problem running the Microsoft Defender onboarding script using GPO

HK G 516 Reputation points
2023-05-03T21:36:58.6066667+00:00

I am following the article below to onboarding our Windows servers to the Microsoft Defender Portal using the onboarding script with GPO.

The GPO was successfully applied to the servers and I can see the scheduled task (running the onboarding script) on the task list locally on the server. However, the script didn't seem to run and Network Threat protection service was not installed. I checked the task history and it didn't show any error other than the return code 2147942401. I checked the path (to the script) and the name of the script few times and it looks fine to.

Any idea how to troubleshoot this issue?

https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-endpoints-gp?view=o365-worldwide

Thanks

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,747 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,858 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 43,941 Reputation points
    2023-05-04T16:08:07.44+00:00

    Hello there,

    If the onboarding is completed successfully but the devices aren't showing up in the Devices list after an hour check the result of the script on the device:

    Click Start, type Event Viewer, and press Enter.

    Go to Windows Logs > Application.

    Look for an event from WDATPOnboarding event source.

    If the script fails and the event is an error, you can check the event ID in the following table to help you troubleshoot the issue. https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/troubleshoot-onboarding?view=o365-worldwide#troubleshoot-onboarding-when-deploying-with-a-script

    Hope this resolves your Query !!

    --If the reply is helpful, please Upvote and Accept it as an answer–