Onboarding Detection Test not working

%3CLINGO-SUB%20id%3D%22lingo-sub-728051%22%20slang%3D%22en-US%22%3EOnboarding%20Detection%20Test%20not%20working%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-728051%22%20slang%3D%22en-US%22%3E%3CP%3EWe're%20trying%20to%20complete%20the%20onboarding%20detection%20test%20in%20order%20to%20evaluate%20ATP.%20However%2C%20using%20the%20detection%20script%20provided%20on%20the%20portal%20or%20in%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fmicrosoft-defender-atp%2Frun-detection-test%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Edocumentation%3C%2FA%3E%20does%20not%20work.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20seems%20the%20issue%20is%20that%20there%20is%20no%20reply%20from%20%3CA%20href%3D%22http%3A%2F%2F127.0.0.1%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2F127.0.0.1%3C%2FA%3E%2C%20so%20the%20script%20can't%20download%20the%20'1.exe'%20file.%3C%2FP%3E%3CP%3EAs%20far%20as%20we%20can%20tell%20the%20agent%20itself%20is%20working%20fine%2C%20the%20device%20shows%20up%20in%20the%20portal%2C%20we%20can%20detect%20an%20EICAR%20file%20(which%20is%20reported%20in%20the%20portal)%20and%20toggling%20restrictions%20or%20isolation%20works%20as%20well.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENot%20that%20big%20of%20a%20deal%20but%20it%20would%20be%20nice%20to%20get%20rid%20of%20the%20onboarding%20reminder%20on%20the%20dashboard.%20Is%20there%20an%20alternate%20source%20we%20can%20get%20the%20referenced%20'1.exe'%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

We're trying to complete the onboarding detection test in order to evaluate ATP. However, using the detection script provided on the portal or in the documentation does not work.

 

It seems the issue is that there is no reply from http://127.0.0.1, so the script can't download the '1.exe' file.

As far as we can tell the agent itself is working fine, the device shows up in the portal, we can detect an EICAR file (which is reported in the portal) and toggling restrictions or isolation works as well.

 

Not that big of a deal but it would be nice to get rid of the onboarding reminder on the dashboard. Is there an alternate source we can get the referenced '1.exe'?

0 Replies