Description | This article explains how to troubleshoot communication issues between the FSSO DC Agent and the FSSO Collector Agent caused by Microsoft Defender Exploit Guard, and provides steps to resolve them. |
Scope | FSSO. |
Solution |
Communication between the FSSO Collector Agent and the DC Agent (via the 'lsass.exe' process) may be blocked by Microsoft Defender Exploit Guard. To identify such blocked events and the associated process names, review the Windows Defender logs in Event Viewer by navigating to Event Viewer -> Applications and Services logs -> Microsoft -> Windows -> Windows Defender -> Operational. Check for the events blocked by Microsoft Defender Exploit Guard and the associated Process Name.
In the example above, Microsoft Defender Exploit Guard is blocking communication between the FSSO Collector Agent and the DC Agent (lsass.exe).
To address this issue, configure the Attack Surface Reduction policy (specifically Attack Surface Reduction Only Exclusions) for C:\Windows\System32\lsass.exe and C:\Windows\System32\svchost.exe.
For more information, refer to Microsoft's documentation for Microsoft Defender: Enable attack surface reduction rules - Microsoft Defender for Endpoint | Microsoft Learn. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.