Hi Community Members,
One of our customers has been having issues with MDE for around 9 months now and wondered whether anyone had any ideas on what could be the root cause.
The issue manifests itself by way of Drive Encryption activations inasmuch as they simply stop completing. Then there will be numerous failures reported for various reasons - "No local domain users" being a common one but there are many different reasons.
The estate has around 13,000 managed endpoints with approx. 40% consisting of various models of laptops.
If the ePO server and Agent Handler are rebooted, the issue is resolved - at least for a day or two or sometimes longer. In the beginning, the issue would disappear for weeks at a time (after the reboots) but recently it has become necessary to reboot the ePO platform more and more frequently.
We have gathered the logs from the ePO server and are looking through them for clues but in the meantime, if any of you guys have any ideas or maybe have even experiecned similar symptoms, then it would be great to hear from you!
Cheers!
Hi Nick_B,
Thank you for choosing McAfee Support Community. Apologize for the delay in response.
Please let us know the below information
Drive Encryption Version on ePO:
Drive Encryption Version deployed to client system:
Client System OS(With Build Number):
Please also attach a screenshot of General and Log on tab of Drive Encryption policy along with MfeEpe.log located in C:\Program Files\McAfee\Endpoint Encryption Agent from one of the client machines so that we can provide with more information.
Was my reply helpful?If you find this post useful, Please give it a Kudos!
Please don't forget to select "Accept as a solution" in my reply and together we can help other members?
Regards
Avinash R
Data Protection
McAfee Employee
Hi @Nick_B ,
Just curious to know. Did you try to find a cause for this issue?
Was there any support tickets raised with McAfee for this?
Thank you.
Hi @jsubbura,
Thanks for reaching out.
We never raised a McAfee ticket for this but rather a colleague of mine investigated the issue in some depth and concluded that ePO was simply overloaded. As a result, the ASCI was adjusted to 120 mins from 60 which improved things a lot.
It is too early to say whether this has actually resolved the issue, however!
Thanks and be safe!
HI @Nick_B
Thank you for the update.
Yes if all the machines reach out to the EPO at the same time EPO would have to reject the other requests as it would be flooded with requests from the client machine.
it is always recommended to have different ASCI value for group of machines so that they will not communicate to the EPO at the same time.
Thank you again.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA