Trying to Enroll Devices from Intune into Defender, But It's Not Working

Johnny Lechnir 0 Reputation points
2026-09-11T22:41:43.3733333+00:00

We are setting up environments for several clients, and a consistent issue we are running into is enrolling devices already enrolled in Intune with Defender. Enrolling devices into Intune is commonplace, and we've done it for everyone, but doing so for Defender has proven to be extremely difficult. We have connected Intune to Defender, proven the connection from Intune's Endpoint Security status, enabled enrollment options for every type of device, and even deployed policies for EDR, both custom and pre-configured. Yet nothing is getting enrolled for any device, despite syncing, updates, or otherwise.

We have seen the enrollment option for installing a package from Defender manually onto the computer, but it doesn't seem like the correct method or a necessary one. There shouldn't be any reason this can't be done through the M365 environment itself, not to mention doing it manually is extremely problematic, especially for clients with hundreds of devices. Getting them enrolled this way is neither feasible nor practical.

What issue are we encountering, or what process/configuration are we missing in order to connect these devices to Intune? We want to monitor these devices within Defender, as is its purpose, but we cannot bridge the connection. We need assistance with this process, as we cannot find any more information related to this that does not already cover the settings/configurations we've tried so far.

If there is any aid you can provide in solving this problem, it would be greatly appreciated.

Microsoft Security | Microsoft Defender | Other
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-09-11T22:42:03.09+00:00

    For Intune-enrolled devices, the missing step is typically onboarding the devices to Microsoft Defender for Endpoint. Connecting Intune to Defender and deploying EDR-related policies does not by itself onboard devices into Defender.

    The supported flow for Intune-enrolled devices is:

    1. Establish the Intune–Defender service-to-service connection.
    2. Onboard devices to Microsoft Defender for Endpoint using Intune policy.
    3. Create a device compliance policy to set acceptable device risk.
    4. Configure Conditional Access if access control based on risk is required.

    If the goal is to see already Intune-enrolled devices in Defender, focus on step 2: Onboard devices with Microsoft Defender for Endpoint using Intune policy. Without onboarding, devices will not appear in Defender for monitoring.

    A separate path exists for devices that are not enrolled in Intune: use security management for Microsoft Defender for Endpoint. In that model:

    • Devices onboard to Microsoft Defender for Endpoint first.
    • Devices then communicate with Intune to receive endpoint security policies.
    • In the Microsoft Defender portal, Managed by should show MDE.
    • In the Intune admin center All devices page, Managed by should also show MDE.
    • MDE Enrollment status should display Success.

    For tenant configuration of Defender security settings management, in the Microsoft Defender portal go to: Settings > Endpoints > Configuration Management > Enforcement Scope

    For initial validation, Microsoft recommends:

    • enabling platforms for security settings management,
    • starting with On tagged devices,
    • tagging test devices with MDE-Management,
    • then validating enrollment.

    Expected timing:

    • Most devices complete enrollment and apply assigned policy within a few minutes.
    • Some devices can take up to 24 hours.

    Validation points:

    • In the Microsoft Defender portal device inventory, Managed by should be MDE.
    • On the device page or side panel, MDE Enrollment status should be Success.
    • In Intune admin center > All devices, Managed by should display MDE.

    If MDE Enrollment status is not Success, confirm the device is:

    • updated, and
    • in scope for security settings management based on the configured Enforcement Scope.

    Also note that security settings management now supports devices that do not fully register in Microsoft Entra by using synthetic registration. Those devices can still onboard to Defender and receive security settings management policies.

    So the key distinction is:

    • Intune-enrolled devices: onboard them to Defender using Intune policy.
    • Unenrolled devices: use Defender for Endpoint security settings management.

    If the current deployment only enabled the connector, EDR settings, and syncs, but did not deploy the actual Defender for Endpoint onboarding policy, that explains why no devices are appearing in Defender.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.