Implement the registry checker to check the Microsoft Defender ATP onboarding status (See https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/how-do-i-know-if-i-have-advanced-threat-protection-and-defender/td-p/1641241)
TLDR:
If the HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\Status OnboardingState value is present and set to 1 then the host is onboarded into MDATP.