Troubleshooting Tip: Repairing an agent that cannot be unlocked
| Description | This article describes how to repair an agent that cannot be unlocked. |
| Scope | FortiDLP. |
| Solution | Under very rare circumstances, it may be possible for a Reveal Agent to enforce a lock or isolate action that cannot be undone via an action from the Reveal Platform. The most likely cause for this would be if a lock action were undertaken and the platform instance was to be erased before the unlock action.
To ensure that lock and isolate actions persist across host reboots and if the network is disconnected, the Reveal Agent will enforce a lock immediately after a log-in. For an isolate action, it remains possible for a local administrator to disable or remove the agent, however, this is possible for a lock action, as the keyboard and mouse input are disabled for all except the Ctrl-Alt-Delete menu (including the task manager.)
If a machine is in a locked state, there are a few mechanisms available to administrators to revert this action. This FAQ will deliberately not list these actions, as they could be used to defeat a legitimate lock action. |
