While configuring the Threat Defense for Active Directory [TDAD] unable to add an Active Directory Getaway [ADG] agent
Symantec Endpoint Security Complete managed Symantec Endpoint Protection 14.3 RU6 client and Symantec Data Center Security Server Agent [DCS]
From ProcMon shows that the PCHSetupRunner.exe cannot find the ccLib.dll. it looks like the DCS agent provides its isolate.ini that conflicts with SEP isolate.ini according to the paths that ccLib.dll is looking for.
This issue is fixed in 14.3 RU9 released on 17th June 2024
Workaround used before the release of the fix
Copy C:\ProgramData\Symantec\Symantec Endpoint Protection\14.3.8268.5000.105\isolate.ini and C:\Program Files\Symantec\Symantec Endpoint Protection\14.3.x.x.x\Bin64\ccLib.dll to C:\Windows\system32
Note: Once the ADG is configured successfully delete the files isolate.ini and ccLib.dll copied to C:\Windows\system32