Forum Discussion

Braguzz's avatar
Braguzz
Brass Contributor
Jan 22, 2020

Problema with ATP and win10 1903 - 1909

I have ~1000 PC managed by sccm and onboarded in ATP.

 

Upgrading to 1903 PC starts to have 'Impaired communications' state.

Pcs have the same hardware and same software, and are configured in equivalent way.

 

The strange is that not all 1909 are in 'Impaired communications'. a little percentage are 'active'.

 

already tested with https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/fix-unhealthy-sensors

I use the proxy way, and no problem with test.

 

What could I try?

 

thanks,

Paolo

 

 

 

 

 

 

 

 
 

 

7 Replies

  • SamP_1993's avatar
    SamP_1993
    Copper Contributor
    please let me know if the solution was found for this issue.
    As its intermittent devices automatically go to active state without doing anything sometimes.

    Even if the proxy is whitelisted for https://winatp-gw-weu.microsoft.com/. Last HTTP error code: 0
    then too it gives this error for impaired communication
    • saravanan408's avatar
      saravanan408
      Copper Contributor

      SamP_1993 

       

      Hi you any solution for this issue we tried all things but still face this issue for 2019 servers.

  • Thomas Höhner's avatar
    Thomas Höhner
    Copper Contributor

     Hi Braguzz 

    did you check affected clients "sense" event log already?

    can you confirm messages on the affected clients like:

    Contacted server 8 times, all succeeded, URI: https://winatp-gw-weu.microsoft.com/.

     

    • Braguzz's avatar
      Braguzz
      Brass Contributor

      Sometimes log says:

      Server contacted 6 times; all failed operations, URI: https://winatp-gw-weu.microsoft.com/. Last HTTP error code: 0

       

      sometimes (same machine) it says:

      Server contacted 7 times; operation failed 6 times and completed 1 times. URI: https://winatp-gw-weu.microsoft.com/. Last HTTP error code: 0

       

      I also have some other 'Infomation log' including:

      The network connection is identified as normal. Windows Defender Advanced Threat Protection will contact the server every 300 seconds. Consumption connection: false, Internet available: true, free network available: true, the proxy is defined by GP: true.

       

       

      but WHY only 1903 and 1909???

      (in 1809 no errors in 'sense' logs)