This concept provides information about the location of the Endpoint DLP logs on the endpoint device and various enrollment errors.
Use the following tips to troubleshooting Endpoint Data Lose Prevention issues:
Endpoint Data Loss Prevention Logs
The Endpoint DLP logs are stored at this location on the endpoint device:
%ProgramData%\\Cisco\\Cisco Secure Client\\EDLP\\logs
Pre-Enrollment Errors
Use the following table to troubleshoot errors encountered before you enroll:
| Error | Description | Condition |
|---|---|---|
| Cannot begin enrollment | Cannot begin enrollment. Contact your IT help desk for error information. | Occurs when there is a TPM error. |
| Device registration error | An issue with the Device Desktop occurred. Contact your IT help desk for assistance. | Occurs when Duo desktop is not installed, is not running, or is non-responsive. The user is asked to ensure that the app is running or contact IT help desk for assistance. |
| Server certification error | Error initiating enrollment | Client is unable to verify the proxy server certificate. |
Enrollment Errors
Use the following table to troubleshoot errors encountered as you enroll:
| Error | Description | Condition |
|---|---|---|
| Certification enrollment error | Occurs when the certificate does not install in the background during enrollment. The certificate is required for Endpoint DLP to work properly. | |
| No network connection | Occurs when the user doesn't have an active or working internet connection (wired or wireless). | |
| Missing Choice File | Occurs when the the choice file downloaded from the Secure Access dashboard is not pushed to the target device and is not available at the location C:\ProgramData\Cisco\Cisco Secure Client\EDLP\enrollment_choices | |
| Missing Identity (aka bootstrap or user) Certificate | Occurs when the identity certificate is not available on the device cert store. | |
| Expired Identity Certificate | Occurs when the identity certificate is not valid during and after enrollment. Expired certificates lead to enrollment failure or if certificate expires after enrollment then existing enrollment will be removed. | |
| Unsigned Identity Certificate | Occurs when the identity certificate is not signed by the same root CA uploaded into secure access dashboard and marked for EDLP. For more information, see Upload a Root CA. | |
| User Not Provisioned | Occurs when the user for which enrollment is failing is not provisioned in your secure access org. View Users Provisioned in Secure Access | |
| 401 error messages during enrollment | Contact your IT help desk. | Occurs when the client lacks sufficient authorization. |
| 56 error enrollment processing failed | Occurs when the root CA certificate is not uploaded and enabled for Endpoint DLP. | |
| Trusted Platform Module (TPM) is unavailable | Occurs when the TPM is unavailable. | |
| Expired or Invalid or Revoked Secure Access Certificate | Occurs when the secure access certificate is not valid during and after enrollment. Expired or revoked certificates will lead to deletion of enrollments. | |
| Timeouts | Occurs when the domains mentioned under the networking requirements are not allowed in your network firewall and that the destinations are not reachable. |
Post-Enrollment Errors
Use the following table to troubleshoot errors encountered after you enroll:
| Error | Description | Condition |
|---|---|---|
| Intelligence mode disabled | Cloud intelligence is unavailable during a network failure. | Unable to establish connections with the server. |
| Unable to see notifications | Notifications on event triggers are not seen on endpoint devices. |
Ensure system notifications are enabled or Focus mode is off. Additionally, ensure Pop up Notifications option is enabled in the applicable policies. |
| Network not allowed | Your organization requires you to be on an authorized network to log in. | Occurs when a private resource is not configured to allow Endpoint DLP. Also occurs when the destination is not a configured private resource, but rather is an IP address that was typed directly into an access rule. |
| User blocked explicitly | Location not allowed. Your organization requires you to use a different operating system. Contact your IT help desk. | Occurs when the user is blocked by a rule that denies access or when the user does not have permission to connect or access the resource. |
| Access protocol block | Location not allowed. Your organization requires you to use a different operating system. Contact your IT help desk. | User does not have permission to connect to the resource using the current protocol. |
| User location block | Location is not allowed. | Occurs when the user did not match any rule and is blocked by default or when the user is not allowed access to the application from their current location. |