diff --git a/windows/keep-secure/event-error-codes-windows-defender-advanced-threat-protection.md b/windows/keep-secure/event-error-codes-windows-defender-advanced-threat-protection.md
index 0f011611fa..029d6bb792 100644
--- a/windows/keep-secure/event-error-codes-windows-defender-advanced-threat-protection.md
+++ b/windows/keep-secure/event-error-codes-windows-defender-advanced-threat-protection.md
@@ -89,22 +89,23 @@ See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defen
7 |
-Windows Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure code: ```variable``` |
-The endpoint did not onboard correctly and will not be reporting to the portal. |
+Windows Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure: ```variable``` |
+Variable = detailed error description. The endpoint did not onboard correctly and will not be reporting to the portal. |
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
8 |
Windows Defender Advanced Threat Protection service failed to clean its configuration. Failure code: ```variable``` |
-The endpoint did not onboard correctly and will not be reporting to the portal. |
-Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
+ | **During onboarding:** The service failed to clean its configuration during the onboarding. The onboarding process continues.
**During offboarding:** The service failed to clean its configuration during the offboarding. The offboarding process finished but the service keeps running.
+ |
+**Onboarding:** No action required.
**Offboarding:** Reboot the system.
See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
9 |
Windows Defender Advanced Threat Protection service failed to change its start type. Failure code: ```variable``` |
-The endpoint did not onboard correctly and will not be reporting to the portal. |
+**During onboarding:** The endpoint did not onboard correctly and will not be reporting to the portal.
**During offboarding:** Failed to change the service start type. The offboarding process continues. |
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
@@ -125,23 +126,16 @@ It may take several hours for the endpoint to appear in the portal.
12 |
Windows Defender Advanced Threat Protection failed to apply the default configuration. |
-Service was unable to apply configuration from the processing servers. |
+Service was unable to apply the default configuration. |
This is a server error and should resolve after a short period. |
13 |
-Service machine ID calculated: ```variable``` |
+Windows Defender Advanced Threat Protection machine ID calculated: ```variable``` |
Normal operating process. |
Normal operating notification; no action required. |
-14 |
-Service cannot calculate machine ID. Failure code: ```variable``` |
-Internal error. |
-Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
-See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
-
-
15 |
Windows Defender Advanced Threat Protection cannot start command channel with URL: ```variable``` |
variable = URL of the Windows Defender ATP processing servers.
@@ -177,8 +171,9 @@ If this error persists after a system restart, ensure all Windows updates have f
|
25 |
-Windows Defender Advanced Threat Protection service failed to reset health status in the registry, causing the onboarding process to fail. Failure code: ```variable``` |
-The endpoint did not onboard correctly and will not be reporting to the portal. |
+Windows Defender Advanced Threat Protection service failed to reset health status in the registry. Failure code: ```variable``` |
+The endpoint did not onboard correctly.
+It will report to the portal, however the service may not appear as registered in SCCM or the registry. |
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
@@ -221,6 +216,12 @@ Ensure real-time antimalware protection is running properly.
[Check for errors with the Windows telemetry service](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-the-telemetry-and-diagnostics-service-is-enabled). |
+32 |
+Windows Defender Advanced Threat Protection service failed to request to stop itself after offboarding process. Failure code: %1 |
+An error occurred during offboarding. |
+Reboot the machine. |
+
+
33 |
Windows Defender Advanced Threat Protection service failed to persist SENSE GUID. Failure code: ```variable``` |
A unique identifier is used to represent each endpoint that is reporting to the portal.
@@ -235,6 +236,97 @@ If the identifier does not persist, the same machine might appear twice in the p
Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages.
See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
+35 |
+Windows Defender Advanced Threat Protection service failed to remove itself as a dependency on the Connected User Experiences and Telemetry service. Failure code: ```variable``` |
+An error occurred with the Windows telemetry service during offboarding. The offboarding process continues.
+ |
+Check for errors with the Windows telemetry service. |
+
+
+36 |
+Windows Defender Advanced Threat Protection Connected User Experiences and Telemetry service registration succeeded. Completion code: ```variable``` |
+
+ |
+ |
+
+
+37 |
+Windows Defender Advanced Threat Protection A module is about to exceed its quota. Module: %1, Quota: {%2} {%3}, Percentage of quota utilization: %4. |
+
+ |
+ |
+
+
+38 |
+Network connection is identified as low. Windows Defender Advanced Threat Protection will contact the server every %1 minutes. Metered connection: %2, internet available: %3, free network available: %4. |
+
+ |
+ |
+
+
+39 |
+Network connection is identified as normal. Windows Defender Advanced Threat Protection will contact the server every %1 minutes. Metered connection: %2, internet available: %3, free network available: %4. |
+
+ |
+ |
+
+
+40 |
+Battery state is identified as low. Windows Defender Advanced Threat Protection will contact the server every %1 minutes. Battery state: %2. |
+
+ |
+ |
+
+
+41 |
+Battery state is identified as normal. Windows Defender Advanced Threat Protection will contact the server every %1 minutes. Battery state: %2. |
+
+ |
+ |
+
+
+42 |
+Windows Defender Advanced Threat Protection WDATP component failed to perform action. Component: %1, Action: %2, Exception Type: %3, Exception message: %4 |
+Internal error. The service failed to start. |
+If this error persists, contact Support. |
+
+
+43 |
+Windows Defender Advanced Threat Protection WDATP component failed to perform action. Component: %1, Action: %2, Exception Type: %3, Exception Error: %4, Exception message: %5 |
+Internal error. The service failed to start. |
+If this error persists, contact Support. |
+
+
+44 |
+Offboarding of Windows Defender Advanced Threat Protection service completed. |
+The service was offboarded. |
+Normal operating notification; no action required. |
+
+
+45 |
+Failed to register and to start the event trace session [%1]. Error code: %2 |
+ |
+ |
+
+
+46 |
+Failed to register and start the event trace session [%1] due to lack of resources. Error code: %2. This is most likely because there are too many active event trace sessions. The service will retry in 1 minute. |
+ |
+ |
+
+
+47 |
+Successfully registered and started the event trace session - recovered after previous failed attempts. |
+ |
+ |
+
+
+48 |
+Failed to add a provider [%1] to event trace session [%2]. Error code: %3. This means that events from this provider will not be reported. |
+ |
+ |
+