From 4bedcfb302ceabaf4a3496c0e8729d243eed83a4 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Fri, 6 Nov 2020 11:46:13 -0800 Subject: [PATCH] Update event-error-codes.md --- .../event-error-codes.md | 70 +++++++++---------- 1 file changed, 35 insertions(+), 35 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md b/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md index b9b993006e..a2b75300ee 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md +++ b/windows/security/threat-protection/microsoft-defender-atp/event-error-codes.md @@ -1,7 +1,7 @@ --- title: Review events and errors using Event Viewer -description: Get descriptions and further troubleshooting steps (if required) for all events reported by the Microsoft Defender ATP service. -keywords: troubleshoot, event viewer, log summary, failure code, failed, Microsoft Defender Advanced Threat Protection service, cannot start, broken, can't start +description: Get descriptions and further troubleshooting steps (if required) for all events reported by the Microsoft Defender for Endpoint service. +keywords: troubleshoot, event viewer, log summary, failure code, failed, Microsoft Defender for Endpoint service, cannot start, broken, can't start search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -28,7 +28,7 @@ ms.date: 05/21/2018 - Event Viewer -- [Defender for Endpoint](https://go.microsoft.com/fwlink/p/?linkid=2146631) +- [Microsoft Defender for Endpoint](https://go.microsoft.com/fwlink/p/?linkid=2146631) You can review event IDs in the [Event Viewer](https://msdn.microsoft.com/library/aa745633(v=bts.10).aspx) on individual devices. @@ -58,39 +58,39 @@ For example, if devices are not appearing in the **Devices list**, you might nee 1 -Defender for Endpoint service started (Version variable). +Microsoft Defender for Endpoint service started (Version variable). Occurs during system start up, shut down, and during onbboarding. Normal operating notification; no action required. 2 -Defender for Endpoint service shutdown. +Microsoft Defender for Endpoint service shutdown. Occurs when the device is shut down or offboarded. Normal operating notification; no action required. 3 -Defender for Endpoint service failed to start. Failure code: variable. +Microsoft Defender for Endpoint service failed to start. Failure code: variable. Service did not start. Review other messages to determine possible cause and troubleshooting steps. 4 -Defender for Endpoint service contacted the server at variable. +Microsoft Defender for Endpoint service contacted the server at variable. Variable = URL of the Defender for Endpoint processing servers.
This URL will match that seen in the Firewall or network activity. Normal operating notification; no action required. 5 -Defender for Endpoint service failed to connect to the server at variable. +Microsoft Defender for Endpoint service failed to connect to the server at variable. Variable = URL of the Defender for Endpoint processing servers.
The service could not contact the external processing servers at that URL. Check the connection to the URL. See Configure proxy and Internet connectivity. 6 -Defender for Endpoint service is not onboarded and no onboarding parameters were found. +Microsoft Defender for Endpoint service is not onboarded and no onboarding parameters were found. The device did not onboard correctly and will not be reporting to the portal. Onboarding must be run before starting the service.
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
@@ -98,14 +98,14 @@ See Onboard Windows 10 devices. 8 -Defender for Endpoint service failed to clean its configuration. Failure code: variable. +Microsoft Defender for Endpoint service failed to clean its configuration. Failure code: variable. During onboarding: The service failed to clean its configuration during the onboarding. The onboarding process continues.

During offboarding: The service failed to clean its configuration during the offboarding. The offboarding process finished but the service keeps running. Onboarding: No action required.

Offboarding: Reboot the system.
@@ -113,14 +113,14 @@ See Onboard Windows 10 devices. 10 -Defender for Endpoint service failed to persist the onboarding information. Failure code: variable. +Microsoft Defender for Endpoint service failed to persist the onboarding information. Failure code: variable. The device did not onboard correctly and will not be reporting to the portal. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
See Onboard Windows 10 devices. @@ -134,26 +134,26 @@ It may take several hours for the device to appear in the portal. 12 -Defender for Endpoint failed to apply the default configuration. +Microsoft Defender for Endpoint failed to apply the default configuration. Service was unable to apply the default configuration. This error should resolve after a short period of time. 13 -Defender for Endpoint device ID calculated: variable. +Microsoft Defender for Endpoint device ID calculated: variable. Normal operating process. Normal operating notification; no action required. 15 -Defender for Endpoint cannot start command channel with URL: variable. +Microsoft Defender for Endpoint cannot start command channel with URL: variable. Variable = URL of the Defender for Endpoint processing servers.
The service could not contact the external processing servers at that URL. Check the connection to the URL. See Configure proxy and Internet connectivity. 17 -Defender for Endpoint service failed to change the Connected User Experiences and Telemetry service location. Failure code: variable. +Microsoft Defender for Endpoint service failed to change the Connected User Experiences and Telemetry service location. Failure code: variable. An error occurred with the Windows telemetry service. Ensure the diagnostic data service is enabled.
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
@@ -180,7 +180,7 @@ If this error persists after a system restart, ensure all Windows updates have f 25 -Defender for Endpoint service failed to reset health status in the registry. Failure code: variable. +Microsoft Defender for Endpoint service failed to reset health status in the registry. Failure code: variable. The device did not onboard correctly. It will report to the portal, however the service may not appear as registered in SCCM or the registry. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
@@ -188,7 +188,7 @@ See Onboard Windows 10 devices.
@@ -218,7 +218,7 @@ See Onboard Windows 10 devices
@@ -226,26 +226,26 @@ Ensure real-time antimalware protection is running properly. 31 -Defender for Endpoint Connected User Experiences and Telemetry service unregistration failed. Failure code: variable. +Microsoft Defender for Endpoint Connected User Experiences and Telemetry service unregistration failed. Failure code: variable. An error occurred with the Windows telemetry service during onboarding. The offboarding process continues. Check for errors with the Windows telemetry service. 32 -Defender for Endpoint service failed to request to stop itself after offboarding process. Failure code: %1 +Microsoft Defender for Endpoint service failed to request to stop itself after offboarding process. Failure code: %1 An error occurred during offboarding. Reboot the device. 33 -Defender for Endpoint service failed to persist SENSE GUID. Failure code: variable. +Microsoft Defender for Endpoint service failed to persist SENSE GUID. Failure code: variable. A unique identifier is used to represent each device that is reporting to the portal.
If the identifier does not persist, the same device might appear twice in the portal. Check registry permissions on the device to ensure the service can update the registry. 34 -Defender for Endpoint service failed to add itself as a dependency on the Connected User Experiences and Telemetry service, causing onboarding process to fail. Failure code: variable. +Microsoft Defender for Endpoint service failed to add itself as a dependency on the Connected User Experiences and Telemetry service, causing onboarding process to fail. Failure code: variable. An error occurred with the Windows telemetry service. Ensure the diagnostic data service is enabled.
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
@@ -253,56 +253,56 @@ See