---
title: GPO Onboarding for MDE (Windows)
description: Comprehensive guide to Windows GPO MDE onboarding.
---

[Skip to content](https://knowledge.sittadel.com/gpo-windows-mde-onboarding#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en)
3. [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)

# GPO Onboarding for MDE (Windows)

## Comprehensive guide to Windows GPO MDE onboarding: retrieving the MDE onboarding package from the Defender portal and utilizing a Domain Controller to deploy the Agent to connected Windows devices.

### **Gather Windows MDE Group Policy Package**

1. Navigate to the [Endpoint Onboarding – Microsoft Defender](https://security.microsoft.com/securitysettings/endpoints/onboarding) portal, from this page specify the **Operating System** as **Windows 10 and 11, Connectivity Type** as **Streamlined,** and the **Deployment Method** as **Group Policy.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-27-2024-01-23-33-1959-PM.png?width=670&height=435&name=image-png-Aug-27-2024-01-23-33-1959-PM.png)**
2. Once the proper selections have been made, locate, and select **Download onboarding package**, a **GatewayWindowsDefenderATPOnboardingPackage.zip** file will be stored to the **Downloads** folder on the **User **account.  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-27-2024-01-24-07-2505-PM.png?width=455&height=80&name=image-png-Aug-27-2024-01-24-07-2505-PM.png)![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-27-2024-01-24-25-9551-PM.png?width=515&height=150&name=image-png-Aug-27-2024-01-24-25-9551-PM.png)**
3. We will need to **extract the contents of the package,** the **extracted .zip folder** should house a **file** named **WindowsDefenderATPOnboardingScript.cmd.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-27-2024-01-25-22-5204-PM.png?width=664&height=50&name=image-png-Aug-27-2024-01-25-22-5204-PM.png)**
4. After the **extraction process** has been completed, we will want to relocate the **.cmd** file to a location where the file can be accessed by the desired **File Server** that can distribute the **MDE agent onboarding package to the** **Windows Devices that have access to the share**.

### **Deploying Windows Group Policy MDE Package**

1. On the **Domain Controller** where desired **Windows Devices** **that are wishing to** **MDE join are connected**. Open the **Group Policy Management Console (GRMC),** once opened we will want to locate the **Group Policy Objects** under our desired  **Right-click** and select **New**.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-27-2024-01-28-09-1914-PM.png?width=670&height=449&name=image-png-Aug-27-2024-01-28-09-1914-PM.png)
2. A window will be displayed, supply a **Name** for the **New GPO** in the text field then select **Ok** to continue.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-27-2024-01-28-37-3887-PM.png?width=419&height=200&name=image-png-Aug-27-2024-01-28-37-3887-PM.png)
3. The new entry will be generated under the **Group Policy Objects** list, locate and right-click the **New GPO** that was created, select **Edit** to define the **policy enforcement**.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-27-2024-01-29-09-9952-PM.png?width=670&height=407&name=image-png-Aug-27-2024-01-29-09-9952-PM.png)
4. This will open the **Group Policy Management Editor,** from the new window, we will want to traverse the directory until we get to the **Scheduled Tasks** section under **Computer Configuration --\> Preferences --\> Control Panel Settings.** Once there, right-click **Scheduled Tasks,** select **New --\> Immediate Task (At least Windows 7).**  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-27-2024-01-31-20-0813-PM.png?width=670&height=461&name=image-png-Aug-27-2024-01-31-20-0813-PM.png)
5. In the Task window that opens, go to the **General** Under **Security options** select **Change User or Group**, within the **User or Group** window type **SYSTEM** and then select **Check Names** followed by **OK**. **NT AUTHORITY\\SYSTEM** appears as the **user account the task will run as**. In the **Name** field, type an appropriate name for the scheduled task such as **Defender for Endpoint Deployment**. Select **Run whether user is logged on or not** and check the **Run with highest privileges** check box. Specify the desired **Windows Server OS** that your **File Server** is currently running off under the **Configure for** drop-down.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-27-2024-01-33-05-7353-PM.png?width=670&height=336&name=image-png-Aug-27-2024-01-33-05-7353-PM.png)
6. After the configuration items have been implemented under the **General** tab, we will locate the **Actions** tab, we will select **New…** Once the New Action window opens verify that **Start a program** is selected from the **Action** dropdown. We will want to supply the **UNC path,** using the **file server’s fully qualified domain name**, of the shared extracted **WindowsDefenderATPOnboardingScript.cmd** file. Select **OK** to confirm the action that the task will perform, the action will generate in the list, we will want to select **Apply** to save our configured settings and then select **OK** to complete the **Scheduled Tasks** deployment**.** Close out of any **Group Policy Management** windows.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-27-2024-01-34-03-3639-PM.png?width=670&height=305&name=image-png-Aug-27-2024-01-34-03-3639-PM.png)
7. To link the **GPO** to an **Organization Unit (OU)**, **right-click the OU** and select **Link an existing GPO**. In the dialogue box that is displayed, select the **Group Policy Object** that you wish to link. Click **OK**.

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>