I have a problem and would like to know if there is a way to fix this.
The business has recently bought 790 defender P1 licenses to help protect endpoints so we have enough licenses to cover the number of devices that we have.
We have a total of 704 devices in Intune and 663 in Defender and we want these numbers to match. These 41 devices that are missing are active devices (made contact with Intune in the last 60 days) and the users have defender P1 license assigned but for some reason the Intune defender onboard policy says that the device is stuck in pending when I go to generate a report.
Intune Profile
The profile has been active for over 2 months and not changed at all. If it helps this is the configuration:
Microsoft Defender for Endpoint client configuration package type:
Onboard
Sample sharing for all files
Not configured
Expedite telemetry reporting frequency
Not configured

Errors:
Of those 37 errors it seems to be only 2 devices that are getting the error but 37 users. I can't show these as that will be too much information and names need to be hidden for privacy reasons.

These devices for whatever reason are still stuck in pending and if I go to look them up in Defender they aren't there which means they have not onboarded.

Things I have done to troubleshoot the issue:
- Re-applied the Intune policy
- Ran a bulk sync task using PowerShell
- Checked that the user is assigned a Defender P1
- The affected devices have made contact with Intune service in the last 7 days
Is there a solution for this and how do we get all the devices to onboard properly into Defender?
Kind Regards
Shaun Slater