Forum Discussion
SteBeSec
Oct 19, 2020Iron Contributor
ATP onboarding - only possible after interactive login?
Hello everybody, we are currently deploying MDATP through SCCM and found something out that is, at least for me, quite shocking: The onboarding is only processed correctly, after an user is s...
Jlouden91
Oct 22, 2020Copper Contributor
SteBeSec I recently just requested that they update the doc's to reflect this missing step.
In a troubleshooting article (https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/troubleshoot-onboarding) there is a section that hints you need to log on with the following
"Sensor does not start because the Out-of-box experience (OOBE) or first user logon has not been completed"
There is a section below that has a very interesting way of dealing with that creating a package that will force a service to start and update the registery to get past this limitation. this might worth for you..but from a Intune\MEM point of view it doesn't help.
SteBeSec
Oct 22, 2020Iron Contributor
Hi Jlouden,
I know this article, but unfortunately that is not the case in our situation.
The Sense Service is running and onboardinginformation is present on affected machines, but the on boarding is still not performed.
You have to login to a machine, to start the onboardingprocess.
I know this article, but unfortunately that is not the case in our situation.
The Sense Service is running and onboardinginformation is present on affected machines, but the on boarding is still not performed.
You have to login to a machine, to start the onboardingprocess.