This is the method I used as an EDR administrator in a multi-country bank before escalating to the vendor. Each check rules out one layer, from name resolution up to the agent itself, so that when a case does reach the vendor it arrives with evidence, not guesses.
Walk through it below. Commands are shown for SentinelOne on Windows; the console address is a placeholder and no real configuration is published.
A console will count this device as covered. It is not. The difference between "agent present" and "actually protected" was the gap I reported to the CISO every two weeks, and this runbook is how individual devices got moved from one side of that line to the other.