Intune - Devices reported as without ATP-sensor

Chned 51 Reputation points
2020-09-29T12:45:57.437+00:00

So we activated Defender ATP within Intune and connected it with Microsoft Defender Security Center:

29124-atp.png

I can see the devices at https://securitycenter.windows.com/machines

29135-atp2.png

But Intune reports them as devices without ATP-sensor:

29108-atp3.png

Also Defender Security Center states: "Device not found in Azure ATP"

I don't know why this is, because I made a Device configuration profile for onboarding the devices in ATP:

29144-onboarsd.png

I looked at the SENSE log at Microsoft-Windows-SENSE/Operational, but don't see any errors there:

29173-image.png

only informational entry's >>

29163-info.png

Does anyone know where to look for now?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,241 questions
{count} votes

10 answers

Sort by: Most helpful
  1. Chned 51 Reputation points
    2020-10-20T14:45:01.027+00:00

    In the MDM Diagnostic Report I can't find anything related to "onboard" or "onboarding".

    At the event log under Applications and Services Logs\Microsoft\Windows\DeviceManagement-EnterpriseDiagnostics-Provider I didn't find anything related to "onboarding" or "WindowsAdvancedThreatProtection".

    Also I logged on with a local admin account on this device and now I see the status on the Device configuration profile for the Defender Onboarding change to succeeded:
    33688-atp.png

    Also the ATP-sensor seems to be working now!

    33610-atp2.png

    But https://securitycenter.windows.com still shows:

    33657-atp3.png

    Additional question: It shouldn't be required to logon with a local account to have the security on these Win10 devices activated in the right way, right?? I can't let this ship to our end-users this way.


  2. Chned 51 Reputation points
    2020-10-21T06:27:47.81+00:00

    Strange, because I do see other details like (see screenshot below).

    About the policy groups: these are 2 Azure Cloud Security groups. In one of these groups is this particular device a Direct member. In the groups only Win10 Devices are assigned.

    33817-1.png


  3. Chned 51 Reputation points
    2020-10-23T07:23:27.487+00:00

    I assigned the configuration profile for onboarding Defender to all users group, but I see the same error. SENSE-log shows no errors. No ATP-sensor active.

    34496-1.png

    34516-2.png

    34427-3.png

    34475-4.png

    0 comments No comments

  4. Chned 51 Reputation points
    2020-10-23T12:11:36.91+00:00

    The above response was too quickly; it is working now the onboarding profile is assigned to the All users group! After the adjustment I enrolled a device too soon I guess.

    Only thing is that https://securitycenter.windows.com/ still shows: "Device not found in Azure ATP"

    0 comments No comments

  5. Crystal-MSFT 45,251 Reputation points Microsoft Vendor
    2020-10-26T04:50:24.42+00:00

    @Chned , Thanks for the update. I am glad to hear that the onboarding is working well now. Congratulations! For the issue in security center, as we are not familiar with this. To better help on this, we suggest to contact the windows security support to help:
    https://learn.microsoft.com/en-us/answers/topics/windows-10-security.html

    Thanks for the understanding.

    0 comments No comments