SCEP not reporting to CM Console

Duchemin, Dominique 2,006 Reputation points
2023-03-06T17:45:11.81+00:00

Hello,

I have the following errors in EndpointProtectionAgent.log

Service startup notification received 3/6/2023 9:36:51 AM 5480 (0x1568) Endpoint is triggered by CCMTask Execute. 3/6/2023 9:36:51 AM 1968 (0x07B0) This machine is not a workstation, returning false for MDMIsExternallyManaged. 3/6/2023 9:36:51 AM 1968 (0x07B0) Not RS3+, this device is SCCM managed. 3/6/2023 9:36:51 AM 1968 (0x07B0) Endpoint protection workload is NOT migrated to Intune. SCCM will apply policy. 3/6/2023 9:36:51 AM 1968 (0x07B0) Failed to get EP event code under registry key SOFTWARE\Microsoft\CCM\EPAgent 3/6/2023 9:36:51 AM 1968 (0x07B0) Failed to get EP event message under registry key SOFTWARE\Microsoft\CCM\EPAgent 3/6/2023 9:36:51 AM 1968 (0x07B0) EP State and Error Code didn't get changed, skip resend state message. 3/6/2023 9:36:51 AM 1968 (0x07B0) Failed to get EP event code under registry key SOFTWARE\Microsoft\CCM\EPAgent 3/6/2023 9:36:51 AM 1968 (0x07B0) Failed to get EP event message under registry key SOFTWARE\Microsoft\CCM\EPAgent 3/6/2023 9:36:51 AM 1968 (0x07B0) State 1, error code 0 and detail message are not changed, skip updating registry value 3/6/2023 9:36:51 AM 1968 (0x07B0) Defender detected 3/6/2023 9:36:51 AM 1968 (0x07B0)

Where to look for more information?

The CM agent seems working fine.

SCEP is running on the Client.

The definition updates are up-to-date.

But there is no report on the CM Console

2023-03-06_9-43-07 VIDDEWEb01 - SCEP.pdf

There is the registry Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CCM\ExternalEventAgent which is missing...

I tried uninstalling the SCEP Agent rebooting the machine reinstalling and still the same issue...

Any idea?

Thanks,
Dom

Microsoft System Center
Microsoft System Center
A suite of Microsoft systems management products that offer solutions for managing datacenter resources, private clouds, and client devices.
829 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

10 additional answers

Sort by: Most helpful
  1. Duchemin, Dominique 2,006 Reputation points
    2023-03-20T23:35:09.0366667+00:00

    Hi @CherryZhang-MSFT

    I would like to provide also this information:

    I saw 4 registries for SCEP:

    User's image

    As I saw some machines with only #1 & #2

    Some other machines with only #1 #3 #4

    Some machines with #1 #2 #3 #4

    Which set of registries is correct?

    Should all machines have the 4 registries? Are they some registries coming only after certain actions ... infections... ?

    Thanks,

    Dom


  2. Duchemin, Dominique 2,006 Reputation points
    2023-04-01T03:45:16.35+00:00

    Hi @CherryZhang-MSFT

    I have now 3 collections

    I have my collections now

    2023-03-31_20-24-33 SCEP installed and onboarding status.png

    onbboarded

    not onboarded

    blank

    Why does this happened?

    1. I do not use onboarding why do I get onboarded machines?
    2. Between the onboarded and not onboarded what is the criteria to have them selected: Windows 2016, Windows 2019.?
    3. Is the onboarding set automatically in Windows Server 2016 and Windows Server 2019?
    4. How to do the offboarding of Windows Defender?
    5. For the machines having System Center Endpoint Protection (SCEP) + Policy deployed by Configuration Manager and Windows Defender "Onboarded" does any conflicts exist?
    6. Any precedence between the Policy deployed by Configuration Manager for SCEP and Windows Defender Onboarded policy?

    Thanks

    Dom

    0 comments No comments