From a total of 17 servers, only one onboarded without intervention, and this set is just for the testing phase.
The documentation is not good and there is no good troubleshooting support too.
Deploy ATP to Windows server 2016 1607

Belan Marek
51
Reputation points
Hi all
i folow this guide https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/defender-advanced-threat-protection
Download package, get key and ID, put to MECM and deploy to servers.
We have SCOM 2019 UR2 on all servers.
On log file i find :
WorkspaceId does not match the expected value.
ATPHandler: Mma Agent is not onboarded to the intended Workspace. The device needs to be offboarded before onboarding to a different Workspace.
When I put id and key to SCOM agent it connect and work:
{count} votes
1 answer
Sort by: Most helpful
-
SIMOS George 1 Reputation point
2020-11-03T16:09:46.067+00:00
I have exactly the same problem, it seems to me that the implementation in SCCM is half-baked.
I will report it via the "send a smile/frown" option and will open a support case also at Microsoft.
The error is ridiculously vague.