scloud by Florian Salzmann
ende

Defender for Endpoint: Failed to Enable Intune Integration

Short answer: this error is a timing issue, not a misconfiguration. Wait 15 minutes up to 24 hours after the Defender license first gets assigned, then retry - the integration will complete on its own.

Why do I see “Failed to enable Intune integration”?

Do you get the error “Failed to enable Intune integration” when activating Defender for Endpoint or Defender for Business? You’re probably just as impatient as I am. And you just logged in to the Security Portal for the first time since the Defender for Endpoint or for Business license got assigned.

Just give it some patience (15 minutes up to 24 hours, I’ve seen it all) and try again after that.

Defender for Endpoint "Failed to enable Intune integration" error message

Unfortunately the message itself doesn’t give a very helpful hint. To not waste your time unnecessarily, it’s worth keeping a cool head here. In the end a green bar finally shows up and the Defender message “Failed to enable Intune integration” disappears.

If you’re using Defender for Business, the initial wizard won’t show up a second time. So you have to activate the integration manually in Intune.

I put together a walkthrough for setting up Defender for Business with the simplified administration here: Defender for Business Onboarding / Setup | scloud

FAQ

Does this error mean something is misconfigured?
No. In almost every case it just means the license assignment hasn’t fully propagated to the Security Portal yet.

What if it still shows after 24 hours?
That’s unusual - double-check the Defender for Endpoint / Defender for Business license is actually assigned to your account, then activate the Intune integration manually rather than waiting on the first-run wizard, which (for Defender for Business) only appears once.

Where do I activate the integration manually in Intune?
Go to Intune admin center > Endpoint security > Microsoft Defender for Endpoint, and toggle “Connect Windows devices…” (and the compliance policy evaluation options below it) to On. Give the connector another 5-10 minutes after saving before checking device compliance status - the connector handshake isn’t instant either.

How do I confirm the connection actually succeeded?
Back in the same Intune blade, the connection status field should read “Enabled” with a recent “Last sync” timestamp rather than an error. If it still shows an error after manually enabling it, sign out of both the Intune admin center and Security Portal and back in - stale admin sessions are a common reason the status doesn’t refresh even after the backend sync completed.

Related posts

Defender Web Filter
Defender for Business

Defender for Endpoint - Web Filter

With Defender for Endpoint and Defender for Business, implement a web filter regardless of location and monitor it centrally.

Defender Scope-Tag Intune
Defender for Business

Defender for Endpoint Scope Tag with Autopilot and Intune

I explain how to move the Defender for Endpoint Scope Tag from Autopilot through Intune into MDE device groups in five easy steps.

802.1X Wi-Fi Failing - Check Your Assignments
Microsoft Intune

802.1X Wi-Fi Failing? Check Your Certificate Chain

Troubleshooting 802.1X Wi-Fi in Microsoft Intune? Learn why assigning Wi-Fi, Root CA, Intermediate CA, and SCEP or PKCS profiles to different groups can cause certificate chain issues and failed authentication.