Where does MECM console list unhealthy Defender for Endpoint clients (2)

uMarko 2 31 Reputation points
2022-03-18T15:12:17.903+00:00

I am planning the deployment of Defender for Endpoint Plan 1 clients across our enterprise. I would prefer using MECM, because we don’t have our Win10 endpoints enrolled in InTune. We need to manage the clients after they are deployed.

The article https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/defender-advanced-threat-protection#monitor says that to Monitor clients using MECM, go to the dashboard at Monitoring > Security > Microsoft Defender ATP Status. At that page I see a piechart for Microsoft Defender ATP Agent Health, which shows percentage of clients that are Healthy, Inactive, Agent stopped, or Not onboarded. See attached << MECM-ATPagentHealthDashboard.png>>.

184549-mecm-atpagenthealthdashboard.png

But when I click on any pie slice, it does not give a listing of the clients. How do I get such listings in MECM console?

If I am forced to use Intune, I can get such listings at Endpoint Manager admin center’s Microsoft Defender Antivirus Agent Status report, which has client health columns for MDE Sense Running State and MDE Onboarding Status. See attached << EndpointMgrShowsMDEsenseRunningState.PNG>>. I am hoping that MECM can give me the equivalent.

197474-endpointmgrshowsmdesenserunningstate.png

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,754 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. Simon Ren-MSFT 30,116 Reputation points Microsoft Vendor
    2022-03-25T03:02:53.093+00:00

    Hi,

    Thanks very much for your feedback and sharing. Here's a short summary for the problem, hope it could help other users to search for useful information more quickly.

    Problem/Symptom:
    Where in the MECM console can we get a list of unheathy Defender for Endpoint clients?

    Solution/Workaround:
    Unlike Intune, MECM does not list unhealthy Defender for Endpoint clients right now.

    Thanks again for your time! Have a nice day!

    Best regards,
    Simon


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. uMarko 2 31 Reputation points
    2022-03-24T14:33:16.64+00:00

    The answer is No, unlike InTune, MECM does not list unhealthy Defender for Endpoint clients. This according to Sani Sheikh of Microsoft.

    1 person found this answer helpful.
    0 comments No comments

  2. Simon Ren-MSFT 30,116 Reputation points Microsoft Vendor
    2022-03-23T10:53:12.55+00:00

    Hi,

    Thanks for posting in Microsoft MECM Q&A forum.

    1,Have you ever successfully onboarded the devices by providing the configuration file, Workspace key, and Workspace ID to Configuration Manager?

    2,If the onboarding completed successfully but the devices are not showing up in the Devices list after an hour in Configuration Manager, please refer to official article to check if an error occurred with the Microsoft Defender for Endpoint agent:
    Troubleshoot onboarding issues on the device

    Best regards,
    Simon


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.