How to fix devices in Intune not onboarding to Defender

Shaun Slater 66 Reputation points
2023-10-27T14:04:19.65+00:00

I have a problem and would like to know if there is a way to fix this.

The business has recently bought 790 defender P1 licenses to help protect endpoints so we have enough licenses to cover the number of devices that we have.

We have a total of 704 devices in Intune and 663 in Defender and we want these numbers to match. These 41 devices that are missing are active devices (made contact with Intune in the last 60 days) and the users have defender P1 license assigned but for some reason the Intune defender onboard policy says that the device is stuck in pending when I go to generate a report.

Intune Profile

The profile has been active for over 2 months and not changed at all. If it helps this is the configuration:

Microsoft Defender for Endpoint client configuration package type:

Onboard

Sample sharing for all files

Not configured

Expedite telemetry reporting frequency

Not configured

User's image

Errors:

Of those 37 errors it seems to be only 2 devices that are getting the error but 37 users. I can't show these as that will be too much information and names need to be hidden for privacy reasons.

User's image

These devices for whatever reason are still stuck in pending and if I go to look them up in Defender they aren't there which means they have not onboarded.

User's image

Things I have done to troubleshoot the issue:

  • Re-applied the Intune policy
  • Ran a bulk sync task using PowerShell
  • Checked that the user is assigned a Defender P1
  • The affected devices have made contact with Intune service in the last 7 days

Is there a solution for this and how do we get all the devices to onboard properly into Defender?

Kind Regards

Shaun Slater

Microsoft Security | Intune | Other
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2023-10-30T02:11:18.4366667+00:00

    @Shaun Slater, Thanks for posting in Q&A. From your description, I know there are some devices not onboard to Defender.

    To troubleshoot the issue, please follow the steps in the following link to check the logs to see which phase we are failed and if we can find any related error message:

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/troubleshoot-onboarding?view=o365-worldwide#troubleshoot-onboarding-issues-using-microsoft-intune

    If there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.