Forum Discussion

Afsar_Shariff's avatar
Afsar_Shariff
Brass Contributor
Aug 03, 2026

Purview Endpoint DLP "Turn on Device onboarding" Query

Hello Microsoft Community,

We are planning to enable device onboarding in Microsoft Purview as a prerequisite for deploying Microsoft Purview Endpoint DLP.

Our environment uses CrowdStrike Falcon as the primary antivirus/EDR solution. However, we have identified a significant number of Windows 11 devices where Microsoft Defender Antivirus is currently reporting: AMRunningMode : Normal

This is occurring even though CrowdStrike is installed and is expected to be the primary antivirus provider. Our understanding is that, when a supported third-party antivirus such as CrowdStrike is correctly registered with Windows Security Center, Microsoft Defender Antivirus should normally operate in Passive mode after the device is onboarded to Microsoft Defender for Endpoint.

We are investigating why these devices are showing Normal mode. One suspicion is that there may have been an incomplete or unsuccessful Microsoft Defender for Endpoint deployment in the past, or an issue with CrowdStrike registration, Windows Security Center, Defender policies, or the existing MDE onboarding state.

We would like clarification on the impact of enabling Purview device onboarding in this situation.

Environment

  • Windows 11 devices
    CrowdStrike Falcon is intended to be the primary antivirus/EDR
    Microsoft Purview Endpoint DLP is planned
    Device onboarding has not yet been broadly enabled through Purview
    Some devices report Microsoft Defender Antivirus in Passive mode
    Large number of devices report Microsoft Defender Antivirus in Normal mode
    We are separately troubleshooting the Normal-mode devices

Questions

  • Does enabling Turn on device onboarding in the Microsoft Purview portal make any immediate configuration change to Windows devices, or is it only a tenant-side setting until the onboarding package is deployed?
  • After “Turn on device onboarding” When the Purview onboarding package/script is deployed when the device is in “Normal mode”, does it modify the Microsoft Defender Antivirus operating mode?
  • Is there any risk of performance degradation, duplicate file scanning, application impact, or antivirus conflict on devices where:
    • CrowdStrike is active, and
    • Microsoft Defender Antivirus is also reporting Normal mode? If we enable device onboarding?

We are mainly trying to determine whether Purview device onboarding itself introduces any negative impact, as there is a pre-existing condition where both CrowdStrike and Microsoft Defender Antivirus may be operating actively.

Thank you.

1 Reply

  • KnutPetter's avatar
    KnutPetter
    Tin Contributor

    Short version, and it inverts the premise a little: device onboarding is not what puts you at risk here. It is one of the five documented conditions that must be true before Microsoft Defender Antivirus can enter passive mode at all, and it is the one you are currently missing across most of the estate. That is the likeliest reason those devices report Normal.

     

    QUESTION 1, DOES THE TOGGLE CHANGE ANYTHING ON DEVICES

     

    No. ✅

    Turn on device onboarding is a tenant side setting. It enables the capability and the device list. Nothing reaches a device until an onboarding package or script is deployed through Intune, Configuration Manager, Group Policy or a local script.

     

    One thing worth knowing: onboarding is shared between Purview and Defender for Endpoint. Any device already onboarded to MDE appears in the Purview managed devices list immediately and needs no further onboarding. The reverse also holds, onboarding a device from the Purview portal also onboards it into MDE. So if an earlier MDE deployment partially succeeded, those devices are already onboarded for DLP purposes whether or not that was intended.

     

    https://learn.microsoft.com/purview/device-onboarding-overview 

     

    QUESTION 2, DOES ONBOARDING CHANGE THE ANTIVIRUS MODE

     

    Not directly, but it removes the blocker. Microsoft documents five conditions that must all be true for Defender Antivirus to run in passive mode.✅

     

    Windows 10 or newer. Defender Antivirus installed. A non-Microsoft antivirus installed and used as the primary solution. The endpoint onboarded to Defender for Endpoint. The Windows Security Center Service enabled.

     

    Onboarding is the fourth of those. On a device where CrowdStrike is correctly registered with Windows Security Center and the rest is in place, onboarding is precisely what allows Defender Antivirus to drop into passive mode. It does not force the mode, it satisfies a prerequisite.

     

    https://learn.microsoft.com/defender-endpoint/microsoft-defender-antivirus-compatibility 

     

    THE DIAGNOSTIC I WOULD RUN BEFORE ANYTHING ELSE

     

    You mention that some devices report Passive and a large number report Normal, and separately that onboarding has not been broadly enabled yet. Those two facts probably explain each other.

     

    Correlate AMRunningMode against onboarding state rather than treating Normal mode as a separate fault. If the Passive devices turn out to be exactly those onboarded by the earlier partial MDE deployment, and the Normal devices are exactly those that were never onboarded, then there is no broken CrowdStrike registration to chase. There is an unfinished onboarding, and completing it resolves the mode.

     

    If you instead find devices that are onboarded and still report Normal, that is a real finding, and the first thing to check is the Windows Security Center Service. The documentation is blunt about it: if that service is disabled on a Windows client, Defender Antivirus cannot detect the non-Microsoft antivirus installation and stays Active.

     

    QUESTION 3, RISK OF CONFLICT AND PERFORMANCE

     

    Worth being precise about the direction. Microsoft describes two antivirus products both providing active protection as a state that impacts performance and is not supported. That is your situation today, before onboarding. Onboarding is the documented route out of it, not into it.✅

     

    The risk of doing nothing is therefore higher than the risk of proceeding. I would still stage it. Onboard a ring, capture AMRunningMode before and after, confirm the devices move to Passive, and only then widen.

     

    ONE SIDE EFFECT THAT IS EASY TO MISS

     

    Once a device is onboarded, file activity flows into Activity Explorer before you configure or deploy a single DLP policy. Always audit file activity for devices is on by default, covering file created, modified, renamed, created on removable media and created on network share.

     

    That is useful for baselining, and it is also a data collection change that begins the moment onboarding lands. If you have employee representatives, a privacy sign off or an internal process for monitoring changes, have that settled before the first ring goes out rather than after.

     

    https://learn.microsoft.com/purview/dlp-configure-endpoint-settings