← What we check

Onboard devices to Defender

DevicesHigh severityNeeds Intune

Corporate Windows devices should be covered by Defender for Endpoint/Business (EDR, not just signature AV) with tamper protection enabled so malware can't switch Defender off. This reports the tenant's Defender licensing capability and per-device tamper-protection state — the signals readable via Microsoft Graph. (Per-device MDE onboarding status isn't exposed by Graph; it lives in the Defender portal's machines API.)

A scan reports where your tenant stands on this check — pass, fail with a step-by-step fix, or not applicable if your licensing doesn’t include the feature. When Tenant Strike can’t read a setting with read-only access, it says unverified and gives you a one-command way to confirm it yourself — it never guesses.

Check your own tenant

Is your tenant covered on "onboard devices to defender"?

One read-only scan answers it — this check and every other one in the catalog, each with a plain-English fix. 7-day Pro trial, no credit card.