Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →You can create endpoint security policies in the Microsoft Defender portal and use Windows SENSE and MDM logs to diagnose why a targeted device has not applied one. The key is to separate assignment, eligibility, delivery, local processing, and effective configuration: a policy shown as assigned is not necessarily active on the endpoint.
This guide is for Windows devices managed through Microsoft Defender for Endpoint (MDE) security settings management. The portal interface has changed since the 2023 walkthrough by HTMD; use Microsoft’s current policy workflow and treat specific event IDs as examples, not universal definitions.
What Defender for Endpoint security settings management does
Security settings management extends Intune endpoint security policy delivery to supported devices that are onboarded to MDE but are not enrolled in Intune. Policies can be authored in Intune or the Defender portal, target Microsoft Entra device objects, and be enforced by Defender components on eligible devices. Policy status is reported to the management portals. It is not a substitute for full Intune enrollment and its broader device-management capabilities. See Microsoft’s security settings management documentation.
Distinguish the management path before troubleshooting:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Intune-enrolled device: Use the normal Intune policy deployment path. It does not process the same policy through the MDE security settings management path.
- MDE security-settings-managed device: The device is onboarded to MDE but not enrolled in Intune; it can receive supported security settings policies through this feature.
The Defender portal can provide a shared authoring experience for supported policies, but not every Intune feature or policy type is available there. Microsoft identifies Device Control policies in this portal experience as applying only to Intune-enrolled devices. Review Microsoft’s policy-management guidance for current template and platform limitations.
Check prerequisites and device eligibility first
Work through these checks before creating a replacement policy or interpreting a local event.
- Licensing and integration: Confirm the tenant has a subscription granting MDE access, at least one appropriate MDE user subscription, and configured Intune–Defender communication. Microsoft says Defender for Servers alone is not sufficient for this scenario. See the Microsoft prerequisites.
- Onboarding: Confirm that the endpoint is onboarded to MDE and that its device record is current.
- Enforcement scope: In Defender portal settings, find the endpoint configuration-management setting for Enforcement scope. If the older menu path is absent, search portal settings for that label. Microsoft recommends beginning with tagged devices for a controlled test.
- Permissions: The documented access paths include Defender XDR Unified RBAC permission to manage core security settings, the Intune Endpoint Security Manager role, or appropriate Entra roles such as Security Administrator or Intune Administrator. A role scoped only to selected device groups may not expose the full policy page. Prefer least privilege to Global Administrator. See Microsoft’s role guidance.
- Supported device: Check the operating system, architecture, virtualization type, policy profile, and setting. Microsoft lists exclusions including non-persistent desktops, Azure Virtual Desktop clients, 32-bit Windows, and Windows Server Core 2016 or earlier for this scenario. Supported profiles vary by platform.
- Correct target type: Assign to a Microsoft Entra device group. User targeting and assignment filters are not supported for devices managed through this feature.
Create a policy in the Defender portal
Microsoft’s current documented workflow uses the Endpoint security policies page. Portal menus can vary during rollouts; an older route shown in the 2023 HTMD article was Endpoints → Configuration management → Endpoint security policies.
- Sign in to the Microsoft Defender portal and open Endpoint security policies.
- Select Create new policy.
- Choose a platform: Windows, macOS, or Linux.
- Choose a policy template, then select Create policy.
- On Basics, enter a unique name and, optionally, a description.
- Configure the settings required by the selected template.
- On Assignments, select the intended Entra device group.
- Review the configuration and select Save or Create, according to the current portal prompt.
For a first test, use a narrow pilot rather than a broad production assignment. Choose one observable setting, avoid overlapping controls or exclusions, and record the policy name, target device, OS version, assignment time, and expected local value. For example, a name such as MDE-Test-AV-NetworkProtection-2026-08 makes the scope and purpose clear. Do not assume every profile or setting is supported on every listed platform.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Verify assignment and device targeting
Security settings management depends on device identity and scope. Confirm all of the following before diagnosing a CSP failure:
- The assignment uses a device group, not a similarly named user group.
- The endpoint’s current Entra device object is a member of the assigned group. For a dynamic group, verify the device satisfies the membership rule.
- The MDE device record corresponds to that Entra object; investigate duplicate or stale device records.
- Include and exclude assignments do not cancel each other.
- The device is within the configured enforcement scope and has not been excluded.
Assignment filters are not supported for devices managed through security settings management. If a device is already Intune-enrolled, troubleshoot its ordinary Intune policy assignment instead.
Read portal status as one layer of evidence
Policy reporting is asynchronous. An immediate status after assignment is not conclusive, and Microsoft does not promise a fixed processing interval. HTMD described an approximately 10-minute manual-sync observation in its example; that is not a service guarantee. Check device check-in and fresh endpoint events before deciding that a delay is a failure.
| Status or message | What it can indicate | Next evidence to collect |
|---|---|---|
| Pending or no result | Processing or reporting has not completed, or the device has not reported back. | Check onboarding, group scope, recent SENSE activity, connectivity, and check-in. |
| Succeeded | The reporting layer accepted the policy or setting. | Confirm the effective local value and check for competing management sources. |
| Failed | A payload or setting may not have processed. | Correlate SENSE/SenseCM and MDM/CSP errors; check setting support, value format, and conflicts. |
| Not applicable | The device or setting may not meet applicability conditions. | Check enrollment path, OS and architecture, group membership, enforcement scope, and profile support. |
| No policies have been applied | This may be a transient state after assignment or indicate no eligible policy reached the device. | Verify onboarding, integration, assignment, eligibility, and sync timing before treating it as failure. |
The “No policies have been applied” message is not automatically an error; the historical HTMD troubleshooting video describes it as occurring before policy processing completes for some MDE-managed devices.
Recommended Free Tools
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Inspect Windows SENSE and MDM event logs
Start with SENSE
On the endpoint, open Event Viewer and expand Applications and Services Logs → Microsoft → Windows → SENSE → Operational. Depending on Windows build and provider presentation, relevant entries may appear under SENSE-related nodes or providers such as Microsoft-Windows-SENSE and SenseCM. The exact tree is not identical on every build. Filter or inspect events around the recorded assignment and check-in times.
Correlate MDM/CSP processing
Also inspect Applications and Services Logs → Microsoft → Windows → DeviceManagement-Enterprise-Diagnostics-Provider. SENSE activity can show that processing was attempted; MDM/CSP diagnostic events can help show whether a setting was accepted or rejected. A failure here is different from a device never receiving an eligible policy.
Build a timestamped evidence trail
For each test, record the assignment time, device check-in time, SENSE event time, any SenseCM error, MDM/CSP diagnostic errors, portal status, and actual local setting. Compare events from the same interval rather than relying on an old warning or a single portal snapshot.
Validate the effective Defender Antivirus configuration
Microsoft documents Get-MpPreference as a local way to inspect Microsoft Defender Antivirus preferences:
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Get-MpPreference
For a focused view, use:
Get-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, DisableIOAVProtection, EnableNetworkProtection, ExclusionPath, ExclusionExtension, ExclusionProcess
Property names and availability can vary with Windows version and Defender configuration. This output is evidence of effective Defender Antivirus configuration; it does not identify which policy source supplied each value. If portal status says succeeded but the expected value is absent, verify that you are checking the setting represented by the profile and investigate other management sources.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot by symptom, not by recreating the policy
The policy cannot be created
- Check Defender XDR or Intune RBAC and whether the role is scoped too narrowly.
- Confirm the template is available for the selected platform and that the tenant meets the required capability prerequisites.
- Use the current Endpoint security policies page and consult Microsoft’s workflow and permission documentation.
The policy exists, but the device is absent
- Verify onboarding and device identity, including duplicate or stale records.
- Check Entra device-group membership, include/exclude scope, and enforcement scope.
- Check OS, architecture, virtualization type, and profile support against the Microsoft eligibility requirements.
The device is targeted but says “Not applicable”
Start with applicability rather than setting-level logs: confirm device-group targeting, whether the device is already Intune-enrolled, supported OS and architecture, policy profile support, enforcement scope, and complete onboarding. Mixing a server workflow with a client workflow can also mislead; use platform-specific guidance.
The device remains pending
Check recent SENSE activity, Defender onboarding state, connectivity to Microsoft services, accepted sync activity, and whether the device is online. An offline, sleeping, or connectivity-restricted device may not check in promptly. Do not treat a reported approximate delay as a guaranteed deadline.
The policy succeeds but the setting appears unchanged
- Check the effective value with
Get-MpPreferenceand confirm it is the correct property for the policy setting. - Check whether Group Policy, Configuration Manager, Intune profiles, security baselines, local policy, or another Defender configuration mechanism also manages it.
- Review whether tamper protection or another security control affects the setting, and whether the setting requires a later policy cycle or service refresh.
- Separate policy acceptance from effective enforcement: one does not by itself prove the other.
An exclusion setting fails
Validate the exclusion value and format, avoid empty or malformed extension values, and confirm the setting is supported by the selected platform and profile. Check for an existing exclusion policy from Group Policy, Intune, Configuration Manager, or a security baseline. Inspect SENSE/SenseCM and MDM/CSP evidence together; a policy can apply one control while a separate exclusion setting fails.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Interpret event IDs cautiously
The 2023 HTMD article records examples, not an official universal event-ID map. It describes Event ID 60 with a failure to run endpointconfigmanagementcheckincommand and error 0xFFFFFFFF80072713, and Event ID 2001 examples involving a WindowsSecurityExperience.psm1 warning or SenseCM: AV::VerifyAssignment failure for ExcludedExtensions. These messages may depend on Windows build, Defender client version, provider, policy type, and deployment architecture. Event ID 60 alone does not prove policy failure, and Event ID 2001 alone does not establish that a setting is unsupported.
There is no single event ID that universally proves a policy was received, applied, and is effective. Confirm the chain with four kinds of evidence: portal scope/status, recent SENSE processing, MDM/CSP acceptance or rejection, and the effective local configuration.
Keep client, server, and platform workflows distinct
Microsoft documents applicability across Windows client, Windows Server, Linux, and macOS, but supported profiles and exclusions differ. Do not apply a Windows client event interpretation to a server deployment without checking server-specific guidance. The HTMD troubleshooting follow-up also emphasizes that server management can follow a different operating model. Devices such as non-persistent VDI, Azure Virtual Desktop clients, 32-bit Windows, and older Windows Server Core releases are among the exclusions documented for this scenario; verify current applicability before targeting a broader estate.
For MDE onboarding through Intune, see Microsoft’s endpoint onboarding guidance. For Defender Antivirus policy context, see Microsoft’s Defender Antivirus policy example.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchChoose the right management path
| Approach | Best fit | Important trade-off |
|---|---|---|
| Defender portal policy management | Security teams wanting a direct Defender authoring experience, including supported policies for Intune-enrolled and MDE security-settings-managed devices. | Not all Intune policy features are exposed; scope tags require policy creation in Intune; RBAC and platform applicability still matter. |
| Intune endpoint security policies | Fully Intune-enrolled devices and administrators who need Intune’s broader administration features. | Do not expect an Intune-enrolled device to process through the MDE-only security settings management path. |
| Group Policy or Configuration Manager | Established domain or Configuration Manager estates that retain those control planes. | Multiple management sources can conflict or obscure which source governs the effective value. |
| Full Intune enrollment | Organizations needing application, compliance, configuration, update, and endpoint-security management as broader MDM capabilities. | Requires a wider device-management commitment than MDE onboarding alone. |
For general Intune endpoint-security integration context, see Microsoft’s Intune endpoint security documentation. The Defender portal policy experience is a management option for supported endpoint security settings, not a replacement for full Intune management.
Quick Recap
Operational checklist
- Is the device onboarded to MDE and eligible for the selected policy?
- Is the correct enforcement scope enabled?
- Does the administrator have appropriate RBAC?
- Is the assignment to the correct Entra device group, with no scope conflict?
- Is the device managed through MDE security settings management rather than already enrolled in Intune?
- Is there recent SENSE activity and a matching MDM/CSP diagnostic result?
- Does the effective local Defender value match the intended setting?
- Could another policy source be overriding or conflicting with it?
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




