How to List All Protected Endpoints in Microsoft Defender
Question details
The user wants to find a comprehensive list of all onboarded and protected devices (endpoints) within the Microsoft Defender environment.
- Product
- Microsoft Defender for Endpoint
- Device & OS
- not provided
- Scenario
- Reviewing device inventory and verifying endpoint protection status in an enterprise network.
- Observed behavior
- The user needs to view the complete inventory of protected endpoints using Defender portal tools or advanced KQL queries.
Ensure you have the appropriate administrative permissions in the Microsoft 365 Defender portal to view the device inventory and execute Advanced Hunting queries.
Use the Microsoft Defender Portal Device Inventory
The built-in Device Inventory provides a straightforward way to view all onboarded endpoints and their protection status.
Navigate to the Microsoft 365 Defender portal in your web browser and log in with your enterprise administrator credentials.
In the left-hand navigation pane, locate the 'Assets' section and click on 'Devices'.
Review the comprehensive list in the Device Inventory, which displays all endpoints currently onboarded and protected by Microsoft Defender.
Run Advanced Hunting Queries
For enterprise administrators needing highly customizable data, Advanced Hunting queries allow you to extract specific endpoint inventory details.
Manage Your Exported Security Reports with WPS Office
While Microsoft Defender manages your endpoint security, analyzing and formatting the exported endpoint data is easier with WPS Office. It provides a lightweight, highly compatible, and free alternative to Microsoft Office for all your IT reporting needs.
- 1. Export Defender Data: Export your endpoint inventory or Advanced Hunting query results as a CSV file directly from the Microsoft Defender portal.
- 2. Open in WPS Spreadsheet: Launch WPS Office and open the exported CSV file to view your raw endpoint data.
- 3. Analyze and Share: Apply filters, generate charts, and save your final security report as an .xlsx or PDF file to share with your organization.

Frequently Asked Questions
Why are some endpoints missing from the Defender device inventory?
Endpoints may not appear if they have not been properly onboarded, if they have been inactive for an extended period, or if network configurations are blocking communication with the Microsoft Defender service.
What role do I need to run Advanced Hunting queries?
To run Advanced Hunting queries and view endpoint data, you typically need to be assigned roles such as Security Reader, Security Administrator, or Global Administrator in your organization's directory.
Can I export the protected endpoints list for auditing purposes?
Yes, both the standard Device Inventory view and the results from Advanced Hunting queries can be exported as CSV files directly from the Microsoft 365 Defender portal for offline auditing and reporting.




