Forum Discussion

viorel_popa's avatar
viorel_popa
Copper Contributor
Jan 06, 2023

misconfigured devices WDATP

Hello.

from a large number of computers protected by WDATP we also have some problems like: Misconfigured:

Health Status
Impaired communications- 20

---------------------------------------

Managed by    ConfigMgr 14
                                 Intune 1
                            Unknown 5
No sensor data-                  33

---------------------------------------

Managed by        ConfigMgr 1

                                  Intune 17
                              Unknown 15
No sensor data + Impaired communications 11

----------------------------------------------------

Managed by              Intune 11
                          Grand Total 64

How to proceed to solve this situation - what are the steps?

Thank you !!!

 

5 Replies

  • jbmartin6's avatar
    jbmartin6
    Iron Contributor
    Run the MDE Client analyzer and review the results. Support will ask you to do this anyway (https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/download-client-analyzer?view=o365-worldwide)

    We have a similar problem, I found that clients were dropping the registry configuration for telemetry services to use our proxy. Unknown why. But it seems that the client will still operate as 'impaired' without that setting. The main symptom was not getting process events, etc. from the client.
    • viorel_popa's avatar
      viorel_popa
      Copper Contributor
      I use Live Response Session where it's possible and all the others tools from security center
      and thank you so much
  • ambarishrh's avatar
    ambarishrh
    Iron Contributor

    viorel_popa Please check the steps given here https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/fix-unhealthy-sensors?view=o365-worldwide

    • viorel_popa's avatar
      viorel_popa
      Copper Contributor

      ambarishrh 

      yes, I know this link - only that the devices are in use, they are not reinstalled or renamed, they are all onboard and send a signal, only that they are not online all the time and I don't know how to proceed, I also have security center (microsoft) and SCCM

       

Resources