# Endpoint-security State changed to DEGRADED: Protecting with policy

**URL:** <https://discuss.elastic.co/t/endpoint-security-state-changed-to-degraded-protecting-with-policy/281308>\
**Category:** Endpoint Security\
**Created:** [August 13, 2021, 7:40am UTC](https://discuss.elastic.co/t/endpoint-security-state-changed-to-degraded-protecting-with-policy/281308 "2021-08-13T07:40:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexey\_Shalin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexey_shalin/32/77531_2.png) [@Alexey\_Shalin](https://discuss.elastic.co/u/Alexey_Shalin)\
**Post date:** [August 13, 2021, 7:40am UTC](https://discuss.elastic.co/t/endpoint-security-state-changed-to-degraded-protecting-with-policy/281308/1 "2021-08-13T07:40:40Z")

</div>

Good Day, After some mins after staring agent Elastic Agent .. status changed from Health to UnHealth (with Endpoint Security Integration)  
I check logs and find line:  
endpoint-security State changed to DEGRADED: Protecting with policy {policy\_id}

OS : Windows 10  
Elastic Agent 7.12

Any suggestion how to resolve this issue ?

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [August 13, 2021, 9:29am UTC](https://discuss.elastic.co/t/endpoint-security-state-changed-to-degraded-protecting-with-policy/281308/2 "2021-08-13T09:29:34Z")

</div>

Hi @Alexey_Shalin

This most likely indicates that the Endpoint Security policy has failed to apply cleanly. A good place to start debugging this is by looking at the Endpoint policy status details.

If you go to the Security -\> Endpoint page you should be able to find the Endpoint in the degraded state. If you click on the Policy status entry for the failing Endpoint a fly out will appear on the right hand side with details of what failed. Can you do that and post back with what is failing? If the answer isn't clear from there we'll have to look at Endpoint logs.

---

<div class="post-metadata">

**Author:** ![Alexey\_Shalin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexey_shalin/32/77531_2.png) [@Alexey\_Shalin](https://discuss.elastic.co/u/Alexey_Shalin)\
**Post date:** [August 13, 2021, 9:45am UTC](https://discuss.elastic.co/t/endpoint-security-state-changed-to-degraded-protecting-with-policy/281308/3 "2021-08-13T09:45:33Z")

</div>

Ok. Thx,. I'm checking.  
[Security]-\>[Administration]-\>Endpoints  
and did not find my new agent :frowning  
So.. I resolved issue. I removed old CA and SubCA from Certification Util and restart agent. And now it's working properly. Events and etc going to ELK,, but some problem with retrieving infos like:  
Host ID  
—  
First seen  
—  
Last seen

Your visualization has error(s)  
Data Fetch Failure  
Request Timeout after 30000ms

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [August 15, 2021, 10:17pm UTC](https://discuss.elastic.co/t/endpoint-security-state-changed-to-degraded-protecting-with-policy/281308/4 "2021-08-15T22:17:50Z")

</div>

I'm glad you made progress!

I'm not sure what you mean by "some problem with retrieving infos like:..." Can you state that another way?

---

<div class="post-metadata">

**Author:** ![Alexey\_Shalin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexey_shalin/32/77531_2.png) [@Alexey\_Shalin](https://discuss.elastic.co/u/Alexey_Shalin)\
**Post date:** [August 17, 2021, 3:18am UTC](https://discuss.elastic.co/t/endpoint-security-state-changed-to-degraded-protecting-with-policy/281308/5 "2021-08-17T03:18:09Z")

</div>

Seems there was issue with ELK cluster and it's was a reason. why i did not see information about agent :  
like OS and etc.  
Now everything works OK  
but it's very strange that windows agent - pick up first CA and SubCa in certificate storage .. and not tring to find fresh one 🙂

and now everything works find  
thx\

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2021, 3:18am UTC](https://discuss.elastic.co/t/endpoint-security-state-changed-to-degraded-protecting-with-policy/281308/6 "2021-09-14T03:18:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
