> Source: [sk169592](https://support.checkpoint.com/results/sk/sk169592)

# sk169592 - Endpoint Detection and Response (EDR) is blocking System Center Configuration Manager (SCCM) client communication

| Property | Value |
|----------|-------|
| Solution ID | sk169592 |
| Date Created | 2020-10-07 |
| Last Modified | 2020-10-11 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |
| Platform | Open Server |

## Symptoms

- * SCCM Client is not able to communicate with the SCCM server.
* SCCM client is unable to fetch policy from SCCM server, and interrupts Windows patch downloads.
* The Issue is resolved after removing Check Point Anti-Malware blade.

## Cause

**This is a Microsoft issue.**   

It occurs when Windows Defender is extremely outdated, since it is the default Anti-Virus. This creates issues with a 3rd Party Anti-Virus (Check Point Anti-Malware).

<br />

## Solution

There is a hard link in the SCCM to Windows Defender (as Windows Defender can be controlled via SCCM). This creates issues with other Anti-Virus endpoint protection software.   

Below is the official workaround from Microsoft.   

1. Rename `C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1910.4-0\mpclient.dll` (and/or `C:\Program Files\Windows Defender\mpclient.dll`, if it exists), and reboot.  
   This will allow the SCCM client (and the 3rd Party Anti-Virus) to be functional, but will prevent Windows Defender from assuming the default Anti-Virus role, if a 3rd Party Anti-Virus is removed in the future.  

   **OR**
2. Uninstall the 3rd Party Anti-Virus (EPAM blade)  
   Update Windows Defender to the latest version for the appropriate platform (this might require running `updateplatform.exe` manually - possibly from MU - as SCCM client remains non-functional). Reinstall 3rd Party Anti-Virus (EPAM blade)  

   **For example:**   
   Update for Windows Defender Antivirus antimalware platform - KB4052623 (Version 4.18.1911.3)  
   <https://www.catalog.update.microsoft.com/Search.aspx?q=4052623>

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
