Forum Discussion
Device* tables missing from Advanced Hunting schema despite M365 E5 license
We have an M365 E5 trial (with Microsoft Defender for Endpoint service plan enabled) and a standalone Defender for Cloud Apps trial on the same tenant. Two devices are onboarded and show as Active in Device Inventory. one Windows 11 VM hosted on mac m4 and one Windows Server 2019 Azure VM.
The issue: the entire Devices section is missing from the Advanced Hunting schema. No DeviceInfo, DeviceNetworkEvents, DeviceEvents, DeviceProcessEvents, etc. The schema only shows Alerts & behaviors, Apps & identities, Email & collaboration, Defender Vulnerability Management, and Exposure Management.
Additionally:
- The device Timeline tab does not appear on device pages (not in visible tabs or overflow menu)
- "Go hunt" from a device page only generates a query against IdentityLogonEvents, not any Device* tables
- Settings → Microsoft Defender XDR does not show an "Advanced hunting" option for managing data sources
- The MDE Client Analyzer on the Azure VM passes all EDR cloud connectivity checks (CnC, Cyber, AutoIR, SampleUpload, MdeConfigMgr all Succeeded 200)
- Settings → Endpoints → Optional features loads with all toggles including the Defender for Cloud Apps integration
- Cloud Discovery via MDA works (discovered apps visible on the device page)
- The Tenant ID and Org ID shown in XDR settings are different values
The tenant originally had only the Defender for Cloud Apps standalone trial. The E5 trial was added afterward. It appears the MDE data source was never deployed/activated in Defender XDR despite the license and onboarding being in place.
I've opened a support case but wanted to ask here as well, has anyone resolved this issue? I've found several older posts describing the same problem but none with a confirmed fix.
Any guidance would be appreciated.