> Source: [sk121122](https://support.checkpoint.com/results/sk/sk121122)

# sk121122 - Endpoint Security Client is unable to register to the Endpoint Security Server

| Property | Value |
|----------|-------|
| Solution ID | sk121122 |
| Date Created | 2017-10-30 |
| Last Modified | 2025-06-24 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | E89.X, E88.X |

## Symptoms

- * Endpoint Security Client is unable to register to the Endpoint Security Server.
* The Client UI displays 'Working Offline' and the error "The Endpoint Security Client cannot register with the Server. The Security-ID of this Computer was not found. Please contact your Administrator".
* The following error is found in *cpda.log* :  
  `
  20171020 15:31:07.143 e20 Startup: Endpoint not registered yet (CDA::doRegister)`  
  `
  20171020 15:31:07.143 e20 ##### Enter sendRegisterEndpoint (CDAProtocol::sendRegisterEndpoint)`  
  `
  20171020 15:31:21.511 e20 ---ERROR--- LoadAccount using account: XXXXXX, failed. Error: 1789(g_getCompSIDBySpecificName)`  
  `
  20171020 15:31:21.511 e20 Going to try NetBios account name: XXXXXX, to find SID (g_getNetBiosCompAccountName)`  
  `
  20171020 15:31:21.511 e20 ---ERROR--- LoadAccount using account: XXXXXX, failed. Error: 1789 (g_getCompSIDBySpecificName)`  
  `
  20171020 15:31:21.511 e20 ---WARNING--- No Sid retrived (g_getCompSID)`  
  `
  20171020 15:31:21.511 e20 ---ERROR--- Failed to get computer SID (CDAProtocol::createRegisterEndpoint)`  
  `
  20171020 15:31:21.511 e20 ---ERROR--- Could not create register-endpoint message
  (CDAProtocol::sendRegisterEndpoint)`  
  `
  20171020 15:31:21.511 e20 ---ERROR--- Startup: Failed to register or update register endpoint (CDA::doRegister)`

## Cause

The trust relationship between workstation and domain failed.

By default, Windows "machine account password" expires every 30 days.

The next setting defines the password expiration:  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk121122/word-image-21911130633.jpeg)  

To prevent such scenario the following changes to GPO could be applied (**applying the below settings reduces domain security!**):

Under - Computer Configuration \> Policies \> Windows Settings \> Security Settings \> Local Policies \> Security Options

Change two options:

*Domain member: Disable machine account password changes* - **To Enabled**

*Domain member: Maximum machine account password age - **To*** **999** *(maximum possible value)*

More information on common causes on Trust Relationship can be found in the following Microsoft Technet link.

https://social.technet.microsoft.com/wiki/contents/articles/9157.troubleshooting-ad-trust-relationship-between-workstation-and-primary-domain-failed.aspx

Issue was also reported in the following scenarios:

* Missing Windows 7 KB976494.
* Hostname was changed when machine was already assigned to the domain after Endpoint Security Client installation.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
