Microsoft Defender for Endpoint
Developer and API

Offboard Machine Api

In brief

The documented supported platforms now include macOS 14 and later and supported Linux distributions, alongside the existing Windows versions. On Windows, the API still stops the sensor without removing registry onboarding information.

What Defender admins need to know

Administrators can use the API for eligible macOS and Linux devices and should account for the remaining registry information on Windows.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Supported operating systems

  • This API is supported on
    Operating systemSupported versions
    Windows 11,clientWindows 11 and Windows 10, version 1703 and later; later
    Windows ServerWindows Server 2019 and later; Windows Server 2012 R2 and Windows Server 2016 when using the new, unified agent for Defender for Endpoint.
    macOSmacOS 14 and later
    LinuxSupported Linux distributions

    Limitations

    • Rate limitations for this API are 100 calls per minute and 1,500 calls per hour.
    • This API is not supported on macOS or Linux devices.
    • RunningOn Windows devices, running the offboarding API only stops the sensor service from running, but it does notservice. It doesn't remove the onboarding information from the registry like an offboarding script does.

    Permissions