---
title: "RMM Tool \"Detection and Remediation\" Script Onboarding for MDE (Windows)"
description: Comprehensive guide for Windows MDE Detection and Remediation RMM Script Deployment.
---

[Skip to content](https://knowledge.sittadel.com/windows-mde-detection-and-remediation-deployment#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en)
3. [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)

# RMM Tool "Detection and Remediation" Script Onboarding for MDE (Windows)

## Comprehensive guide for Windows MDE Detection and Remediation RMM Script Deployment: utilizing the retrieved MDE onboarding package, previously created detection script, and a preferred RMM tool for bulk deployment to desired Windows machines.

**Required Windows Versions:** Windows 10 1803+, Windows 11 (All)

### **Deploying MDE Detection and Response Script through RMM**

1. This deployment example will be leveraging **Ninja RMM** tool, while the **RMM tool** can vary **the process should remain relatively the same.**
2. From the console of your desired **RMM tool**, we will want to access the portal that will **allow the creation of scripts**, here we will want to **create a detection and remediation script that will determine if the agent is already present on the device and if not execute the onboarding script gathered from the organizations Microsoft Defender portal**. Let’s start with the **detection script**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-12-46-2559-PM.png?width=670&height=379&name=image-png-Aug-26-2024-04-12-46-2559-PM.png)**
3. Within **Ninja RMM,** you can either **copy and paste the code into the console** or **leverage drag and drop functionality to upload the necessary code for script execution.** We will be leveraging traditional **copy and paste** methodology for our example.
4. Leveraging the previously created **MDEDetection.cmd** script from the **MDE Detection and Remediation Script** steps, we will want to **open the file** directly from a **preferred text editor.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-13-48-1060-PM.png?width=670&height=424&name=image-png-Aug-26-2024-04-13-48-1060-PM.png)**
5. Once opened, we will want to **copy all the contents of the file** **and paste the contents from the text editor window into the** **RMM console**.  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-14-09-1306-PM.png?width=670&height=471&name=image-png-Aug-26-2024-04-14-09-1306-PM.png)**
6. Once the **script has been successfully ported over**, provide a **Name** and **Description** that is relevant to the **detection of the agent**. We will want to specify that this is a **Batch file (\*.bat,\*.cmd,\*.nt)**, the **OS** is **Windows**, the **Architecture** can be either **32-bit** or **64-bit**, and we want to leverage **administrative privileges** during execution so specify **Run As System.** Once the **script and additional configuration items have been configured**, select **Save** to confirm the **script creation**.  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-14-39-3195-PM.png?width=317&height=540&name=image-png-Aug-26-2024-04-14-39-3195-PM.png)**
7. After the **detection script** **creation**, we will move to **creating the remediation script**.
8. Leveraging the previously extracted **WindowsDefenderATPOnboardingScript.cmd** script from the **MDE Detection and Remediation Script** steps, we will want to **open the file** directly from a **preferred text editor.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-15-52-4582-PM.png?width=670&height=424&name=image-png-Aug-26-2024-04-15-52-4582-PM.png)**
9. Once opened, we will want to **copy all the contents of the file** **and paste the contents from the text editor window into the** **RMM console**.  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-16-16-7751-PM.png?width=670&height=472&name=image-png-Aug-26-2024-04-16-16-7751-PM.png)**
10. Once the **script has been successfully ported over**, provide a **Name** and **Description** that is relevant to the **remediation of MDE detection failure**. We will want to specify that this is a **Batch** **file (\*.bat,\*.cmd,\*.nt)**, the **OS** is **Windows**, the **Architecture** can be either **32-bit** or **64-bit**, and we want to leverage **administrative privileges** during execution so specify **Run As System.** Once the **script and additional configuration items have been configured**, select **Save** to confirm the **script creation.**  
    **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-16-36-1187-PM.png?width=307&height=540&name=image-png-Aug-26-2024-04-16-36-1187-PM.png)**
11. After **both scripts have been generated**, we will want to access the area of the **RMM tool that allows conditional remediation for devices.**  
    **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-23-57-6012-PM.png?width=670&height=379&name=image-png-Aug-26-2024-04-23-57-6012-PM.png)**
12. Provide a **Name** and **Description** that is relevant to the **detection/remediation behavior of the scripts for the MDE agent**. We will want to specify that this **policy enforcement** will be on **Windows devices**, and we will want to make sure that this **policy is active once creation is completed**, select **Create** to confirm the **policy creation.**  
    **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-24-25-4845-PM.png?width=534&height=450&name=image-png-Aug-26-2024-04-24-25-4845-PM.png)**
13. After the **creation** we will need to **specify what this policy is trying to achieve during execution.** For this example, we will be utilizing a **conditional based policy**. Verify that the proper sections are selected to achieve this functionality within your designated **RMM tool**.  
    **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-25-02-7142-PM.png?width=670&height=176&name=image-png-Aug-26-2024-04-25-02-7142-PM.png)**
14. Specifying the **Condition** for the **remediation script** to execute, we will want the launch criteria to be based on the **Result Returned** from the **MDE Detection script** we created earlier. You can specify the **Run Time** to be **any desired spam**, the **Timeout** should be higher due to the **client server architecture being utilized.** For the **error detection** metric, we will leverage the logic provided in the **MDE detection script**, in the code the catch for **detection failure** is based on **either the registry key or process not being captured**, this should **return an exit value of 1** and display the ‘**One or both checks failed.**’ Once all the **designated fields have been filled**, select **Apply** to continue.  
    **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-25-51-9100-PM.png?width=531&height=450&name=image-png-Aug-26-2024-04-25-51-9100-PM.png)**
15. After the **condition** **has been specified**, we will want to select the **MDE Remediation script** we created earlier as the script that will be leveraged on **condition failures**. Provide a **Name** that is relevant to the **detection/remediation of the MDE agent**. You can designate **any sort of system flagging you desire for execution failures** **if your tool allows it**. Within the policy if you can designate a **re-execution state**, make it fire when the **compliance has failed**. You can also specify **if you want individuals to receive notifications if your** **tool allows it**. Select **Add,** to continue to **policy finalization**.  
    **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-27-02-4760-PM.png?width=558&height=450&name=image-png-Aug-26-2024-04-27-02-4760-PM.png)**
16. If done correctly the **condition should be listed within the section**, select **Save** to **finalize the creation of the conditional based policy for the** **MDE Detection and Remediation Script RMM Deployment.**  
    **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-26-2024-04-27-26-5504-PM.png?width=670&height=172&name=image-png-Aug-26-2024-04-27-26-5504-PM.png)**

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>