Tracking Your Windows Defender ATP Status on Your Devices

About this task

To use custom data to track the status of Windows Defender ATP on your devices:


  1. Create a Registry custom data item for the Windows Modern platform.
  2. In the Custom Data Type: Registry dialog box, enter the following values in the appropriate fields:
    • Registry Hive: HKEY_LOCAL_MACHINE
    • Key Path: SOFTWARE\Microsoft\ Windows Advanced Threat Protection\Status
    • Value Name: OnboardingState
  3. Save the custom data item and apply it to the applicable devices.


The value of the Windows Defender ATP status will be fetched on the next device check in and appears in the device's Device Information panel.

If you want to verify the status manually, navigate to HKLM\SOFTWARE\Microsoft\ Windows Advanced Threat Protection\Status in the Registry and verify the status of OnboardingState. The value should be 1.