ATP connectivity challenge HTTP Error 400

%3CLINGO-SUB%20id%3D%22lingo-sub-800920%22%20slang%3D%22en-US%22%3EATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-800920%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20I%20am%20trying%20to%20onboard%20an%20ATP%20client%20on%20Windows%2010%20using%20SCCM.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESCCM%20states%20the%20policy%20was%20applied%20correctly.%20The%20ATP%20service%20is%20running%2C%20the%20sense%20logs%20only%20contains%20warning%20and%20error%20messages%20stating%20the%20following%3A%3C%2FP%3E%0A%3CP%3EContacted%20server%2020%20times%2C%20failed%2014%20times%20and%20succeeded%206%20times.%20URI%3A%20%3CA%20href%3D%22https%3A%2F%2Fwinatp-gw-neu.microsoft.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwinatp-gw-neu.microsoft.com%2F%3C%2FA%3E.%20Last%20HTTP%20error%20code%3A%20400%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20ATP%20connectivity%20verifier%20states%20the%20client%20is%20onboarded%20along%20with%20HTTP%20code%20200%20success%20messages.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAny%20ideas%20what%20to%20check%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-829207%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-829207%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F116860%22%20target%3D%22_blank%22%3E%40kim%20oppalfens%3C%2FA%3E-%20exact%20same%20problem%20here...%3CBR%20%2F%3EWDATPConnectivityAnalyzer%20shows%20no%20errors%20at%20all%2C%20but%20the%20Eventlog%20shows%20Connection%20failed%20-%20error%20400.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-829216%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-829216%22%20slang%3D%22en-US%22%3EI've%20opened%20a%20support%20ticket%20and%20have%20had%20one%20session%20with%20a%20support%20engineer.%20No%20results%20so%20far.%20%3CBR%20%2F%3EIs%20your%20data%20in%20Europe%20by%20any%20chance%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-829223%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-829223%22%20slang%3D%22en-US%22%3EYes%2C%20we%20are%20in%20Europe%20as%20well.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-829235%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-829235%22%20slang%3D%22en-US%22%3EPlease%20keep%20me%20posted%20on%20progress.%20I'll%20do%20the%20same.%20I%20think%20I%20am%20going%20to%20try%20analyse%20the%20network%20traffic%20involved%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-831206%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-831206%22%20slang%3D%22en-US%22%3EUpgraded%20one%20of%20the%20machines%20involved%20to%20Windows%2010%201903%20without%20result.%3CBR%20%2F%3EAre%20all%20of%20your%20machines%20affected%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-853356%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-853356%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F116860%22%20target%3D%22_blank%22%3E%40kim%20oppalfens%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESame%20issue%20here%2C%20I%20get%20lots%20of%20the%20following%20errors%20in%20the%20SENSE%20event%20logs.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EContacted%20server%2058%20times%2C%20all%20failed%2C%20URI%3A%20%3CA%20href%3D%22https%3A%2F%2Fwinatp-gw-eus.microsoft.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwinatp-gw-eus.microsoft.com%2F%3C%2FA%3E.%20Last%20HTTP%20error%20code%3A%20400%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHave%20you%20had%20any%20luck%20from%20support%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-853360%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-853360%22%20slang%3D%22en-US%22%3E%3CP%3EMy%20issue%20was%20resolved%20by%20offboarding%20from%20a%20different%20tenant%20and%20onboard%20subsequently.%3C%2FP%3E%0A%3CP%3EEven%20if%20you%20reset%20the%20device%2C%20if%20it%20has%20been%20part%20of%20a%20previous%20poc%20on%20atp%20the%20onboarding%20will%20fail.%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F45785%22%20target%3D%22_blank%22%3E%40Mark%20Aldridge%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-853383%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-853383%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F116860%22%20target%3D%22_blank%22%3E%40kim%20oppalfens%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eand%20if%20we%20can't%20remember%20the%20tenant%20that%20we%20used%20before%20to%20login%20and%20get%20the%20offboarding%20script%20I%20assume%20there%20is%20nothing%20else%20we%20can%20do%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-853431%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-853431%22%20slang%3D%22en-US%22%3E%3CP%3ESupport%20was%20looking%20at%20creating%20an%20offboarding%20script%20based%20on%20data%20found%20in%20the%20registry.%20There%20wasn't%20an%20easy%20way%20to%20create%20that%20ourselves.%20I%20managed%20to%20find%20my%20tenant%20back%20and%20eventhough%20it%20had%20long%20expired%20I%20could%20still%20log%20into%20it%20and%20download%20an%20offboarding%20script.%20If%20you%20still%20know%20what%20mailbox%20the%20poc%20was%20requested%20in%20you%20might%20find%20the%20mail%20with%20your%20login.%20It%20should%20contain%20this%20string%20%3CSPAN%20style%3D%22font-size%3A%2011.0pt%3B%20font-family%3A%20'Segoe%20UI'%2Csans-serif%3B%22%3E%3CA%3EAnalyst%40Windows%3C%2FA%3E.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20style%3D%22font-size%3A%2011.0pt%3B%20font-family%3A%20'Segoe%20UI'%2Csans-serif%3B%22%3EGood%20luck%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F45785%22%20target%3D%22_blank%22%3E%40Mark%20Aldridge%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-918386%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-918386%22%20slang%3D%22en-US%22%3E%3CP%3EFor%20anyone%20else%20having%20a%20similar%20problem%20you%20can%20use%20the%26nbsp%3BMDATPClientAnalyzer%20tool%20at%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fmicrosoft-defender-atp%2Fconfigure-proxy-internet%23verify-client-connectivity-to-microsoft-defender-atp-service-urls%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fmicrosoft-defender-atp%2Fconfigure-proxy-internet%23verify-client-connectivity-to-microsoft-defender-atp-service-urls%3C%2FA%3E%3C%2FP%3E%3CP%3EIt%20finds%20the%20issue%20I%20was%20having%20and%20that%20I%20need%20to%20off-board%20my%20device%20from%20my%20previous%20Azure%20Tenant.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F138372iE353DEEE6BAD73CB%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-919445%22%20slang%3D%22en-US%22%3ERe%3A%20ATP%20connectivity%20challenge%20HTTP%20Error%20400%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-919445%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F116860%22%20target%3D%22_blank%22%3E%40kim%20oppalfens%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheck%20your%20proxy%20and%20firewall.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
MVP

Hi, I am trying to onboard an ATP client on Windows 10 using SCCM.

 

SCCM states the policy was applied correctly. The ATP service is running, the sense logs only contains warning and error messages stating the following:

Contacted server 20 times, failed 14 times and succeeded 6 times. URI: https://winatp-gw-neu.microsoft.com/. Last HTTP error code: 400

 

The ATP connectivity verifier states the client is onboarded along with HTTP code 200 success messages.

 

Any ideas what to check?

11 Replies
Highlighted

@kim oppalfens- exact same problem here...
WDATPConnectivityAnalyzer shows no errors at all, but the Eventlog shows Connection failed - error 400.

 

Highlighted
I've opened a support ticket and have had one session with a support engineer. No results so far.
Is your data in Europe by any chance?
Highlighted
Yes, we are in Europe as well.
Highlighted
Please keep me posted on progress. I'll do the same. I think I am going to try analyse the network traffic involved
Highlighted
Upgraded one of the machines involved to Windows 10 1903 without result.
Are all of your machines affected?
Highlighted

@kim oppalfens 

 

Same issue here, I get lots of the following errors in the SENSE event logs.

 

Contacted server 58 times, all failed, URI: https://winatp-gw-eus.microsoft.com/. Last HTTP error code: 400

 

Have you had any luck from support?

Highlighted

My issue was resolved by offboarding from a different tenant and onboard subsequently.

Even if you reset the device, if it has been part of a previous poc on atp the onboarding will fail.

@Mark Aldridge 

Highlighted

@kim oppalfens 

and if we can't remember the tenant that we used before to login and get the offboarding script I assume there is nothing else we can do?

Highlighted

Support was looking at creating an offboarding script based on data found in the registry. There wasn't an easy way to create that ourselves. I managed to find my tenant back and eventhough it had long expired I could still log into it and download an offboarding script. If you still know what mailbox the poc was requested in you might find the mail with your login. It should contain this string Analyst@Windows.

 

Good luck

@Mark Aldridge 

Highlighted

For anyone else having a similar problem you can use the MDATPClientAnalyzer tool at

https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/configure...

It finds the issue I was having and that I need to off-board my device from my previous Azure Tenant.

clipboard_image_0.png

 

 

Highlighted

@kim oppalfens 

Check your proxy and firewall.