Offboard a device

Is it possible to somehow obtain from the endpoint itself the information to which MDE tenant it was onboarded to? And additionally, if the MDE tenant no longer exists or the device was part of the PoC and remained onboarded to the test/demo MDE tenant, can it be off-boarded or at least re-onboarded to a different tenant without first offboarding it using the official offboard script?


Contact the Microsoft Support. They will get some logs from you and will provide you an offboarding script.
I had a customer with the same issue, because he tested Defender ATP with a demotenant and the devices could not be offboarded and the demotenant was already deleted.


To answer your first question, you would need to query the following registry key using a tool such as SCCM's CMPivot to query the registry string value "OnboardedInfo" (image below). This will show the OrgID. For offboarding, as noted above -- If you don’t have an offboarding package then you will need to open a Microsoft CSS Security -MDE support case to get it.