Forum Discussion
Purview Endpoint DLP "Turn on Device onboarding" Query
Short version, and it inverts the premise a little: device onboarding is not what puts you at risk here. It is one of the five documented conditions that must be true before Microsoft Defender Antivirus can enter passive mode at all, and it is the one you are currently missing across most of the estate. That is the likeliest reason those devices report Normal.
QUESTION 1, DOES THE TOGGLE CHANGE ANYTHING ON DEVICES
No. ✅
Turn on device onboarding is a tenant side setting. It enables the capability and the device list. Nothing reaches a device until an onboarding package or script is deployed through Intune, Configuration Manager, Group Policy or a local script.
One thing worth knowing: onboarding is shared between Purview and Defender for Endpoint. Any device already onboarded to MDE appears in the Purview managed devices list immediately and needs no further onboarding. The reverse also holds, onboarding a device from the Purview portal also onboards it into MDE. So if an earlier MDE deployment partially succeeded, those devices are already onboarded for DLP purposes whether or not that was intended.
https://learn.microsoft.com/purview/device-onboarding-overview
QUESTION 2, DOES ONBOARDING CHANGE THE ANTIVIRUS MODE
Not directly, but it removes the blocker. Microsoft documents five conditions that must all be true for Defender Antivirus to run in passive mode.✅
Windows 10 or newer. Defender Antivirus installed. A non-Microsoft antivirus installed and used as the primary solution. The endpoint onboarded to Defender for Endpoint. The Windows Security Center Service enabled.
Onboarding is the fourth of those. On a device where CrowdStrike is correctly registered with Windows Security Center and the rest is in place, onboarding is precisely what allows Defender Antivirus to drop into passive mode. It does not force the mode, it satisfies a prerequisite.
https://learn.microsoft.com/defender-endpoint/microsoft-defender-antivirus-compatibility
THE DIAGNOSTIC I WOULD RUN BEFORE ANYTHING ELSE
You mention that some devices report Passive and a large number report Normal, and separately that onboarding has not been broadly enabled yet. Those two facts probably explain each other.
Correlate AMRunningMode against onboarding state rather than treating Normal mode as a separate fault. If the Passive devices turn out to be exactly those onboarded by the earlier partial MDE deployment, and the Normal devices are exactly those that were never onboarded, then there is no broken CrowdStrike registration to chase. There is an unfinished onboarding, and completing it resolves the mode.
If you instead find devices that are onboarded and still report Normal, that is a real finding, and the first thing to check is the Windows Security Center Service. The documentation is blunt about it: if that service is disabled on a Windows client, Defender Antivirus cannot detect the non-Microsoft antivirus installation and stays Active.
QUESTION 3, RISK OF CONFLICT AND PERFORMANCE
Worth being precise about the direction. Microsoft describes two antivirus products both providing active protection as a state that impacts performance and is not supported. That is your situation today, before onboarding. Onboarding is the documented route out of it, not into it.✅
The risk of doing nothing is therefore higher than the risk of proceeding. I would still stage it. Onboard a ring, capture AMRunningMode before and after, confirm the devices move to Passive, and only then widen.
ONE SIDE EFFECT THAT IS EASY TO MISS
Once a device is onboarded, file activity flows into Activity Explorer before you configure or deploy a single DLP policy. Always audit file activity for devices is on by default, covering file created, modified, renamed, created on removable media and created on network share.
That is useful for baselining, and it is also a data collection change that begins the moment onboarding lands. If you have employee representatives, a privacy sign off or an internal process for monitoring changes, have that settled before the first ring goes out rather than after.
https://learn.microsoft.com/purview/dlp-configure-endpoint-settings