Additional Microsoft Defender tools and services that provide security across various platforms and environments
Hello @Michael O'Brien
The 0/120 assigned count does not necessarily mean that the devices are unlicensed. Standard group-based licensing in the Microsoft 365 admin center applies licenses to user members of a group, so a group containing only device objects can remain at zero. Microsoft documents direct device-group licensing for Microsoft 365 Apps, but there is no equivalent published assignment process for Defender for Endpoint device license
Since the devices are already onboarded through the Intune EDR policy and appear in the Microsoft Defender portal, no additional activation should be required on each endpoint.
Mixed mode is not relevant in this case. It is intended for tenants that own both Defender for Endpoint Plan 1 and Plan 2 and need to control which devices receive each plan’s capabilities. Device tags used in mixed mode do not assign the purchased Defender Endpoint P2 Device licenses
The device-based subscription should therefore be treated as a licensing entitlement: the organization must maintain enough licenses to cover the shared devices using Defender for Endpoint. The 0 assigned value is not an indication that onboarding failed.
Because Microsoft’s public documentation does not clearly explain the administration of this specific device-based SKU, it would also be advisable to confirm the entitlement and counting method with the Microsoft licensing provider or account representative.