remove ```

This commit is contained in:
Joey Caparas 2016-05-09 17:06:10 +10:00
parent 5273d5b205
commit 31fcd89097

View File

@ -48,11 +48,11 @@ If the endpoints aren't reporting correctly, you might need to check that the Wi
![Image of OnboardingState status in Registry Editor](images/onboardingstate.png) ![Image of OnboardingState status in Registry Editor](images/onboardingstate.png)
If the **OnboardingState** value is not set to **1**, follow the instructions on **Identifying and addressing onboarding issues**. If the **OnboardingState** value is not set to **1**, follow the instructions on **Identifying and addressing onboarding issues**.
**Identifying and addressing onboarding errors:** **Identifying and addressing onboarding errors:**
1. Click **Start**. 1. Click **Start**.
2. Type **Event Viewer**. 2. Type **Event Viewer**.
3. In **Event Viewer**, browse to the **Application and Services Logs\Microsoft\Windows\SENSE** directory. 3. In **Event Viewer**, browse to the **Application and Services Logs\Microsoft\Windows\SENSE** directory.
@ -64,71 +64,72 @@ If the endpoints aren't reporting correctly, you might need to check that the Wi
6. Select **Critical**, **Warning**, and **Error**, then click **OK**. 6. Select **Critical**, **Warning**, and **Error**, then click **OK**.
![Image of Event Viewer log filter](images/filter-log.png) ![Image of Event Viewer log filter](images/filter-log.png)
7. Review the remaining events which can indicate issues and troubleshoot them based on the corresponding solutions from the following table: 7. Review the remaining events which can indicate issues and troubleshoot them based on the corresponding solutions from the following table:
Event ID | Message | Resolution steps Event ID | Message | Resolution steps
:---|:---|:--- :---|:---|:---
5 | Windows Advanced Threat Protection service failed to connect to the server at _variable_| Ensure that the Windows Defender ATP endpoint has internet access. 5 | Windows Advanced Threat Protection service failed to connect to the server at _variable_ | Ensure that the Windows Defender ATP endpoint has internet access.
6 | Windows Advanced Threat Protection service failed to read the onboarding parameters. Failure code: _variable_ | Run the onboarding script again. 6 | Windows Advanced Threat Protection service failed to read the onboarding parameters. Failure code: _variable_ | Run the onboarding script again.
7 | Windows Advanced Threat Protection service failed to read the onboarding parameters. Failure code: _variable_| Ensure that the Windows Defender ATP endpoint has internet access, then run the onboarding script again. 7 | Windows Advanced Threat Protection service failed to read the onboarding parameters. Failure code: _variable_ | Ensure that the Windows Defender ATP endpoint has internet access, then run the onboarding script again.
15 | Windows Advanced Threat Protection cannot start command channel with URL: _variable_ | Ensure that the Windows Defender ATP endpoint has internet access. 15 | Windows Advanced Threat Protection cannot start command channel with URL: _variable_ | Ensure that the Windows Defender ATP endpoint has internet access.
### Ensure that the Windows Defender ATP service is enabled ### Ensure that the Windows Defender ATP service is enabled
If the endpoints aren't reporting correctly, you might need to check that the Windows 10 Windows Defender Advanced Threat Protection service is enabled on the endpoint. If the endpoints aren't reporting correctly, you might need to check that the Windows 10 Windows Defender Advanced Threat Protection service is enabled on the endpoint.
**Check the startup type from the command line:** **Check the startup type from the command line:**
1. Open an elevated command-line prompt on the endpoint: 1. Open an elevated command-line prompt on the endpoint:
a. Click **Start** and type **cmd**. a. Click **Start** and type **cmd**.
b. Right-click **Command prompt** and select **Run as administrator**. b. Right-click **Command prompt** and select **Run as administrator**.
2. Enter the following command and press **Enter**: 2. Enter the following command and press **Enter**:
```
sc qc sense sc qc sense
```
If the the service is running, then the result should look like the following screenshot: If the the service is running, then the result should look like the following screenshot:
![Result of the sq query sense command](images/sc-query-sense-autostart.png) ![Result of the sq query sense command](images/sc-query-sense-autostart.png)
3. If the service **START_TYPE** is not set to **AUTO_START**, then you'll need to enter the following command and press **Enter**: 3. If the service **START_TYPE** is not set to **AUTO_START**, then you'll need to enter the following command and press **Enter**:
```
sc config sense start=auto sc config sense start=auto
```
4. A success message is displayed. Verify the change by entering the following command and press **Enter**: 4. A success message is displayed. Verify the change by entering the following command and press **Enter**:
```
sc qc sense sc qc sense
```
**Check that the service is running from the command line:** **Check that the service is running from the command line:**
1. Open an elevated command-line prompt on the endpoint: 1. Open an elevated command-line prompt on the endpoint:
a. Click **Start** and type **cmd**. a. Click **Start** and type **cmd**.
b. Right-click **Command prompt** and select **Run as administrator**. b. Right-click **Command prompt** and select **Run as administrator**.
2. Enter the following command and press **Enter**. 2. Enter the following command and press **Enter**.
```
sc query sense sc query sense
```
If the service is running, the result should look like the following screenshot: If the service is running, the result should look like the following screenshot:
![Result of the sc query sense command](images/sc-query-sense-running.png) ![Result of the sc query sense command](images/sc-query-sense-running.png)
3. If the service **STATE** is not set to **RUNNING**, then you'll need to enter the following command and press **Enter**: 3. If the service **STATE** is not set to **RUNNING**, then you'll need to enter the following command and press **Enter**:
```
sc start sense sc start sense
```
4. A success message is displayed. Verify the change by entering the following command and press **Enter**: 4. A success message is displayed. Verify the change by entering the following command and press **Enter**:
```
sc qc sense sc qc sense
```
### Ensure that telemetry and diagnostics service is enabled ### Ensure that telemetry and diagnostics service is enabled
If the endpoints aren't reporting correctly, you might need to check that the Windows 10 telemetry and diagnostics service is enabled on the endpoint. The service may have been disabled by other programs or user configuration changes. If the endpoints aren't reporting correctly, you might need to check that the Windows 10 telemetry and diagnostics service is enabled on the endpoint. The service may have been disabled by other programs or user configuration changes.
You will need to check the startup type and verify that the service is running. You will need to check the startup type and verify that the service is running.
There are two ways to check the startup type for the service: from the command line or in the services console. There are two ways to check the startup type for the service: from the command line or in the services console.
@ -139,32 +140,32 @@ There are two ways to check the startup type for the service: from the command l
a. Click **Start** and type **cmd**. a. Click **Start** and type **cmd**.
b. Right-click **Command prompt** and select **Run as administrator**. b. Right-click **Command prompt** and select **Run as administrator**.
2. Enter the following command and press **Enter**. 2. Enter the following command and press **Enter**.
```
sc qc diagtrack sc qc diagtrack
```
If the service is enabled, then the result should look like the following screenshot: If the service is enabled, then the result should look like the following screenshot:
![Result of the sc query command for diagtrack](images/windefatp-sc-qc-diagtrack.png) ![Result of the sc query command for diagtrack](images/windefatp-sc-qc-diagtrack.png)
4. If the **START_TYPE** is not set to **AUTO_START**, then you'll need to enter the following command and press **Enter**: 4. If the **START_TYPE** is not set to **AUTO_START**, then you'll need to enter the following command and press **Enter**:
```
sc config diagtrack start=auto sc config diagtrack start=auto
```
5. A success message is displayed. Verify the change by entering the following command and press **Enter**: 5. A success message is displayed. Verify the change by entering the following command and press **Enter**:
```
sc qc diagtrack sc qc diagtrack
```
**Check the startup type in the services console:** **Check the startup type in the services console:**
1. Open the services console: 1. Open the services console:
a. Click **Start** and type **services**. a. Click **Start** and type **services**.
b. Press **Enter** to open the console. b. Press **Enter** to open the console.
2. Scroll through the list of services until you find **Connected User Experiences and Telemetry**. 2. Scroll through the list of services until you find **Connected User Experiences and Telemetry**.
3. Check the **Startup type** column - the service should be set as **Automatic**. 3. Check the **Startup type** column - the service should be set as **Automatic**.
@ -179,24 +180,24 @@ ASK ALON HOW SET TO AUTOMATIC IF IT'S NOT SET FROM THE CONSOLE.
b. Right-click **Command prompt** and select **Run as administrator**. b. Right-click **Command prompt** and select **Run as administrator**.
2. Enter the following command and press **Enter**. 2. Enter the following command and press **Enter**.
```
sc query diagtrack sc query diagtrack
```
If the service is running, the result should look like the following screenshot: If the service is running, the result should look like the following screenshot:
![Result of the sc query command for sc query diagtrack](images/windefatp-sc-query-diagtrack.png) ![Result of the sc query command for sc query diagtrack](images/windefatp-sc-query-diagtrack.png)
3. If the service **STATE** is not set to **RUNNING**, then you'll need to enter the following command and press **Enter**: 3. If the service **STATE** is not set to **RUNNING**, then you'll need to enter the following command and press **Enter**:
```
sc start diagtrack sc start diagtrack
```
4. A success message is displayed. Verify the change by entering the following command and press **Enter**: 4. A success message is displayed. Verify the change by entering the following command and press **Enter**:
sc query diagtrack sc query diagtrack
### Ensure that the Windows Defender ATP endpoint has internet connection ### Ensure that the Windows Defender ATP endpoint has internet connection
The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to be able to report telemetry and communicate with the Windows Defender ATP service. The Window Defender ATP sensor requires Microsoft Windows HTTP (WinHTTP) to be able to report telemetry and communicate with the Windows Defender ATP service.
WinHTTP is independent of the Internet browsing proxy settings and other user context applications and must be able to detect the proxy servers that are available in your particular environment. WinHTTP is independent of the Internet browsing proxy settings and other user context applications and must be able to detect the proxy servers that are available in your particular environment.
To ensure that sensor has service connectivity, follow the steps described in the [Verify client connectivity to Windows Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md# To ensure that sensor has service connectivity, follow the steps described in the [Verify client connectivity to Windows Defender ATP service URLs](configure-proxy-internet-windows-defender-advanced-threat-protection.md#
Verify-client-connectivity-to-Windows-Defender-ATP-service-URLs) topic. Verify-client-connectivity-to-Windows-Defender-ATP-service-URLs) topic.