oeltayeb.com · Defender Toolkit

Checklist

Device shows "Inactive" or "No sensor data" in Microsoft Defender: how to troubleshoot

Based on the article: Device shows "Inactive" or "No sensor data" in Microsoft Defender: how to troubleshoot · 4 min read

A device marked Inactive or Misconfigured in the Defender device inventory is either a blind spot, where the sensor isn't sending the telemetry you're paying for, or a stale record cluttering your reports. In this post I'll explain what each sensor health state means, then walk through the checks that tell you whether to fix the device, fix the network, or simply let an old record age out.

Symptoms to confirm

  • In Assets › Devices, the Sensor health state column shows Inactive, or Misconfigured with the detail Impaired communications or No sensor data.
  • The device timeline has gaps, and alerts you'd expect never appear.
  • The same computer name shows up twice: one Active record and one Inactive.
  • Intune still reports the EDR onboarding policy as Succeeded.

Likely causes

StateWhat it meansTypical causes
InactiveNo signals from the device for more than seven daysDevice switched off or out of use; reinstalled or renamed (a new record is created and the old one goes inactive); offboarded; sensor stopped reporting
Misconfigured: Impaired communicationsOnly limited communication with the serviceProxy, firewall or WinHTTP configuration
Misconfigured: No sensor dataThe device reaches the service but sends only partial sensor dataConnectivity or proxy gaps, the Windows diagnostic data service disabled, or Defender Antivirus disabled by policy alongside third-party antivirus
  • Inactive isn't automatically a fault. An offboarded device stays in the inventory, turns Inactive after seven days, and its profile (without data) can remain for up to 180 days.

Checklist

  1. 1

    Rule out a stale or duplicate record

    Search the inventory for the device name. If a newer Active record exists, the device was most likely reinstalled or renamed and the Inactive entry is just history. With Plan 2, this advanced hunting query lists names that map to more than one device ID:

    kusto
    DeviceInfo
    | where Timestamp > ago(30d)
    | summarize LastReport = max(Timestamp), Records = dcount(DeviceId) by DeviceName
    | where Records > 1
    | order by LastReport desc
  2. 2

    Check the sensor and onboarding state

    From an elevated PowerShell session on the device:

    powershell
    Get-Service -Name Sense, DiagTrack | Select-Object Name, Status, StartType
    Get-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status' |
        Select-Object OnboardingState
    • Sense should be Running and OnboardingState should be 1. If the value is missing or 0, the device isn't onboarded: check the EDR policy assignment and make sure no offboarding policy targets it.
    • DiagTrack is the Windows diagnostic data service. Microsoft's guidance for No sensor data is to confirm it starts automatically and is running; sc qc diagtrack shows the start type.
  3. 3

    Check the proxy the sensor actually uses

    The sensor communicates through WinHTTP in the system context, independently of the user's browser proxy. See what WinHTTP is configured with:

    cmd
    netsh winhttp show proxy
    • Streamlined connectivity consolidates the core services under *.endpoint.security.microsoft.com, plus supporting endpoints such as certificate revocation and Windows Update. Devices only use it after onboarding with a streamlined onboarding package.
    • Standard connectivity uses the longer, region-specific URL list.
  4. 4

    Run the MDE Client Analyzer

    Download the analyzer from the Microsoft Learn page in the references, extract MDEClientAnalyzer.zip, and run it from an elevated Command Prompt (adjust the path to wherever you extracted it):

    cmd
    C:\Tools\MDEClientAnalyzer\MDEClientAnalyzer.cmd

    Tip: the analyzer uses PsExec to run its cloud checks as Local System, so the ASR rule Block process creations originating from PSExec and WMI commands can block it. Add a temporary exclusion or switch that rule to Audit while you test. With Plan 2 you can also run the analyzer remotely through live response.

  5. 5

    Make sure Defender Antivirus isn't disabled by policy

    On devices running third-party antivirus, the sensor still depends on Defender Antivirus components such as its early-launch antimalware (ELAM) driver.

Verify

  • Health states aren't real time, so give the device a while online after the fix.
  • Then re-check Assets › Devices: the sensor health state should return to Active, and new events should appear on the device's Timeline tab.
  • For full confidence, run Microsoft's detection test from the onboarding documentation and confirm an alert shows up for the device.

Prevent it next time

  • Filter the device inventory on Sensor health state regularly, and use the device health report under Reports › Endpoints for a fleet view.
  • Offboard devices before retiring them, and expect a new record every time a device is reimaged or renamed.
  • Keep Defender for Endpoint destinations out of TLS inspection and user-authenticated proxy rules.
  • Next time you revisit onboarding, consider streamlined connectivity; a shorter allow list is easier to keep right.

Microsoft Learn references