Defender not updating - ValidateMapsConnection failed to establish a connection to MAPS

Copper Contributor

Microsoft Defender is not updating. When I click "Check for updates" in the window "Windows Security / Virus & threat protection" under "Virus & threat protection updates",  Defender searches for updates forever but also immediately shows me the message "Security intelligence is up to date.". Problem is that's not true an this message appears even if my definitions ar weeks old. 

 

I ran 

MpCmdRun.exe -ValidateMapsConnection

as documented on https://learn.microsoft.com/de-de/microsoft-365/security/defender-endpoint/command-line-arguments-mi...

 ValidateMapsConnection failed to establish a connection to MAPS (hr=80070057 httpcode=451) CmdTool: Failed with hr = 0x80070057. Check C:\Users\<USERNAME>\AppData\Local\Temp\MpCmdRun.log for more information

 

the logfile looks like this:

MpEnsureProcessMitigationPolicy: hr = 0x1 ValidateMapsConnection ValidateMapsConnection failed to establish a connection to MAPS (hr=80070057 httpcode=451) MpCmdRun.exe: hr = 0x80070057.

 

I already tried the following steps without success:

Any solutions? Is there a way I can do a ping to find out if I can connect to the update-server? 

 

5 Replies

@baumwe Based on the error code you get (httpcode=451), it looks like the URL’s here are being SSL inspected by your Proxy/Firewall.
If you think that these URL's above are already excluded from SSL inspection, I suggest to open a support ticket

Thank you @Heike Ritter, I will verify that an post here again when I know more.

I could check now. Other computers behind the same Firewall are working smoothly. The error occours only on one computer. I completely deactivated the software firewall on that computer but that didn't help.
If this is really just one device, you will need to do more troubleshooting or contact our support. Did you have a look at the docs page will lots of troubleshooting scnearios? https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/troubleshoot-onboarding?v...

@baumwe 

We had a similar issue. This fixed it for us:
https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-proxy-internet?...

 

Specifically this bit:
"If you are using static proxy setting on devices that are otherwise completely offline, meaning the operating system is unable to connect for the online certificate revocation list or Windows Update, then it is required to add the additional registry setting SSLOptions with a dword value of 0. Parent registry path location for "SSLOptions" is "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" "