Troubleshooting
An endpoint keeps showing offline
Separating genuine disconnection from flapping, proxy timeouts and stale records.
Last updated
An endpoint that enrolled successfully and now shows offline intermittently is a different problem from one that never connected, and the health history is what distinguishes them.
Open the endpoint and read its connectivity history before doing anything else. Steady online followed by a clean stop suggests the machine is powered off, disconnected or has had its agent service stopped. Repeated short disconnections — flapping — suggests something is terminating the connection, and that is a network story rather than a machine story.
The most common cause of flapping is a proxy or firewall that terminates long-lived connections. The agent maintains an outbound connection to the platform, and middleboxes configured to close idle or long-running connections will cut it repeatedly. The pattern to look for is disconnections at suspiciously regular intervals, which is the fingerprint of a timeout rather than of a fault.
Laptops flapping around lunchtime and the end of the working day are almost always behaving correctly — lids close, machines sleep, connections drop. If this is producing noise, the offline threshold is set tighter than your estate warrants.
Where several endpoints at one site flap together, treat it as a site issue. Chasing them individually is the classic way to lose a day to a problem that one phone call to the site would have identified.
Rule out stale records too. An endpoint that has been offline continuously for weeks is usually a machine that was decommissioned without anyone resolving the console record. These accumulate quietly and degrade the offline list until nobody reads it, at which point a real failure hides inside it.
Remember that nothing notifies you when an endpoint drops. There is no alerting engine, so an endpoint going offline is a fact that sits in the console until somebody looks or something polls the API for it.