SOLVED

Defender for Endpoint Offboarding Windows 10 Device

Copper Contributor

Hi

I had my Windows PC onboarded to trial of MS 365 Business Premium (done using script). It has never been offboarded. After the trial I started using another paid subscription MS 365 Business Premium and when trying to onboard my Windows 10 PC to a new subscription with a script it keeps saying "The Microsoft Defender for Endpoint Service is already running!"

What's the easiest way to offboard device (I've already tried offboarding script but there was error saying " Machine is onboarded to a different org.")? I don't have any details of previous trial tenant.

 

Thank you

3 Replies
best response confirmed by MichaelSolt (Copper Contributor)
Solution

@MichaelSolt 

The easiest way is to look in the following registry key on the machine:

HKLM:\Software\Microsoft\Windows Advanced Threat Protection\Status

and examine the value of the key:

OnboardingState

 

if the value is 1 change it to 0 reboot your device and try to onboarding it again to the new the MDE org

@eliekarkafy thanks for your response!

Yes. it shows 1 as OnboardingState. 

Unfortunatelly struggling to change it to 0. Keeps showing error message access denied. 

I’m logged in as admin. Any idea how to resolve it? Many thanks

backup the registry key and try to delete it.
1 best response

Accepted Solutions
best response confirmed by MichaelSolt (Copper Contributor)
Solution

@MichaelSolt 

The easiest way is to look in the following registry key on the machine:

HKLM:\Software\Microsoft\Windows Advanced Threat Protection\Status

and examine the value of the key:

OnboardingState

 

if the value is 1 change it to 0 reboot your device and try to onboarding it again to the new the MDE org

View solution in original post