> Source: [sk176728](https://support.checkpoint.com/results/sk/sk176728)

# sk176728 - Full Disk Encryption blade stuck in "Not installed", "Not Running" state

| Property | Value |
|----------|-------|
| Solution ID | sk176728 |
| Date Created | 2021-12-09 |
| Last Modified | 2021-12-15 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * Full Disk Encryption blade is installed but shows "Not Running" on client Display Overview screen.

* Web Portal shows Full Disk Encryption status as "Not Installed" on the affected machine.

* Pre-boot is disabled and disks are unencrypted on the client machine.

* Full Disk Encryption stuck in an unstable transient state after the Full Disk Encryption blade previously requested to uninstall. This log is found in *%PROGRAMDATA%\\CheckPoint\\Logs\\cpda.log* :

  `
  date time root [debug] FDE: FDE unistalltion is in progress, SD policy will be omited from DA known policies list to prevent arrival of new SD policies [CDA::getKnownPolicies]`

* Incorrect deployment policy and lower client version being called shows in *cpda.log* , for example:  

  `root [debug] Calling needToRunInstaller with: version: 84.10.5530, installmask: 201087, productCode: E473FD2D-0AE5-44CE-96B5-70314C5921B8, packageCode: Null [CDA::updateDeplStateFromDeplPolicyAddOrUpdate]`  
  `
  root [error] MsiOpenDatabase failed with error: 87 [cpda::InstallationPrepareWrap::getPackageCodeOfMSI]`  
  `
  root [error] newProdVer 84.10.5530 cannot be installed on 84.50.7526 [cpda::InstallationPrepareWrap::GetProductsToInstallFromGUID]`  
  `
  root [debug] Don't install, wrong version for installation was requested`

## Cause

Endpoint Security Client ignores new deployment policies until Full Disk Encryption is uninstalled (after disks were decrypted).  
This is expected behavior - Full Disk Encryption blade must be uninstalled after disk decryption, before any new deployment (version upgrade) is applied.

Full Disk Encryption uninstalls registry values inconsistently, causing Endpoint Security Client to behave as if Full Disk Encryption is during the uninstallation process, while pre-boot is removed and disks are decrypted.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
