Affected versions: Windows Server 2022

πŸ“– ~1 min read

Table of contents
  1. Symptom & Impact
  2. Environment & Reproduction
  3. Root Cause Analysis
  4. Quick Triage
  5. Step-by-Step Diagnosis
  6. Solution – Primary Fix
  7. Solution – Alternative Approaches
  8. Verification & Acceptance Criteria
  9. Rollback Plan
  10. Prevention & Hardening
  11. Related Errors & Cross-Refs
  12. References & Further Reading

Symptom & Impact

Endpoint telemetry drops and server appears inactive in security portal, reducing detection coverage.

Environment & Reproduction

Appears after outbound proxy or SSL inspection changes.

Get-MpComputerStatus
Test-NetConnection  -Port 443

Root Cause Analysis

Sensor cannot reach required cloud endpoints due to proxy auth/certificate interception mismatch.

Quick Triage

Validate service status and proxy configuration applied to LocalSystem context.

Step-by-Step Diagnosis

Collect Defender connectivity analyzer output and review onboarding logs.

Get-Service Sense
Get-WinEvent -LogName Microsoft-Windows-SENSE/Operational -MaxEvents 200
Illustrative mockup for windows-server-2022 β€” terminal_or_powershell
Defender sensor and connectivity diagnostics β€” Illustrative mockup β€” Progressive Robot

Solution – Primary Fix

Correct proxy allowlist/bypass for Defender endpoints and restart sensor service.

Still having issues? Our IT Solutions & Services team can diagnose and resolve this for you. Get in touch for a free consultation.

netsh winhttp show proxy
Restart-Service Sense
Illustrative mockup for windows-server-2022 β€” event_or_log_viewer
Sensor health recovery events β€” Illustrative mockup β€” Progressive Robot

Solution – Alternative Approaches

Redeploy onboarding package after connectivity restoration if sensor registration remains stale.

Verification & Acceptance Criteria

Device reports healthy in portal and telemetry timestamp updates within expected SLA.

Rollback Plan

Reapply prior proxy baseline and disable recent SSL inspection policy for server segment.

Prevention & Hardening

Test security tooling endpoints in change windows before proxy policy promotion.

Related to TLS interception trust failures and outdated onboarding packages.

View all Windows Server 2022 tutorials on the Tutorials Hub β†’

Browse all common problems & solutions on the Tutorials Hub.

References & Further Reading

Microsoft Learn: Defender for Endpoint server onboarding and network endpoint requirements.

Need Expert Help?

If you cannot resolve this yourself, our team offers hands-on Server Management, Managed IT Services, and flexible Support Plans. Contact us today β€” we respond within one business day.