From 9b47e9a116fdf1bd499a761f12e2cf2fa5163428 Mon Sep 17 00:00:00 2001 From: Iaan Date: Fri, 29 Apr 2016 16:05:35 +1000 Subject: [PATCH] troubleshooting changes --- .../keep-secure/images/windefatp-sc-query.png | Bin 0 -> 18795 bytes ...ows-defender-advanced-threat-protection.md | 178 ++++++++++++++++-- 2 files changed, 164 insertions(+), 14 deletions(-) create mode 100644 windows/keep-secure/images/windefatp-sc-query.png diff --git a/windows/keep-secure/images/windefatp-sc-query.png b/windows/keep-secure/images/windefatp-sc-query.png new file mode 100644 index 0000000000000000000000000000000000000000..fd1c05b648f5c21d1836501969f7aed52c9db01a GIT binary patch literal 18795 zcmb5Wby!qw+b=wTg0!G?N_XCfGzbV1(jhg3gh&Vs4Ksw4q=2L{gn)E+42^^!IUo&^ zLw5~)3!nRa_xJ9-|JidK9Kf~Knpx|L^E`iXO@!tvB|gaF#G?@rTw z3vsXpecv5r2Z0ztFBRl;y}shaLzO_YV*_v$_3f^d^dZqgr`mk zT*XrWUe#4)7;VmF{0xoscmKwYBKb@A7bGF9;lPVt0$ca4l~6E~33%CuV~~-MkZ8#h ze7`$NZ7Hh=92|d$#RVM94sF%9&brvU_0EZgz)q0Slk7mNxXouwF3>srHd%(twC56W z%X_~)P1-nHM-`_6o@7y+Z3 z%?tLHc2Eq9b+_BG`{~1GMMjQ`ypIlJZ$V}KlSPfQTHZL$M2^h|FV2UDZ^_{VH>|B4 zRs}Gld9fS%`PSBs$PmsEJZ89Nn5Q%YpN&$;3n?!~1-jhK~G@oaA-A-sAB8GEe zVVTao&6vYu{U^L zSC=?#N^Oyz&ik9)G8i|TWd|PPadl>FE%U>Vu0qOpnFKD)DhJ`1&bJ3YJw)e?7uq95 zZO+xTRCW8F+S4_u41}82MWAml@}dT<%pfsEm-Ca}UMG`a+BXZ`zPJ9TVysNrISE9C zL}Y3hB3Ol9zaFD+odR_?O7<4--w?r}*dRm~ca&ub(L(2pMRL-u#nex%#iNsccCVG# zKn=duh_d-B#QrWZEE);RTFHsj2sqLmzhJDcBuSG`gB|qS}p_@0k zA%PxI#ap-9t}-+YJMYiTiVoCip{MjrPeq!4|GrI5-?64YI#V5TsYN1gv6|1X_xAf5 z-MOIj^D=|2h!cu9m}Ez~*(C6+TxW(jUOFNY!}4VJwGPa=>{|*|AZKVH2mgzEWjFL* zE9kTCbZ0c5+3mISf%g>N(Zui#8yW4~vKzNU!^J*Ua|f@PcdHkwlXxF5-wRz*Tr$6W zl*}KQY&^eMw`V4I1D#f+n_**g`hkQm&UJyd66>H8WmcgETBuQ5=IgbbM}94zwbsJ? z{r;h}j(y~_0-3|C8hBdB&_q43whJ2)}cV zK3YR&+H-+desA$abk95CE(kVbY#?F*8=iapUz;pqT?sE73zzU z@H%)gu;yFj zGc%Q3c*Wou?$(U-mubgml{{OjugSqRj|k^5FcUc0>IBmk=N5Y4>y3C7WHWN_bnn5J z>R`^fjaAa^MF>Q<1maeDe`)w&Qv(t02|It+d?hbvenEDV>E!Ntlo8?y^CG{o3f18E z)2fRt-S=?N^yvsAm%g>4*)zGN+P@$uo5Tu)W*F_QpC7}~e18}s(I1V>%qARNF3MwL zlWdAagRDu`+V_L zMsk=gfF8Z$d9&|VR-#+xf89PX0c0F}inQAs_{#11(XD?z;dK$>2B{_`ANz1U4M-;T ztxy-emXJb7(5t)LVq2&!+fB}P_opARw2t_Q%cYof%emO@?c3)}Og>Q_8DSsqQqsNu zr+fvh|Fhfc%Pf=}kcJ?8`bA`|*M|cyta)G}R``E2ozB0R?zfICYiCM*3gsd6qc2|d z6BEw|yeGEPDQ#aVz3i1#Xd2&#ZMLuicS0YJ@%iZoRAYoejqkVEgYn>TF<;lf4rt#q zlybm$&*l>qSav%#3CT#s42#la=zI11^UB?A5jPz2r9Pe>r50yACUz@Rmx+I@{7Nma ze@!p~Puzls#YHHuBWHf5(;i2>5PNGJDp--JO8;UD)K~wqTDw6Ct5W!drHDCQc{`2V z&xrc!EPS2mYl-r!XAHe6@q}tTbfY#H$HT(4pXHyjl|wjBlgFX7nb+HALNQ>7-z4S~ z+Red3M*OrO+K2gg&!?i&-LSM(FVsQJye40BeeS2n@|8iO|G2pH$c@uidEkze{wT>@ zl0Xj=;EDX_2RQr&anTc9UyBK-xHC6c%c3HhT-}l<^yQJJgf*2XVcfhY84hatyIqET z-ZM$SneGOU%bm<%O@l#{f3P5K1JPWCQz%~^y`Ut4xO>YKM=CE^tHOD zBK$G|{(3DUMNzP(D70$NOZ*4BPLnW~HTqxT1)^qLBiWGPCXn6NH_36c(32Hrqr4=_ zRWoK__Vn%nJ)*UQ7_$r>HU801H@O^}zn?hoQJ!eHhUdX3SNBxzvy3z`R>^x=Kg;(g z9=gg9e)&R|=3GOcO_qoo`@e;iiD z>`dx-RXF9#oqTvtrINrr`;lR2`&c{%J}?TUr(~M`C4Loj7gk@2zI3?q zznY257IZ?HH3&mk+R}wmfOzF&7l!}c4)z5@mtZN4&qVmr3e;3aZ;N68t`~Nz=aadM zY0RG2rcmH>6=K_DZdPP=n|DQ94+udK5mFIAP_v_m2vB*-mY!N!rQP`t=}!x?)@LtA zB-9h>Ap3NtfH(5-scpJ;T{jyQfT*+BJXaYOOcXR2wV~(!wDl(HeN48; zTw&h2p~~>5lV4o4@Zd+ng-Qv&yZ+5SOBZuUHj@-y8h;TKwd9{0vM-3Bx7^~9$0qOY z_vSC6OT=2cnkwE(^_P}e)!&4NXOw-k`u>LU(Ib@+3W!&gvc^5GyL+IN@*>nvmaFpdSKH9~8J=yTS$&C-w|WWtg(p ziuO`FrT zIxBr9my_nvNXs`u(E$Zh)!za+`2V#2tX!#z-N_$Avz&=do2DmFb9@DfO}Hn45%%k% zFn=v%R?_xq$r#GG6;{BvYGgVvF$8X{Tp2q)($Yudov<@y=W$`{YLz0sq-Wl(Q68JH zw_NcWMzZCymFEHo6V$g+uQYXo_#Yw2I*d7$xfHTTPJ4VNHup3}U9v2`O8R^)B7VR= z8Fkw5=X~4x3eV@o{Haw$u5dhc zHrOQ8ah9knBLWA->kCW?ssWu|$D4j~+yxtV^>qilX7uEV(m-nj=KtyjS zrS2OJp-f{!ke;cPC`8A44iA+l&_feI52a1HSZd&4kx@3XHBv7=bMwke9Tcfky4fN9 zHKySa!QL9wO&}dmwTxM=@Jm3eD!9S6W7{6osJZw=CgUXoT*_gA!D?$WeFx|1rN~~Q z_B<|^l(gQEv$**~IojQ=2^Z0&nunk~RENS;e~lZOY}Y3vLD>9fArr4gui~CeOjKPe@CiFqs3yiM(p>+LL2o zyhx7+Y~~n;YNBN~Ek<=7P9eJy*N=K_HD=(xvejsTxMDV1=e%RrA&u8)l_BRz%Bp?2 zAo=JbRnp+f|PDUKWdAq zv3s`6E~qvTLT_v@bM#n@@>oNlLaiPpT`+#SPOm2HBNHH1IU-=FKk>JP8DZJ%BYj=!Gqhsr>oGL<`Cts^S`_8YBgxN;r5qik-9oho+#^BPY4eu z;{HVY8Yo!ABbQxheHqzKzwG{FJLEqhXp6FxE@oZ7663o6$obF&U?e_G*oVN*!(db1 zXlK6_8p9j=({tC0ixtl1t}#uVEt^@=pX0k0T{OooVvh1bAKYX4A4+@wXh;nY-+(%J zUX(P^oz7Xusn8|ddKu&51kWka?7jI)&hkSw;yH0Ym29`b#41JGZqfE35UhPaZ5%S+ zMfO)2j>$k62Wq)#7y7>xNd6Md!ug98p{eKpgBYRI1kNH6=?b{3QNKU=f2mRb-!47T zeJfwT`_O1>xKc1sLXc5LIhP2?ZT}XhjSS$K>$1?Sch4gbsOU^0TF~+fhfQsJcVcFD z5ROn(L`c_6VD!xeCG>dSRcF#BLB5_%KpUs+S4aUPE0;{GpX(FnZ1i? zoOs<8^91O!qlehKz$fB%4?OT$CdE*ioY9hff=T=i^LV&7g%@+fhl2Wx!hWVZSsP6R zf>8GvM?Gg4hRS1E#gn8JbzasJZr08EUp+sh?)|;AF!p4XUv&F6DU4XKShJ6snV{CkZtrP$BX*Vw|n z3j3dm5OhvvyeVJlTrh@^wjF_TZDlnnryUu-O#SX!gXP5g@p0JLDQku}tm zzSD&@IJ#ps7GH11A|o4pDjHr#O-e#Sr~E9mzkL?#@mM!BH0y_e58mR>ZuJ=;{$Qwx z>eo+(U=km3X$AkAl3E1kO*NKYit`D@%29%b=+1$FSrA;+CHqZckOCvI6#JqWi^nEq z?ta|we2MXIAqi>0U#hdXjZSsR3Jagpc}JX~54_hFkY575Wc*GXW$T_=l~-F#InuPs z9G35r#`N#b1U_(`T>Xa0)cs+m34eisHP*fFbY-p(wTc(a2`mPJJYe;h731VeV7XN3 zsZo@oY=}*gAcjuo&>o?9r;t6z*i=`bVuXl_ZaDEQa=HC2$_I9%fzewBGLZte-erjw zXk)ni0n5h0k9Xeqwvr+F$M2`*JoXKYWJXx)$ifpxf9YXP8C;=W9Xlsi!1|uO#b}@V zdC5OCi)F-q662h$xQXqF@vA?AHem**8lNs+l#4J7xc6VvZGB4elBKa>=oE}lJH$1T&2BvzPaitN#A~11DC>(B9ht-FHmT!_5R{+k?WOwO7l?K@cA@_eYSAdcJ0ikySF@83 zmfx?G(u-s;pF*96jPB|~04n!Am_Es5bMzZjAwbJKgxM=BDok)xRd z?FOKl6i4HSpP(zP!Y}G|3-?E3TSHW5`966Kmbs$2AkKMPOc{mMj30^3V;vxahBU_Z z8T@1J7Nx@#Q{Vx}Qkun22bw_ol09>Qt&Zpx{%@ru>(m~@cmqRTG6vJ9-I8H=os=@*{2{F7sYJ zKW(jI0s-DH^?u9e>$ajHliYa1(y6TijUzfDhVxZqP920IP6bh zSxAoV>vw18mgnP0=5OU{>8e?4+_e{aX=X42VEqV`stK&~b8XnpK+l_1qMDtv>ZM5$ z)8h*lB%Go+dw6hd;UL+Izg69_zQxJrs}OkU(70ELws#a=WO}>3vksH_wxEHmtG_`t zHf~=2;BFW_)0jRe_HDjcM!B@;7foyd6oB3F<=x$ST<9&ux>)1H9Y?yWP&(Q@$8|7S zzm`1$3eE7`;3vODY97)ObR^2Gk6FK{!1hrAUD=OiKPg4bxw=eNHkVAPJZ?L}`K1j+GAk&(VOub7u{(hzAIHbps@mSUK2=NnsgKIRS5JU0Uv(J;@&R@C@ zr_j3ZQi&0xeIy0BhwF*lzVL8ROje?LsH8!&e!frk83v+Z*t6LuaZo#ETCbgGA^}y{ z?#)--LRf0$URc}iir;pm+@VF}>l4%BIL(&rt6nNu_W+K?s#%Z2tW@AOGQ?^%Cm?PV zpmw@SC+5JpFzRS`i&x~0{Gy%@I&@_Z@+%wrGaA1*?>+4cFklhKjznB)FIibt0G$7q`P=$DjgJHJe~2AAXl#iAJCsvFvVvsx$UBJEq7 zj?A9~WeKB~N>*RkBs{upegPSPu@0kh+dtbj+!T8Da@0c6@dosac*0FD%a=`2_2t`0`_h*ICBBGTK8?r&&Dd4K9( zvlx9((n_`C`OV1E4JY^pmreiryldTsYXO)Ad*Jb!Dd9KIRw^$eceM#jQxtpI_paEb zdJP({f$o0*N?-;GvJv5)KR@m$52YX=9v+8Ve^Yo_Fv)vvSf`=Td)K6(aO_Yq5DQey z8_ELzQ+}jPY)ulZAICp>8?wnKqA88?Q2!zw5i&Etkzam| zS2lQJZ6)F|=05r#0<`!tWVJrw^OL=NGd~gEx1Ad%-KB6mB+3lzjjVGhW~+F|YS#Nl zB-xYB5k^0X1RtO_{h$}ik!4q~5+J5gfc-``PVP9??L#ckmuy}Pvrb7mBLj?P&QfxW zZ$q!;o_a8>6eNFwqhzlIOSeJs(27^y*@SgfbL2$la5u@_}trCxhUbJF-kA%%wLN0h)PN~(dO6=_nw=C6h0jc%py`(` zOy*nu?FDPLRc`>-5S6T+-uJBs8Q(e!M?{z#@w36jOJ(nJ(+y?HuQc_@n2FEkO|d}l zu_?VtS^7HvS&33+_W!;qHyjw8(M`avruUOAUVs3UtZ$_8F|+CdGQ1MyY1!q z${k6`JLP|37F;lj`Zb_*@4vhN5-3YNy-lH0=i~ss9%jd+B$vrg4|!}P?(Jxt9jPkx zM)K-MwJ?B_BA(B3P0=Qh_r7WhLI=6o_NG{sZ5A!$FVP*HCE0Mn**l-c-g4j_ir|`)rKD zoNQZ!J?KiQd%LDRk>Lbkq;O>zlt6XFDGvC;5{$ z^XmSbv;uJmQieo|=--Mc^8a2DEoUCb0UE@n_Ey=5r0Rd;Q}Gj(>8sZRUF&@XmC*YZ zM)6(r#W>sK4l-%I>{jsKI%HT5$uu*d@pko2bnF(<&^tX2>P%Csm^^=uCTW1dtVBuh zFdU>_cD@r6^M&cY>bW_(e3FgRLta=9DQz52c1s*k)w?Rs>QrGh{|S?6CNbB6E?`66 zVak`9L9^Ur>i#$kBSk0bh+it%w9dH4{6pq1p-i7YwW6nf20yf;d?7|2ytq{O$zuNR&B%*cMD2G+w+7M7#iuiC2D6`Sgqt*H*cEVWOBo@nN|FEJE8i)n)q7 zv`~xlchVQ<^~4Khjc8B?h3w|UgJoBdx!Zhuqwne6^v?={}Cu_XY*gWLfTN>@f zcKpW>5m4n{NSga}Ob_Jzu}BeA;MVh}O97%wsky_VVjwuYX{OxD53dd|4}4=(DUjoD zGkIBgI2H-d47qN$)vJSfN`)lP;Att1p)D_W@A}F^=P8tP@q_XkE z_~vn(@SH{9bd3lg2Ls13XbQqNQr;8jnTQ*h+SA5;>vjF?oulAs@cC>&6tQx7SK%zz z9;8s?AU%lnhXb|;?aSsMw{U5O6*sb#u+p9(A}@a)=cOp;5qIBu2aHH=hG&r_w5$Ri zAoEbgOnJmFfi;mAK%U^$b=efuEs$Fpp^We z)l2_L&_9O(x$E9ru{rAZ{Eb)H)C~m$ubQ~Rc2xM(}b6NLeS_0h{sz8G7{TIso|Lj2{ z3G8c#G|3sUdl^?Z$=(|)N55uZ*MJ~-X0fK3MTxBodiscOZP=nJ1Bc^X2G?|3*Ig;7pyQx~a zd4P|EvuIGxPAzm*6uJ_`81{I7Kc(BUk~{%8ZlN)ZRVdZF&J(e>5VX=>ep&j5W06L& zUcD`L`uQI-FAi>UAZT=4^vkt%FK268D6E)5IU~61N-t)3#q-C?E$#mKXDeBxIypw;a+?idYP99LpXm)`hm$CaRaN% zYdT?|n$%s4j;{&s`A(1~{9p zlhGXLR$N3;UN*8++3=B+#z+@t_-JLLD z4p_gh>2pESth_JYJ;B6rA;JL_EIrD(urisJ6Edev)5N4fN- z{2lt(Yd=V!F5Mv$S!sck3c;y+w?*}@Dm`X(zW=BlqII#H#wFgGnp8*T#+w93D3}f@ zrKcWu%1*cbW???-H7Liz^_ixFdgC+X+o=YK@?Q!(-huU9{uZdy6PxEsbLv*Di!o|U z?C;SW$D{Yvpy{BqN1cTknW>)HfSr^35YK|o$GMhxjw0@@ts<4?Zz5I_TGxb(zT+GB zffoN6QAu@T9F&q~Jt^|J9{A%VQxqb(;%t4gkZ%Vsa?e@&%I)%sn*kAj@thr*Zph+w@^3tod%>)Fw}#l7G5P>xc!*tHwCbq){Ocv%i>ejRunVSu z(FsQQ9WJP90%@D|Y~bh#pF{z)+}0ndLC%HLb%urgH7=S2cY|cV(L$}h%A-0xszE7P zd-%tld-yD#&TeBeyd~hofy!_A|9IZ2P7)`?vKuL`3PUU#@T{#ct3EqmND-&Ugj9((S~Wi(P{WZ!)z?-JnsJE=B!H3*escbjbz z6YcdNL z6?8QO*KC~#1PfK{DckEhP0rCxmVY)R_b<@w2V>84^gUnUH6hzF;Q6YgN!#f|O^aCN z{c`X)W37b^< z;A+cN1E<`=f?_DD0?O2xcXHWU_zfPYG%3D|Vx3onBkI5r9vfKqO5H!8BQ#L}=)4g~*0uWu$w5 z=wzZ)qm~zV-G`m?cEZ?dchx`QswOW+@A^8}U0nG8LaoyS>t|)~$#PmF!@!2Y<^A6% zLri=Q*`H`Vl9pPZ?o`CMudfaKkQW?|L1$Y4ylM zY$yLr``*`x$(D49d)hR%76zMMd>QBB?~qQG3a1wXq^OP-Q=4lavJ$O!OKgM(nwDT( z>lMCi&kev2Zd?=&YWM7z7|$i4#00^{mB9c|ExMTZ0x^Z@ceYor#VHd@P|+Sv52nH@kFLs* z!)SBa&q}E01tLz?^4Dp4nFD9U4)P8IH(kb}(AUzHc{$gXZz8fR< zkJ3+ap8DPnASqBM0-Kx7F?v#sH%Ne=mm)&yhgy`WcB@R!xSJ?42^Pr;;VAE=p;-2Bi z4xJ=OON*RoBuhqV8n3{21``h5r<4{igZ! z4!9ABl z<=#2%8w?qJ1?n^L^q=Cb>WP}3s71WwP5A7S)p0u3u&a%sM1@1jIh$CNKo8uYrgoGID^Z^#Og_}~+F3{-0r;bn za~RwtU}fRTquV@D=z`{+VOifgz__dll5gWUaMh@BAQ>;`wXFSx* z{~VSZ52*VP=-L1BUOB{2kP9h1wZQQ$h2g%eTf9RV3In^&J9n<3Qs8+O7x;vG@b658 z56FejEj$?>3pZOdEj@C>YiuBy$crq$I8FG{4v-)@US3)!JNbItupA=_JLrY`nGD~2 zE(Jp(bSMgVoN6V4?}hKz_A}dPotPf{%Mx6xd&1NFf_@T#ScS8HL&QuCB5eC>5iOXd zfIlTw^t@s1^j$K1`LAxLKhZu_a5!+f02mFV+9YXzKs~GU&asv=Axzo%fJun-aY`w^ z8+y;Kl=&}Dn1qWI(b?-0-~)u+Tx`2YCmGYd=S{6xfJ4qiLH+|~6LF0z_sfyfD&+oO zPe{g-&eW{mr(;&%@z(5B62XlO+39;88+kGOi>oD{I1moEIcHW@<%~VHbhh$-oNH6pW3NaB>>DoSpJW- zf&&67@~GHDJ~k9$5iFMrqCaM_HQ}1FM()k{PeQ0o)4(=2B?>x+AixcF*Sm> z4~yhjWHXlSNo2RaIL4p#WAoJoaf0@js_q9)dZP@qyz89Y^^P3F3M=bG&D$kZvO-g6tEe&as;kq|qF70eU7}ekbnv=W*K#HY+ym!qL zw$GR*B_Gbp{aK1OdeZgo2l+jtM`DC}?#K#_r5bBYX1(qoSl>=JTe)8V4YS zO%GeqQ&_g*n2Rb+-^iN|qnq{Q-Q3hRZzMlnePHh}tNY&bD61{+M=*0C zHR=?ZdT!-{Qo<5MD#II=NzwCp_-Vj46k6l&Dt&i?c(itG{(t67aPUFH$C)hrF?SN@ z&cofh%43cXz{iX7{fEn5;r&Mc;)_sV_=cT;m=NH;kTO<_QTx9Q^Z)6_kdppge&c60 zp5mak_=-Rv_)UawtF*OMJj@!i7IoYeBd#*;B41eHz?L z_8u{~1ie^QGyhS5u=eYVAb#yP9go&XeA2H@A6mTQJPGf*{Z6>lbCY!4b`*?A*iY#J z$8s9{37(6x#!4s|4y;dN&t-_YI(R0{AT%US%2?A*5bv9K&@j|Qyn4{PZrQOp()rWx zhk5!V-=2Hr$O0+AhKFA|W2%v{L7@BWAw~4W>r9w*%+CRi&Xg3*W|DEa8{NpjxnA!S z2?fAQGmHD`QiOEXp5j+7NRBbfjm>KN3gj16<^bWLOYU(nmCjsx4itLhTdS(#eAR-k zo=@Da4kq|Bqq`4A6-qO{wY{PfEmWiF5Fzto7V&_-`7wMkgDMca91i=TBM#lLmlPQS z*`KElwIY65wFhvG+1P9WOPDiS`PE1g$l1t$-u|z?o*MX){!^y+hoUC>;vuR(75vhW z8%hHY9DT`5syqCN?$^Ux^bQymW|Wv_SexB}*FL#VFUi4FxAb4G3*EWvDn?9q(?W@X zhS016#`3EIbEL+fnDJ1)L3i3FG**_>&Pu7RTyhs_`eN}my7Dk*PFSD@d*h2@Rl^e(QWc;+wV0^1rXVzML9gfaoid&S%zgtF ztX7uM{XO}+ulskX`M#7q_8TlIR=}IQH*me{g9kVbKQ$0{&*1C|fbVHGQvazUDo?TS zpwN|s4y&j5L~DJu5Rvi2dZrG zvOpU;eZjp-VCijyLf-yD+U6c1-}rYc?3FU?CQl82V)tR{pDa7Ph^hVL?Jwr$HRXU0 zVuWWglliaHv19A{E)!()SCsEHmGi&u{6)sAjMPi#?6~*S4JWnF6$8*faQ;i^_IerBAnQ^yfuQRhZQolk$<`Nh*xMyUFAAM41zBD42Gb|z%pbgL~n)Z&5kR| zxf>oUZw4njL-bt+Mi*^Ng`MT5pAawS%`7-DUtN-((G|GWw$9h!(`lEtF-PW4t=1W! zTHlihympcp`G;?lJbUt2+pc_x%TYw*jKb@_u0d3po^5~@GNizZa%W17+FjAiPIy*t z_6G2-6oLR9?-BFJpl=e_^+sU0-T+O zv$T2F`{bdU{^S!M4G}gM;93^U#acGFZ{#_3Fo}KeE(@o~Q_K76 zz)>;y3~9tZTuinF0^ILok4p#}k~PE^Nkt1<{06S-44K-p-wcN8nzYXi$SmG}yytq> zyRO-58QjwqBobK9X)t>$pAe0!#wz=eLm-U$OAwBEw#(N6V}^YVV&hvWI`}Lq-}0hi zy$muy9jfKIl1J>r?d2t)9_u`PX1m<{jnGt%m7E1u4DgQ;nYtP)Lb4d! z=5{}+7xED27&0L43b+96qMtR?K+I$3)XavzJ8MSgbEkP^@2>2RP_}&G6sYWB{Gjn> z*Os7za2FHz(%Ouo#IEAQDEF7_PK4VlD`MV$iOj#{X`u0-WKU2Gm1{A8<7vN+x{0TY%1 z%QbcnT@1gyDD7#eCE<`#^TETsYV47h=ndx8eMbrz=)S!8pqp%Rh#R)?GIalK^5EL? zrG^CvZ}5Ack7*CtuSm~2Mb}33>GNuB&c+WX$*S$A{Mx>)W=wPIEZuMr#$g7z&m~^t zp6j#hzDG9O)c3R5qiG2)*;5SD`Bvvj5t8ZoW=BH{jRUM^2uNMz9Y*UeJ@_7Dy&6gL z&FRGzMH~I}M#|2|lVNdbWi`%t=yRSz(AV+(Eb5_X_$3~{)J(3lI_fc<3gmt7^>>|g~%BUv7Wzt z*#O@wY!d5a`qe!a66?6HyHOJ>)@&zriMUBzY z06)S(x98A6xc1J=IU@h@=ZNQx*A)+?rj+-RS9uU?E!z~}?rFq9MaW^%phxo!VriPL z@5Jlr-v-GH@V}1H|9$@~P$e@;>;xqHLEIz~o|UJDG5b7!f@;A-Da~jM&OEYyW*}Jq z)(`=tF3Vb>QfKU9=i#IH+1}+9tT#k4XS=rtQ@xxkm%n|f88R4{ve_s#OS;*gJQ5W^ z?y#}*aW_PC>kRw=-1rjhFa0d5D$_H+g*8MG=^#1|JI%Q+y5Iz2U#LY@IGJf4ebSS9 zC($sIY@w#c(JUug+0eR`H_6d?B(E_3xanFbBGp2QV}opUl!MDca_$w5HpgEIS#K0; zTN{ymC_?Z^SkSq4WiJ<3;Sbr-+A!Lt<=s|lHN>7!YgaR}pQ6mdhZ!iDn!FdjDj=WN z9OV#Np&FemwjKe#|4q<}A?rQ7`znCwd z)5Gn80X6!Yo8zj7i(@?Z*;jE?m{_h4_8VJ|fXmfH*qtTOz6)AYw?{B8!2UXg|J|Nd z06o@UtVV}?^~Zi-BO}sNtTVM!SiM>U<2(ScVI01QxK4EWJftzjblN;bMWQ7_@O_H| z7js#(8RELig~GBh$Z}eKp1$NXe8SC#fOgFPp7Ff%AmTmatwXCNFz>P9r2vXZm3z?g zm^-kaXyb#r#ow^|*g13Yx;O#(B0>XhEvu%G2uSG-|3E(btU!YdJ^Od(o)7^LOl1$V zyP+S2dBzdo>6X~(L zZJ=V6Bf*%&O!KFL#`gk7i=a^aVGSQmNfMHZ0cZ6fr-ty*?{7S&b9*1;uBCA;C`_Dm z8?v(s9{iF<)tR;mYX)ZF3)d1dI@1^0NfaC&)xt%F4J@g{*Ymv3?8n__0I_)~v$%`0 zXuRRI=XCe5^SGnI(zU~|JlnjjCojpTHozznn~{=SShaD~C&84R_Ft&(zic5^-^1x! zY>tcpBeQ<5~n)DYz3oJheM11S*#%+7!$C z7^86twN8dJrzvrMB2sjyk|OKPFNaoiwXdf~Brm4*i_fVZt;}d{8+nJz0*O?f&Uve% zPeh@k_0SDi7wOjV2^+2`wO zJyRNdpFI7p3s;jrK}_td{$zB-U%mu3O;kKEtaf@4(0lDJ#s!4}b3z~{3-jTsR1utl zUqeVFOvadTs^8dvodO@p$0kTJ-VXq$ogdS1RYtf(RC97A&nr%RmSP_fo*{WB9X4#65S+Q@ zC;T;{L{759q6%<04#HJXJ+396$vpqFS;wAcy7$HzQ{g`~bdqnC3LRXkp(%r$g^;gk zfo?4lq+$^4H;F+mJh&S~jT?e`pfkK3{otWm)MQ`7)zeJlihw7RB~-jQJ;pO%+Sm3_ zCq>v$R-{IXU(+L*MSzYUT}w-f#vM$Gh87cPoxMv;Y;eZO{`|g0jZ5T}1G?mro6X15 z|86f2XJe3(S>Y?-`x68*@&1)A06IIC1xn}4&kPvl=1)^NZFezLJkj_0ja0d?AOA-y z=gHtI0Dn@s0<+LFUJCPI;`(q^a*9h|k+2aC+2?WWDR>;6*!G6bu)WdeJAnzdHP|GC+z)F=B`#^7SMToUv*(+XyOG`>|~XitC`ZkDDpUf>(4N9W^qfNzl0a=8lOexrEF zt^#K)$^&mb+QyF0=~ZmncB~#f`j44g9ZI#i+twU*@8e?=nZBcVGSJr?=Q{IU(&Bz# zk5Ib#ko!^|&W~PR=h&5Il97at0Ir1KKyj6uj*_ZV^F$XN;wHt$G&|mxx8nRfnvm4l zh1ku;D}JXq&A}5wbxD%s7U=20bn^GlTbMg^Tk8blZw96VF%f80oLQ#uj|0xpBLZrk zI5BAij025OZ6xf4r{{Q0{@)#wdW4056ON>9w>M~RzgzH70Rjff)e*o{m${+j-@2dY z#AfXE->&NO&$Q864ZU*J?x!-%axtW$RnpsxB2EsxSLfT2c7$4)3RSe@r3+cKcA7qu zl)3v6FGk#{YJQyHmBCjVBe-c-CKY;4R!n9d{C}Gwr)JCASQ~rc?%cl@n(B9-c`3FB zJOi-iHmkSG7W+A7j5p3CPx+BtrKj4Gobly`{HN!NpJ0P!om_>_KKKZC2_4wy*A^U= z1S)c8f12B<^=#Fq7?mu6`ECo{{+8YP|7Pl8#%GJKl>NC;B6vG6^4Z6m(xBxTU3#Ib zfGe&)dxKV7H~PKd-z|4vH!(Zt?cK11U3zAh9bBKEIJls`sWUY(c<+;+pN~I(0qjcG z{av%XQQ-J#qq|>ag6HKbUr5faSy_3>#r9C{f=6E;0|yFA4Eb-YdGYK1n)w#n&Y8ZM zCu+@h(G0Sq=-Iq;{DOhCkZs}H_x=6ne7(72-kv7Uyv`1}6IojiO^>g;xuWOk`ZQqC zzUa5W*`W7{CFc^lI_Al-h4{z0c})PVwm$xBrqj7u|8meD@)KWE4?j+tqeV&mgP&1 z-G5AYd|4as`m;LQ{c$Ot{Nh&eUBxYH7rAIpy<|K=vKhFlcpZ27j=gH2kVsZzf{qKU zD!aC|V3MdQu#Y{duY1jmlfX4|zc)mu`8fc`PF=oObT+)&!prG>XWFq~yJOF_LcYp8 zK9dSw4U-qQL*?50+qyH}vB(?-7Hls5j&C&g&k0*T>knvFSDR+aytv>C z@AF%33re<6zt~m~D=e`x;HQQHNR{C0OyN0=T)@?&)3|N7IefDTN&KD=_j(d&?g+G6 zEl_xhSxfe|gzur-yg;6v{OQ(l`8_eUuW!G9zdr@I%;Z(V#q{lRKq=Yfz`bJn`~PeT zlsp}OHpqDC`^omlc3Rm*d<1$2xbzgfY^@`y?#p8NtG}!dfcI==cw1FyaV=wjq?DP9 z6jtfXV1gtC)jv+_0v^CK8(;a1(H!u&w-|_FJO1uLeJmX b{GY2VAmMAck7XS2Od$qOS3j3^P6Naama: Should we also include instructions for doing this in the services console? I can write that up. + +1. Open an elevated command-line prompt on the endpoint: + + a. Click **Start** and type **cmd**. + + b. Right-click **Command prompt** and select **Run as administrator**. + + ![Window Start menu pointing to Run as administrator](images/run-as-admin.png) + +2. Type **```sc config diagtrack start=auto```** and press the **Enter** key. + +3. You will receive a success message. Confirm the change by typing **```sc qc query diagtrack```** and press the **Enter** key. + +4. Now attempt to [onboard the endpoint](onboard-configure-windows-defender-advanced-threat-protection.md#onboard-endpoints-and-set-up-the-windows-defender-atp-user-access). + +For more information about the telemetry service used in Windows 10, see **Manage your telemetry settings** at the [Configure telemetry and other settings in your organization](https://technet.microsoft.com/itpro/windows/manage/disconnect-your-organization-from-microsoft#bkmk-utc) topic. ## Configure proxy and Internet connectivity -The endpoints must be able to connect to the Internet and send their data outside of your organization’s network. You might need to set additional proxy configurations to ensure endpoints can report correctly. +The endpoints must be able to connect to the Internet and send their data outside of your organization's network. You might need to set additional proxy configurations to ensure endpoints can report correctly. + +If endpoints in your network use manual or specific proxy configurations to connect to the Internet, you may need to configure the Windows telemetry service on the endpoint to recognise your customized proxy configurations. + +You can use GP to make the changes for a large number of endpoints (or across your entire organization), or make manual registry changes if you just need to configure a few endpoints individually. + +**Use GP to configure the proxy with the Windows telemetry service:** 1. Open the [Group Policy Management Console](https://technet.microsoft.com/en-us/library/cc731212.aspx), right-click the GPO you want to configure, and click **Edit**. @@ -69,8 +132,36 @@ The endpoints must be able to connect to the Internet and send their data outsid 4. Click **Windows components** and then **Data Collection and Preview Builds**. 5. Click **Configure connected user experiences and telemetry** and then - configure the GP. The GP accepts a string in the following format: - ```:``` + configure the GP. The GP accepts a string in the format ```:```. + +**Make changes to the registry to configure the proxy with the Windows telemetry service:** + +1. Open your preferred registry editing tool. You can use Windows Registry Editor by opening the **Start menu**, typing **regedit** and pressing **Enter**. + +2. Navigate to the **HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DataCollection** registry key. + +3. Right-click the key and click **New** and **String Value**. Type **TelemetryProxyServer* and press **Enter**. + +4. Double click the **TelemetryProxyServer** entry and enter the proxy server you want to allow in the format ```:```. Naama: Please confirm this is all correct. + +In some cases, you may need to configure your firewall to ensure the Windows Defender ATP service can connect to our processing servers. The URLs for the servers depend on the datacenter location you chose during service onboarding. + +If you chose the US as your datacenter, you will need to allow the following URLs: + +- https://us.vortex-win.data.microsoft.com/collect/v1 +- https://sevillegwcus.microsoft.com +- https://sevillegweus.microsoft.com +- https://psapp.microsoft.com/PSApp/SubmissionFEService + +If you chose the EU as your datacenter, you will need to allow the following URLs: + +- https://eu.vortex-win.data.microsoft.com/collect/v1 +- https://sevillegwweu.microsoft.com +- https://sevillegwneu.microsoft.com +- https://psappeu.microsoft.com/PSApp/SubmissionFEService + + + ## Review errors on endpoints with Event Viewer @@ -89,11 +180,70 @@ For example, if endpoints are not appearing in the **Machines view** list, you m 3. Events recorded by the service will appear in the log. See following table for a list of solutions to common errors. -Message | Action -:---|:--- -Windows Advanced Threat Protection Service failed to connect to server at `````` | Check the connection to the URL. See [Configure proxy and Internet connectivity](#configure-proxy-and-Internet-connectivity). - Windows Advanced Threat Protection Service failed to read onboarding parameters. Failure code: `````` | Check that GP settings are correct and there are not settings impacting permissions in the policy. -Windows Advanced Threat Protection Service failed to persist onboarding information. Failure code: `````` | Check that GP settings are correct and there are not settings impacting permissions in the policy. +Error ID|Message|Action +:---|:---|:--- +1|Windows Advanced Threat Protection service started (Version ``````).|Occurs during system start up, shut down, and during onbboarding.|Normal operating notification; no action required. +2|Windows Advanced Threat Protection service shutdown.|Occurs when the endpoint is shut down or offboarded.|Normal operating notification; no action required. +3|Windows Advanced Threat Protection service failed to start. Failure code: ``````|Service did not start.|Review other messages to determine possible cause and troubleshooting steps. +4|Windows Advanced Threat Protection service contacted the server at ``````.| = URL of the Windows Defender ATP processing servers. +This URL will match that seen in the Firewall or network activity.|Normal operating notification; no action required. +5|Windows Advanced Threat Protection service failed to connect to the server at ``````.| = URL of the Windows Defender ATP processing servers. +The service could not contact the external processing servers at that URL.|Check the connection to the URL. See [Configure proxy and Internet connectivity](#configure-proxy-and-Internet-connectivity). +6|Windows Advanced Threat Protection service is not onboarded and no onboarding parameters were found.|The endpoint did not onboard correctly and will not be reporting to the portal.|Onboarding must be run before starting the service. +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md). +7|Windows Advanced Threat Protection service failed to read the onboarding parameters. Failure code: ``````|The endpoint did not onboard correctly and will not be reporting to the portal.|Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +8|Windows Advanced Threat Protection service failed to clean its configuration. Failure code: ``````|The endpoint did not onboard correctly and will not be reporting to the portal.|Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +9|Windows Advanced Threat Protection service failed to change its start type. Failure code: ``````|The endpoint did not onboard correctly and will not be reporting to the portal.|Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +10|Windows Advanced Threat Protection service failed to persist the onboarding information. Failure code: ``````|The endpoint did not onboard correctly and will not be reporting to the portal.|Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +11|Windows Advanced Threat Protection service completed.|The endpoint onboarded correctly.|Normal operating notification; no action required. +It may take several hours for the endpoint to appear in the portal. +12|Windows Advanced Threat Protection failed to apply the default configuration.|Service was unable to apply configuration from the processing servers.|This is a server error and should resolve after a short period. +13| machine ID calculated: ``````|Normal operating process.|Normal operating notification; no action required. +14| cannot calculate machine ID. Failure code: `````` +|Internal error.|Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +15|Windows Advanced Threat Protection cannot start command channel with URL: ``````| = URL of the Windows Defender ATP processing servers. +The service could not contact the external processing servers at that URL.|Check the connection to the URL. See [Configure proxy and Internet connectivity](#configure-proxy-and-Internet-connectivity). +17|Windows Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: ``````|An error occurred with the Windows telemetry service.|[Ensure the telemetry service is enabled](#ensure-that-the-telemetry-and-diagnostics-service-is-enabled) +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +18|OOBE (Windows Welcome) is completed.|Service will only start after any Windows updates have finished installing. +Normal operating notification; no action required. +19|OOBE (Windows Welcome) has not yet completed.|Service will only start after any Windows updates have finished installing. +Normal operating notification; no action required. +If this error persists after a system restart, ensure all Windows updates have full installed. +20|Cannot wait for OOBE (Windows Welcome) to complete. Failure code: ``````|Internal error. +If this error persists after a system restart, ensure all Windows updates have full installed. +25|Windows Advanced Threat Protection service failed to reset health status in the registry, causing the onboarding process to fail. Failure code: ``````|The endpoint did not onboard correctly and will not be reporting to the portal.|Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +26|Windows Advanced Threat Protection service failed to set the onboarding status in the registry. Failure code: ``````|The endpoint did not onboard correctly. +It will report to the portal, however the service may not appear as registered in SCCM or the registry.|Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +27|Windows Advanced Threat Protection service failed to enable SENSE aware mode in Windows Defender. Onboarding process failed. Failure code: ``````|Normally, Windows Defender will enter a special passive state if another real-time antimalware product is running properly on the endpoint, and the endpoint is reporting to Windows Defender ATP.|Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +Ensure real-time antimalware protection is running properly. +28|Windows Advanced Threat Protection Connected User Experiences and Telemetry service registration failed. Failure code: ``````|An error occurred with the Windows telemetry service.|[Ensure the telemetry service is enabled](#ensure-that-the-telemetry-and-diagnostics-service-is-enabled) +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +29|Windows Advanced Threat Protection service failed to read the offboarding parameters. Failure code: ``````|Naama: Should I remove this error? Or just leave it as internal? +30|Windows Advanced Threat Protection service failed to disable SENSE aware mode in Windows Defender. Failure code: ``````|Normally, Windows Defender will enter a special passive state if another real-time antimalware product is running properly on the endpoint, and the endpoint is reporting to Windows Defender ATP.|Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +Ensure real-time antimalware protection is running properly. +31|Windows Advanced Threat Protection Connected User Experiences and Telemetry service unregistration failed. Failure code: ``````|An error occurred with the Windows telemetry service.|[Check for errors with the Windows telemetry service](#ensure-that-the-telemetry-and-diagnostics-service-is-enabled). +32|Windows Advanced Threat Protection service failed to request to stop itself after offboarding process. Failure code: ``````|Naama: Should I remove this error? Or just leave it as internal? +33|Windows Advanced Threat Protection service failed to persist SENSE GUID. Failure code: ``````|A unique identifier is used to represent each endpoint that is reporting to the portal. +If the identifier does not persist, the same machine might appear twice in the portal. +Check registry permissions on the endpoint to ensure the service can update the registry. +34|Windows Advanced Threat Protection service failed to add itself as a dependency on the Connected User Experiences and Telemetry service, causing onboarding process to fail. Failure code: ``````|An error occurred with the Windows telemetry service.|[Ensure the telemetry service is enabled](#ensure-that-the-telemetry-and-diagnostics-service-is-enabled) +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +35|Windows Advanced Threat Protection service failed to remove itself as a dependency on the Connected User Experiences and Telemetry service. Failure code: ``````|Naama: Should I remove this error? Or just leave it as internal? + ## Related topics