Confirmation for Offboarded servers

Eddie Vincent 145 Reputation points
2024-12-02T09:45:24.6266667+00:00

Hi All!

I'm currently in the process of offboarding a bunch of servers (Windows Server 2012 R2 version) machines from Defender using the local script method to start (as a pilot to prove the process). https://learn.microsoft.com/en-us/defender-endpoint/configure-endpoints-script#offboard-devices-using-a-local-script

It seems to be successful, providing all the right signs that the machine has offboarded:

Server:

User's image

Machine:

User's image

However they don't disappear from the defender portal as would be expected (neither does the status of the machines change in any way).

I do believe Defender for Endpoint holds onto machines for 180 days as per the below:

User's image However are there any tips or tricks to proving/understanding that the machines are in an "offboarded" state and would no longer be incurring charge?

I did consider that they maybe getting re-onboarded by a policy, but this has been checked and is not the case - also this would show in the Event viewer logs on the server itself (which isn't the case).

Any assistance would be appreciated - thanks.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
{count} votes

Accepted answer
  1. Givary-MSFT 35,626 Reputation points Microsoft Employee Moderator
    2024-12-03T05:17:25.7166667+00:00

    @Eddie Vincent Thank you for reaching out to us, once the device is offboarded, it still appears in devices list. After seven days, the device health state should change to inactive. Machines will go into an ‘inactive’ state after 7 days of zero cyber data activity (for example if machines were offboarded, turned off, disconnected... etc.). Same information has been documented here - https://learn.microsoft.com/en-us/defender-endpoint/fix-unhealthy-sensors

    Regarding the retention your understanding is correct. For security purposes, the device will remain in the portal as an historical record for up to 180 days. However, the device's data will be purged according to your retention period. 

    I.e. The machines will “disappear” from the portal once the machines become inactive (they stop sending cyber data), and no later than 180 days since they stopped sending data to cloud. 

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.


1 additional answer

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.