---
title: Hands-On Offboarding for MDE (Linux)
description: Comprehensive guide to Linux Local MDE offboarding
---

[Skip to content](https://knowledge.sittadel.com/manual-linux-local-script-mde-offboarding#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en)
3. [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)

# Hands-On Offboarding for MDE (Linux)

## Comprehensive guide to Linux Local MDE offboarding: executing the necessary commands to stop Agent functionality and validate that the Agent processes are no longer present on the machine.

### **Offboarding Linux Device from MDE Monitoring**

1. On the desired **Linux Device** that you wish to **Offboard**, access the **Activities** tab and within the **search field** provide **Terminal,** this should return the utility in the list below the field, and we will want to select it to **leverage the necessary commands to remove the MDE agent from the machine.** **For this demonstration we are using Ubuntu 20.04 Jamming Jellyfish, if the UI or functionality is different depending on your flavor of Linux, please leverage the utility based on your distribution that allows you to search for other applications to initiate a Command Line session on the device.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-28-2024-04-52-31-7530-PM.png?width=662&height=500&name=image-png-Aug-28-2024-04-52-31-7530-PM.png)**
2. Once the **CLI session** is started, we will **execute the command below** to initiate the decommissioning of the **MDE agent** on the machine and severe the connection between **the device** and **Microsoft Defender** **services**. **We will need to execute this command with administrative privileges, you will need to fulfill the authentication prompt that is generated in the session. Additionally, during execution, you will need to consent to the removal of the mdatp package by supplying Y.**
   
   | **Command** |
   | --- |
   | **sudo apt-get purge mdatp** |
   
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-28-2024-04-53-28-2836-PM.png?width=670&height=307&name=image-png-Aug-28-2024-04-53-28-2836-PM.png)**
3. After execution of the **offboarding command above**, there is a warning during execution that residual packages which were automatically installed during onboarded will need to be removed separately, we can achieve this by supplying the command below to clean up additional resources that were installed. **We will need to execute this command with administrative privileges, you will need to fulfill the authentication prompt that is generated in the session. Additionally, during execution, you will need to consent to the removal of the mdatp package by supplying Y.**
   
   | **Command** |
   | --- |
   | **sudo apt autoremove** |
   
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-28-2024-05-29-25-2307-PM.png?width=670&height=313&name=image-png-Aug-28-2024-05-29-25-2307-PM.png)
4. After the **execution of both commands** **above**, we will proceed with supplying the following **one-liner to evaluate if the MDE agent still has proper security functionality enabled for communication to your Organizations Microsoft Defender portal.**
   
   | **One-Liner** |
   | --- |
   | **echo -e "Org ID: $(mdatp health --field org\_id)\\nHealthy: $(mdatp health --field healthy)\\nDefinitions: $(mdatp health --field definitions\_status)\\nRTP Enabled: $(mdatp health --field real\_time\_protection\_enabled)"** |
5. Upon **execution of the script**, you will see values returned in the window below.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-28-2024-05-31-33-6810-PM.png?width=670&height=342&name=image-png-Aug-28-2024-05-31-33-6810-PM.png)
6. Depending on the results there will be **two different paths forward:** 
     1. **If the one-liner returns that the mdatp application is no longer found on the machine, the agent is no longer on the machine and the MDE offboarding process was successful.** Next steps will be to access the defender portal and exclude the device manually from the system once the offboarding verification process has been executed successfully, this procedure can be [found here](https://knowledge.sittadel.com/mde-device-exclusion?hsLang=en).
     2. **If the one-liner returns fields that possess values related to the agent being active and connected to an organization, that means that the MDE agent has not been successfully removed and the machine is still currently being monitored by the MDE agent. This could be due to the steps outlined above not being conducted correctly, or the offboarding package gathered from the Defender portal having reached its expiration period.** Next steps will require that an investigation of process breakdown be conducted prior to attempting a re-execution of the procedure.

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>