What it means | Typical causes |
|---|---|---|
| Inactive | No signals from the device for more than seven days | Device switched off or out of use; reinstalled or renamed (a new record is created and the old one goes inactive); offboarded; sensor stopped reporting |
| Misconfigured: Impaired communications | Only limited communication with the service | Proxy, firewall or WinHTTP configuration |
| Misconfigured: No sensor data | The device reaches the service but sends only partial sensor data | Connectivity or proxy gaps, the Windows diagnostic data service disabled, or Defender Antivirus disabled by policy alongside third-party antivirus |
- Inactive isn't automatically a fault. An offboarded device stays in the inventory, turns Inactive after seven days, and its profile (without data) can remain for up to 180 days.
Checklist
- 1
Rule out a stale or duplicate record
Search the inventory for the device name. If a newer Active record exists, the device was most likely reinstalled or renamed and the Inactive entry is just history. With Plan 2, this advanced hunting query lists names that map to more than one device ID:
kustoDeviceInfo | where Timestamp > ago(30d) | summarize LastReport = max(Timestamp), Records = dcount(DeviceId) by DeviceName | where Records > 1 | order by LastReport desc - 2
Check the sensor and onboarding state
From an elevated PowerShell session on the device:
powershellGet-Service -Name Sense, DiagTrack | Select-Object Name, Status, StartType Get-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status' | Select-Object OnboardingStateSenseshould be Running andOnboardingStateshould be1. If the value is missing or0, the device isn't onboarded: check the EDR policy assignment and make sure no offboarding policy targets it.DiagTrackis the Windows diagnostic data service. Microsoft's guidance for No sensor data is to confirm it starts automatically and is running;sc qc diagtrackshows the start type.
- 3
Check the proxy the sensor actually uses
The sensor communicates through WinHTTP in the system context, independently of the user's browser proxy. See what WinHTTP is configured with:
cmdnetsh winhttp show proxy- Streamlined connectivity consolidates the core services under
*.endpoint.security.microsoft.com, plus supporting endpoints such as certificate revocation and Windows Update. Devices only use it after onboarding with a streamlined onboarding package. - Standard connectivity uses the longer, region-specific URL list.
- Streamlined connectivity consolidates the core services under
- 4
Run the MDE Client Analyzer
Download the analyzer from the Microsoft Learn page in the references, extract
MDEClientAnalyzer.zip, and run it from an elevated Command Prompt (adjust the path to wherever you extracted it):cmdC:\Tools\MDEClientAnalyzer\MDEClientAnalyzer.cmdTip: the analyzer uses PsExec to run its cloud checks as Local System, so the ASR rule Block process creations originating from PSExec and WMI commands can block it. Add a temporary exclusion or switch that rule to Audit while you test. With Plan 2 you can also run the analyzer remotely through live response.
- 5
Make sure Defender Antivirus isn't disabled by policy
On devices running third-party antivirus, the sensor still depends on Defender Antivirus components such as its early-launch antimalware (ELAM) driver.
Verify
- Health states aren't real time, so give the device a while online after the fix.
- Then re-check Assets › Devices: the sensor health state should return to Active, and new events should appear on the device's Timeline tab.
- For full confidence, run Microsoft's detection test from the onboarding documentation and confirm an alert shows up for the device.
Prevent it next time
- Filter the device inventory on Sensor health state regularly, and use the device health report under Reports › Endpoints for a fleet view.
- Offboard devices before retiring them, and expect a new record every time a device is reimaged or renamed.
- Keep Defender for Endpoint destinations out of TLS inspection and user-authenticated proxy rules.
- Next time you revisit onboarding, consider streamlined connectivity; a shorter allow list is easier to keep right.