How to Fix Microsoft Defender for Endpoint Onboarding Service Will Not Start
Question details
The user is attempting to onboard devices to Microsoft Defender for Endpoint, but the service fails to start, causing the deployment script to hang.
- Product
- Microsoft Defender for Endpoint
- Device & OS
- not provided
- Scenario
- Running the onboarding script with administrator privileges to deploy Microsoft Defender for Endpoint.
- Observed behavior
- The onboarding script begins, but the Microsoft Defender for Endpoint service does not start and the script remains in a waiting state indefinitely.
Ensure that you are running the deployment script with full administrator privileges and that your network environment allows communication with Microsoft Defender for Endpoint cloud services.
Seek Assistance from the Microsoft Defender Tech Community
Since this is a complex endpoint security issue, reaching out to Microsoft product specialists is the most effective way to get targeted troubleshooting.
Microsoft provides a dedicated forum where product specialists and experienced IT administrators can assist with advanced deployment failures, such as onboarding scripts hanging or services failing to initiate.
Open your web browser and go to the official Microsoft Defender for Endpoint Tech Community page at https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/bd-p/MicrosoftDefenderATP.
Log in using your Microsoft account or organizational credentials associated with your endpoint deployment administration.
Create a new discussion post detailing your issue. Be sure to include information such as your operating system version, any output from the script execution log, and the exact point where the service hangs.
Switch to WPS Office for a Lightweight and Hassle-Free Experience
While troubleshooting complex Microsoft deployment issues can be time-consuming, your daily productivity shouldn't suffer. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office, ensuring your document work remains uninterrupted without the need for complex deployment scripts.

Frequently Asked Questions
Why does the Microsoft Defender onboarding script hang?
The script usually hangs because the underlying Windows Defender Advanced Threat Protection (Sense) service fails to start. This can be caused by missing prerequisites, third-party antivirus conflicts, or missing network endpoints.
What permissions are required to run the onboarding script?
You must run the onboarding script from an elevated command prompt or PowerShell session with full Administrator privileges. Without these, the script cannot create the necessary registry keys or start the system-level security services.
Are there network prerequisites for Microsoft Defender for Endpoint?
Yes. The devices being onboarded must be able to reach specific Microsoft cloud URLs and telemetry endpoints. If your enterprise firewall, proxy, or gateway is blocking these endpoints, the service will fail to connect and remain in a waiting state.




