Some clients no longer check in for updates and the Symantec Endpoint Protection (SEP) services cannot be started on it. The SEP tray icon is also not displayed.
The SEP client may have been functioning correctly for a long period of time. Recently there was a network issue where the clients lost connectivity with the manager.
Serdef.dat corruption occurs when a new policy is being distributed and there is a network outage. The policy update on the client does not fully complete and this causes the client services to be disabled and fail to restart.
To verify policy, compare the policy information within the SEP Client User Interface (UI) with the policy within the SEPM.
To determine the policy in place on the client:
To determine the policy the group is set to:
A good sign of corruption is when these policy numbers do not match.
To resolve the issue:
The client will now use the serdef.dat backup file to connect with the SEP Manager and get the new policy/updates.