---
title: Hands-On Offboarding for MDE (Windows Server)
description: Comprehensive guide to Windows Server Local MDE offboarding
---

[Skip to content](https://knowledge.sittadel.com/manual-windows-server-local-script-mde-offboarding#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en)
3. [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)

# Hands-On Offboarding for MDE (Windows Server)

## Comprehensive guide to Windows Server Local MDE offboarding: retrieving the MDE offboarding package from the Defender portal, executing the embedded scripts to stop Agent functionality, and validating that the Agent processes are no longer present.

### **Gather Windows Server Local MDE Offboarding Package**

1. Navigate to the [Endpoint Offboarding – Microsoft Defender](https://security.microsoft.com/securitysettings/endpoints/offboarding) portal, from this page specify the **Operating System** as **Windows Server 2019 and 2022, Deployment Method** as **Group Policy.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-02-26-05-4436-PM.png?width=670&height=441&name=image-png-Aug-29-2024-02-26-05-4436-PM.png)**
2. Once the proper selections have been made, locate, and select **Download Package**. A **disclaimer** will be displayed upon selection, we will want to **consent for this action** by selecting **Download**. This should initiate a **WindowsDefenderATPOffboardingPackage\_valid\_until\_YYYY-MM-DD.zip folder** install that should be stored to the **Downloads** folderon the **User** account**.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-02-27-30-4836-PM.png?width=670&height=44&name=image-png-Aug-29-2024-02-27-30-4836-PM.png)![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-02-28-21-2526-PM.png?width=317&height=300&name=image-png-Aug-29-2024-02-28-21-2526-PM.png)![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-02-28-55-2040-PM.png?width=478&height=105&name=image-png-Aug-29-2024-02-28-55-2040-PM.png)**
3. We will want to **extract** **the contents of the package**, the **extracted .zip folder** should house a **file** named **WindowsDefenderATPOffboardingScript\_valid\_until\_YYYY-MM-DD.cmd.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-02-31-12-6443-PM.png?width=601&height=60&name=image-png-Aug-29-2024-02-31-12-6443-PM.png)**
4. After the **extraction process** has been completed, we will want to relocate the .cmd file to a location where the file can be accessed by the desired **Windows Server** that are wishing to **offboard from MDE monitoring**, this can be done by **uploading the file to a trusted SharePoint, Outlook email, or USB.**

### **Deploy Windows Server MDE Local Offboarding Package**

1. On the desired **Windows Server**, we will first want to verify that the **WindowsDefenderATPOffboardingScript\_valid\_until\_YYYY-MM-DD.cmd** file is housed on a **desired directory** on the server.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-02-32-20-1607-PM.png?width=645&height=130&name=image-png-Aug-29-2024-02-32-20-1607-PM.png)
2. Once we have verified that the **.cmd** **file** is present on the device, we will want to right clickthe **file** from the **file explorer** session and select the **Run as administrator** option. This will initiate an **elevated command prompt** that will run the necessary **offboarding scripts to sever communication** for the **MDE Agent** with **Microsoft Services.**  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-02-51-41-0204-PM.png?width=670&height=379&name=image-png-Aug-29-2024-02-51-41-0204-PM.png)
3. Running this script should initiate an **elevated session** **to run for execution of the offboarding code.** After a few seconds the **session will close automatically**, we will proceed to leveraging **detection commands** to verify that the **service tied to the MDE agent is no longer present on the Server.**  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-02-53-47-3746-PM.png?width=670&height=84&name=image-png-Aug-29-2024-02-53-47-3746-PM.png)

### **Assessing a Windows Server MDE Local Offboarding Deployment**

1. Utilizing the **Windows Search** functionality within the **search field** provide **Command Prompt**, **right click the returned result,** and select the **Run as Administrator** option to initiate an **elevated command line session.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-02-58-20-2757-PM.png?width=576&height=500&name=image-png-Aug-29-2024-02-58-20-2757-PM.png)**
2. Once the **elevated session is generated**, we will want to supply the following **command below into the session** to verify that the **sense** **service** initiated by the presence of the **MDE agent** on the **Server is** **no longer running.** This command should return the **sense service** in the **stopped state,** **the** **Windefend service will remain in the running state since this is the native anti-virus on the server**.
   
   | **Command** |
   | --- |
   | **sc.exe query Windefend && sc.exe query sense** |
   
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-03-02-27-8861-PM.png?width=583&height=330&name=image-png-Aug-29-2024-03-02-27-8861-PM.png)**
3. Depending on the results there will be **two different paths forward:** 
     1. **If the command returns that the sense service is no longer running on the machine, the agent is no longer on the server and the MDE offboarding process was successful.** Next steps will be to access the defender portal and exclude the device manually from the system once the offboarding verification process has been executed successfully, this procedure can be [found here](https://knowledge.sittadel.com/mde-device-exclusion?hsLang=en). 
     2. **If the command returns that the sense process is still running, that indicates that the agent is still active and connected to an organization, that means that the MDE agent has not been successfully removed and the server is still currently being monitored by the MDE agent. This could be due to the steps outlined above not being conducted correctly, or the offboarding package gathered from the Defender portal having reached its expiration period.** Next steps will require that an investigation of process breakdown be conducted prior to attempting a re-execution of the procedure.

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>