Forum Discussion
On-prem, Server2022, onboarded via GPO, not visible in Portal..?
Check the DigiCert Cloud Services CA-1 certificate is present in the Trusted Root Certification Authorities.
Verify network connectivity and disable TLS inspection for MDE URLs.
Re-onboard the device by offboarding and re-onboarding via GPO or script.
Switch to streamlined connectivity mode if possible:
Configure the server to use cloud-delivered protection if not already configured. This can be done by setting the Defender CSP (Configuration Service Provider) policies or by using PowerShell.
Set-MpPreference -CloudBlockLevel High
Set-MpPreference -SubmitSamplesConsent 2
Set-MpPreference -MAPSReporting Advanced
Run MDE diagnostics using MPCmdRun and review logs in C:\ProgramData\Microsoft\Windows Defender
Advanced Threat Protection:
Check the MDE logs located at C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\ for any specific errors or indications of issues with the service registration or connectivity. Key files to review include: SenseLogs: These logs capture data about the device’s registration and communication with the MDE cloud service.
EventsLogs: Look for any errors or warnings that could hint at connectivity or configuration issues.
Ensure the latest updates are installed on Windows Server 2022.