oeltayeb.com · Defender Toolkit

Checklist

MDE onboarding validation: Sense event IDs

Based on the article: Defender for Endpoint onboarding failures: SENSE event IDs, script errors and what they mean · 7 min read

An onboarding failure in Defender for Endpoint rarely tells you what went wrong in one place. The deployment tool reports one thing, the SENSE sensor writes another to its own event log, and the device simply never appears in the portal. In this post I'll map the whole chain: the registry values and service state to check first, the documented event IDs and error codes with what each one means, the Intune-specific failures, and how to offboard and re-onboard without making things worse.

Symptoms to confirm

  • The device isn't in Assets › Devices in the Microsoft Defender portal an hour after onboarding ran.
  • The Intune EDR policy shows an error such as 0x87D1FDE8 or 0x87D101A9, or reports the device as non-compliant on some onboarding settings but not others.
  • The local onboarding script finishes with an error event from the WDATPOnboarding source.
  • The Sense service won't start, or starts and logs connection failures.

Likely causes

  • Onboarding is a short chain.
  • The deployment tool (Intune, Group Policy, Configuration Manager or a local script) writes the onboarding blob to HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection.
  • The Sense service starts, reads it, registers with the cloud over WinHTTP, and records the result under HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status, where OnboardingState becomes 1.
  • Failures fall into three groups: the blob never arrived or couldn't be written (permissions, unsupported edition, mismatched package), the service couldn't start (missing SENSE component, Defender Antivirus disabled by policy, Windows setup not finished), or the service started but couldn't reach the service URLs (proxy, firewall, TLS inspection).

Checklist

  1. 1

    Find out which link broke

    From an elevated PowerShell session on the device:

    powershell
    sc.exe query sense
    Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status' |
        Select-Object OnboardingState, OrgId
    Test-Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection'
  2. 2

    Read the onboarding script events

    When a script (local, Group Policy or Configuration Manager) runs, it logs to Windows Logs › Application under the source WDATPOnboarding. These IDs belong to the script only:

    Event IDMeaningWhat to do
    5Old offboarding data couldn't be removedCheck permissions on the policy registry key above
    10Onboarding data couldn't be written to the registryCheck permissions on the policy key; run the script as administrator
    15SENSE service failed to startCheck sc query sense for a pending state and retry. Errors 577 or 1058 mean Defender Antivirus (ELAM) is disabled by policy. On Windows editions where SENSE is a Feature on Demand, confirm it's installed (see below)
    30Script timed out waiting for the service to runCheck the SENSE Operational log for the underlying error
    35Onboarding status value not found in the registryThe service hasn't written OnboardingState; check the SENSE log
    40Onboarding status isn't 1Service failed to onboard; check the SENSE log
    65Insufficient privilegesRun with administrator rights
    70Offboarding script is for a different organisationDownload the offboarding package from the tenant the device belongs to
  3. 3

    Read the SENSE Operational log

    Open Applications and Services Logs › Microsoft › Windows › SENSE › Operational and filter on Critical, Warning and Error. These are the IDs Microsoft documents for onboarding problems:

    Event IDMeaningWhat to do
    5Service failed to connect to the serverFix internet or proxy access (step 5)
    6Not onboarded and no onboarding parameters foundRun onboarding again; the blob isn't on the device
    7Failed to read the onboarding parametersConfirm connectivity, then run the whole onboarding process again
    9Failed to change the service start typeReboot and rerun onboarding; if it happened during offboarding, contact support
    10Failed to persist the onboarding informationRerun onboarding; contact support if it persists
    15Can't start the command channel with the given URLFix internet or proxy access (step 5)
    17Failed to change the Connected User Experiences and Telemetry service locationRerun onboarding; contact support if it persists
    25Failed to reset health status in the registryContact support
    27Failed to enable Defender for Endpoint mode in Windows DefenderContact support
    29Failed to read the offboarding parametersConfirm connectivity, then run offboarding again
    32Service failed to stop itself after offboardingConfirm the start type is Manual and reboot
    55Failed to create the secure ETW autologgerReboot
    63, 68A dependent service's start type was changed or is unexpectedFind what changed it (often Group Policy or a hardening script) and restore the expected start type
    64, 69A dependent service is stoppedStart the named service; contact support if it keeps recurring
  4. 4

    Decode the Intune-specific codes

    CodeMeaningTypical causes
    0x87D1FDE8Remediation failedWrong blob (bad signature or missing PreviousOrgIds field); the policy registry key doesn't exist or the MDM client can't write it; Intune trying to remediate a read-only node such as OnboardingState, OrgId or SenseIsRunning; an unsupported edition
    0x87D101A9SyncML 425: insufficient access control permissionsUnsupported SKU or platform. Intune onboarding supports Enterprise, Education and Professional editions

    Three compliance patterns are documented too. If SenseIsRunning is compliant but OrgId, Onboarding and OnboardingState aren't, Windows setup (OOBE) hasn't finished: wait.

  5. 5

    Fix connectivity

    Events 5 and 15 mean the sensor reached the point of calling home and failed. The sensor uses WinHTTP in the system context, so netsh winhttp show proxy is the proxy that matters, not the user's browser settings.

  6. 6

    Onboarded, but no data

    If OnboardingState is 1 and the device shows in the portal but stays Inactive or Misconfigured, the problem is no longer onboarding.

  7. 7

    Offboard and re-onboard properly

    Download the offboarding package from Settings › Endpoints › Device management › Offboarding. It expires seven days after download (the date is in the file name) and expired packages are rejected.

Verify

  • On the device, sc query sense should report RUNNING and OnboardingState should be 1, with no new errors in the SENSE Operational log.
  • In the Defender portal the device should appear in Assets › Devices as Onboarded with an Active sensor, usually within an hour.
  • Run Microsoft's detection test from the onboarding documentation and confirm an alert arrives for the device.

Prevent it next time

  • Pilot every onboarding change on a device group first and check the EDR Onboarding Status tab before widening the assignment.
  • Keep the Defender for Endpoint URLs excluded from TLS inspection and authenticated proxy rules, and re-test with the Client Analyzer after network changes.
  • Never change the start type of the Sense service or the Defender Antivirus services (WdBoot, WdFilter, WdNisDrv, WdNisSvc, WinDefend); Microsoft treats that as unsupported.
  • Treat offboarding as a planned operation with a fresh package, and record which devices it targeted.

Microsoft Learn references