Intune - Devices reported as without ATP-sensor

Chned 46 Reputation points
2020-09-29T12:45:57.437+00:00

So we activated Defender ATP within Intune and connected it with Microsoft Defender Security Center:

29124-atp.png

I can see the devices at https://securitycenter.windows.com/machines

29135-atp2.png

But Intune reports them as devices without ATP-sensor:

29108-atp3.png

Also Defender Security Center states: "Device not found in Azure ATP"

I don't know why this is, because I made a Device configuration profile for onboarding the devices in ATP:

29144-onboarsd.png

I looked at the SENSE log at Microsoft-Windows-SENSE/Operational, but don't see any errors there:

29173-image.png

only informational entry's >>

29163-info.png

Does anyone know where to look for now?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,233 questions
{count} votes

10 answers

Sort by: Most helpful
  1. Chned 46 Reputation points
    2020-09-29T14:32:05.427+00:00

    By the way, the following setting is enabled within Intune:

    29109-setting.png


  2. VipulSparsh-MSFT 16,251 Reputation points Microsoft Employee
    2020-09-30T12:45:33.917+00:00

    @Chned Can you confirm if the device configuration profile was created before establishing the connection as if we do that the package file needs to be uploaded separately. Also try targeting the Device Config policy for the Device Group as the evaluation is done in Device context. So you would not see different UPNs and system accounts.

    0 comments No comments

  3. Chned 46 Reputation points
    2020-09-30T13:20:50.747+00:00

    This current profile was created AFTER making the Microsoft Intune connection in Microsoft Defender Security Center. I then choose for "Create a device configuration profile to configure ATP sensor" at the bottom of the "Microsoft Defender ATP"-page.
    This profile is assigned to two groups and the Members in those groups are only those Devices.

    29407-profile.png


  4. Chned 46 Reputation points
    2020-10-06T13:07:25.223+00:00

    So here we go... I just deleted this onboarding device configuration profile again (for the 3rd time, as a last effort) and made it again (just the same way as I did this before) and now it is working! It's a really simple profile and you can't really mess up anything here..

    Very strange/buggy behaviour here..


  5. Chned 46 Reputation points
    2020-10-09T11:26:58.14+00:00

    Unfortunately, like I said: the device got wiped already so I can't see those logs anymore..

    Problem is that ATP-sensor doesn't work anymore. What could be the cause?