Idolbe Patch

Troubleshooting agents

Endpoint shown as disconnected, log locations, permissions repair, re-enrollment, moving to another organization.

Most problems are one of four things: the computer is off or has no route to the console, the service is not running, the agent cannot read its own configuration, or the endpoint was removed from the console and the agent needs to re-enroll. Work through the sections in order.

The endpoint shows as Disconnected

An endpoint is Connected when it checked in during the last hour or so and Disconnected otherwise. Alerts → "Endpoint offline" and "Endpoint group uptime" can email you when this happens.

  1. Is the computer on and connected? Laptops asleep or off-site without internet simply stop checking in; they catch up when they return.
  2. Can it reach the console? From the computer, open the console URL in a browser or run curl -sI <console URL>/api/health. A firewall or proxy must allow outbound HTTPS to the console host.
  3. Is the service running? - Windows: Get-Service IdolbePatchAgent in an elevated PowerShell; Restart-Service IdolbePatchAgent restarts it. - Linux: sudo systemctl status idolbe-patch-agent; sudo systemctl restart idolbe-patch-agent.
  4. Read the log: C:\ProgramData\IdolbePatch\agent.log (Windows) or sudo journalctl -u idolbe-patch-agent -n 100 (Linux). The last lines say what the agent is stuck on: a check-in error, a rejected token, a permissions problem.

The log says the token was rejected (HTTP 401)

The endpoint record is gone (database restored, or the endpoint was deleted from the console). Agents 0.11.2 and later try to re-enroll with the organization key at their next check-in: if the endpoint was deleted on purpose the console answers HTTP 410 and a 0.11.4+ agent uninstalls itself; otherwise the computer reappears as a new endpoint. Older agents keep retrying: reinstall from the current download.

Windows: "access denied" on agent.log or agent.json

Agents 0.11.0 to 0.11.2 could damage the permissions of their own files after a start. Agents 0.11.3 and later repair the tree at every start. If a computer is stuck, run in an elevated PowerShell:

icacls "C:\ProgramData\IdolbePatch\*" /reset /T /C /Q
Restart-Service IdolbePatchAgent

The agent then checks in and upgrades itself to the published version. If it does not within ten minutes, download the agent again from Getting started and run it on the computer: this upgrades in place and keeps the endpoint's identity.

Third-party updates are missing on Windows

Third-party detection uses winget (App Installer) in the session of the logged-on user, because winget only sees per-user installations from that session. Check that App Installer is installed from the Microsoft Store and that a user has signed in since the agent was installed. Applications installed for the machine are also matched against the version catalog, which refreshes several times a day.

An update stays "Missing" after a deployment

Open History, find the run and read the per-endpoint log. Usual causes: the update needs a reboot that was postponed by the user (the endpoint shows "Reboot pending"); the update failed with a Windows Update error code (the log contains it); the application was running and the restart behavior is set to "skip" (Advanced → Updates).

A script or action is still Running

Every command has a timeout (per action type, or the timeoutSeconds you set); the agent kills the process tree when it expires and reports Failed with the output collected so far. Output is capped at 4 MB. If a command shows as Running for longer than its timeout, the agent has not been able to report back: check connectivity, the report is retried when the agent reconnects.

Enrollment refused (HTTP 402)

New endpoints cannot enroll when the organization has reached its endpoint limit, when the subscription has expired, or when the account is being closed. Subscription shows the limit and the state; Request Quote raises the limit.

Re-enrolling or moving a computer

To move a computer to another organization, uninstall the agent (IdolbePatchAgent.exe -uninstall or sudo idolbe-patch-agent -uninstall) and run the new organization's download or one-liner. The agent never switches organizations on its own.

What to send to support

The last 100 lines of the agent log, the agent version (Endpoints list or -version on Linux), the operating system, and the time of the problem in UTC. Support contact and hours: Availability commitment and support.