Checklist
MDE onboarding validation: Sense event IDs
Based on the article: Defender for Endpoint onboarding failures: SENSE event IDs, script errors and what they mean · 7 min read
An onboarding failure in Defender for Endpoint rarely tells you what went wrong in one place. The deployment tool reports one thing, the SENSE sensor writes another to its own event log, and the device simply never appears in the portal. In this post I'll map the whole chain: the registry values and service state to check first, the documented event IDs and error codes with what each one means, the Intune-specific failures, and how to offboard and re-onboard without making things worse.
Symptoms to confirm
- The device isn't in Assets › Devices in the Microsoft Defender portal an hour after onboarding ran.
- The Intune EDR policy shows an error such as
0x87D1FDE8or0x87D101A9, or reports the device as non-compliant on some onboarding settings but not others. - The local onboarding script finishes with an error event from the
WDATPOnboardingsource. - The
Senseservice won't start, or starts and logs connection failures.
Likely causes
- Onboarding is a short chain.
- The deployment tool (Intune, Group Policy, Configuration Manager or a local script) writes the onboarding blob to
HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection. - The
Senseservice starts, reads it, registers with the cloud over WinHTTP, and records the result underHKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status, whereOnboardingStatebecomes1. - Failures fall into three groups: the blob never arrived or couldn't be written (permissions, unsupported edition, mismatched package), the service couldn't start (missing SENSE component, Defender Antivirus disabled by policy, Windows setup not finished), or the service started but couldn't reach the service URLs (proxy, firewall, TLS inspection).
Checklist
- 1
Find out which link broke
From an elevated PowerShell session on the device:
powershellsc.exe query sense Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status' | Select-Object OnboardingState, OrgId Test-Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection' - 2
Read the onboarding script events
When a script (local, Group Policy or Configuration Manager) runs, it logs to Windows Logs › Application under the source
WDATPOnboarding. These IDs belong to the script only:Event ID Meaning What to do 5 Old offboarding data couldn't be removed Check permissions on the policy registry key above 10 Onboarding data couldn't be written to the registry Check permissions on the policy key; run the script as administrator 15 SENSE service failed to start Check sc query sensefor a pending state and retry. Errors 577 or 1058 mean Defender Antivirus (ELAM) is disabled by policy. On Windows editions where SENSE is a Feature on Demand, confirm it's installed (see below)30 Script timed out waiting for the service to run Check the SENSE Operational log for the underlying error 35 Onboarding status value not found in the registry The service hasn't written OnboardingState; check the SENSE log40 Onboarding status isn't 1 Service failed to onboard; check the SENSE log 65 Insufficient privileges Run with administrator rights 70 Offboarding script is for a different organisation Download the offboarding package from the tenant the device belongs to - 3
Read the SENSE Operational log
Open Applications and Services Logs › Microsoft › Windows › SENSE › Operational and filter on Critical, Warning and Error. These are the IDs Microsoft documents for onboarding problems:
Event ID Meaning What to do 5 Service failed to connect to the server Fix internet or proxy access (step 5) 6 Not onboarded and no onboarding parameters found Run onboarding again; the blob isn't on the device 7 Failed to read the onboarding parameters Confirm connectivity, then run the whole onboarding process again 9 Failed to change the service start type Reboot and rerun onboarding; if it happened during offboarding, contact support 10 Failed to persist the onboarding information Rerun onboarding; contact support if it persists 15 Can't start the command channel with the given URL Fix internet or proxy access (step 5) 17 Failed to change the Connected User Experiences and Telemetry service location Rerun onboarding; contact support if it persists 25 Failed to reset health status in the registry Contact support 27 Failed to enable Defender for Endpoint mode in Windows Defender Contact support 29 Failed to read the offboarding parameters Confirm connectivity, then run offboarding again 32 Service failed to stop itself after offboarding Confirm the start type is Manual and reboot 55 Failed to create the secure ETW autologger Reboot 63, 68 A dependent service's start type was changed or is unexpected Find what changed it (often Group Policy or a hardening script) and restore the expected start type 64, 69 A dependent service is stopped Start the named service; contact support if it keeps recurring - 4
Decode the Intune-specific codes
Code Meaning Typical causes 0x87D1FDE8Remediation failed Wrong blob (bad signature or missing PreviousOrgIdsfield); the policy registry key doesn't exist or the MDM client can't write it; Intune trying to remediate a read-only node such asOnboardingState,OrgIdorSenseIsRunning; an unsupported edition0x87D101A9SyncML 425: insufficient access control permissions Unsupported SKU or platform. Intune onboarding supports Enterprise, Education and Professional editions Three compliance patterns are documented too. If
SenseIsRunningis compliant butOrgId,OnboardingandOnboardingStatearen't, Windows setup (OOBE) hasn't finished: wait. - 5
Fix connectivity
Events 5 and 15 mean the sensor reached the point of calling home and failed. The sensor uses WinHTTP in the system context, so
netsh winhttp show proxyis the proxy that matters, not the user's browser settings. - 6
Onboarded, but no data
If
OnboardingStateis1and the device shows in the portal but stays Inactive or Misconfigured, the problem is no longer onboarding. - 7
Offboard and re-onboard properly
Download the offboarding package from Settings › Endpoints › Device management › Offboarding. It expires seven days after download (the date is in the file name) and expired packages are rejected.
Verify
- On the device,
sc query senseshould reportRUNNINGandOnboardingStateshould be1, with no new errors in the SENSE Operational log. - In the Defender portal the device should appear in Assets › Devices as Onboarded with an Active sensor, usually within an hour.
- Run Microsoft's detection test from the onboarding documentation and confirm an alert arrives for the device.
Prevent it next time
- Pilot every onboarding change on a device group first and check the EDR Onboarding Status tab before widening the assignment.
- Keep the Defender for Endpoint URLs excluded from TLS inspection and authenticated proxy rules, and re-test with the Client Analyzer after network changes.
- Never change the start type of the Sense service or the Defender Antivirus services (
WdBoot,WdFilter,WdNisDrv,WdNisSvc,WinDefend); Microsoft treats that as unsupported. - Treat offboarding as a planned operation with a fresh package, and record which devices it targeted.