DLP agents not responding - EDPA service not running
search cancel

DLP agents not responding - EDPA service not running

book

Article ID: 395467

calendar_today

Updated On:

Products

Data Loss Prevention Data Loss Prevention Endpoint Discover Data Loss Prevention Endpoint Prevent Data Loss Prevention Endpoint Suite

Issue/Introduction

All of the agents are in the not reporting status.
And the EDPA service is stopped (and stops almost immediately after restart).
Yet the WDP service is running.

The agent was uinstalled and reinstalled, no change.
You see the following behavior:
When the account running the service is an admin account, the edpa service doesn’t start neither automatically nor manually.
When the account running the service is the user of the endpoint, the edpa service still doesn’t start automatically but start manually.

Cause

The SEP firewall was blocking the service.
The edpa.exe calls the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal registry key, this behavior triggers a SEP security policy and is blocked.

Resolution

The edpa.exe calling the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal registry key is a part of the Agent operation process and this is totally normal.
You must whitelist/exclude all DLP agent operations from your AV scans.

Exclude all DLP agent processes, drivers, and files from any AV scans following the guidance in KB 160045; Best Practice: DLP Endpoint Agents with Antivirus Protection.