Despite relevant agent tasks completing an agent's AD attributes is not updating or it is not changing agent groups.
DLP 16.1 and later
Checking the SymantecDLPEnforceConntector logs we observe the following error
SEVERE: Exception while getting dataReader for file <file name> in folder Account-storage/EnforceSlot-uuid/AGENT_STATUS_ATTRIBUTE.
com.symantec.dlp.storageandnotification.exceptions.RecoverableStorageSecurityException: Cannot decrypt file, no file encryption key found.
Delete all files under the \ProgramData\Symantec\DataLossPrevention\DetectionServer\Account-storage\EnforceSlot-uuid\AGENT_STATUS_ATTRIBUTE folder (Note: These are likely listed in the error present in the SymantecDLPEnforceConnector log file)
Restart the Symantec DLP Enforce Connector Service.
This error can also occur in other folders underneath the EnforceSlot-uuid/<folder>
This folders are referred to as topic folders and if a crypto key goes missing it can disrupt communication on this topic.