Forum Discussion

KrunalPatel1's avatar
KrunalPatel1
Copper Contributor
Jun 15, 2025

Defender Onboarding

I have domain joined device. 

Implementing Defender thru Intune Connector. (Connector Status is on - EDR policy is Deployed correctly)

-ASR All Rules in place

-AV policy in place

2 Same OS Version Device I tried to Onboard 1 got onboarded & 1 Did not. Not sure why?

Also Domain joined 1 Device got on boarded with some issue where Realtime Protection and Behavior monitoring is disabled.

Any Solution ? 

Please Don't Recommend to make any changes to GPO thru Onprem. Help me to resolve issue thru intune.

 

2 Replies

  • One device may have failed to onboard due to a sync issue or delay in policy application try a manual Intune sync. For the one with Realtime Protection and Behavior Monitoring off, check if those settings are explicitly enabled in your Intune AV policy, and confirm no other AV is interfering. Use Get-MpComputerStatus to verify Defender status.

    • KrunalPatel1's avatar
      KrunalPatel1
      Copper Contributor

      it is onboarded appropriately. it was due to other AV in place. 

       

Resources