Skip to content

Troubleshooting

A device isn't reporting

The device is missing from the Fleet, or shows Overdue.

  1. Check the scan task on the device:

    Get-ScheduledTaskInfo -TaskName 'Trimtab Lookout Scan' | Select-Object LastRunTime, LastTaskResult
    

    0 means success. Anything else usually means the task was blocked or the device wasn't elevated during install.

  2. Check the queue. Files in C:\ProgramData\Trimtab\output\outbox mean scans ran but couldn't upload.

  3. Check the network. From the device:

    Test-NetConnection app.trimtabsec.com -Port 443
    

    Allow outbound HTTPS to app.trimtabsec.com through any firewall, proxy, or web filter.

  4. Check the credential. If the device was revoked in the Bridge, re-run the installer with a current enrollment key.

  5. Run a scan manually and watch for errors:

    powershell.exe -ExecutionPolicy Bypass -File 'C:\Program Files\Trimtab\agent\Invoke-ComplianceScan.ps1' -Upload
    

Lookout is blocked by application control

Tools such as ThreatLocker block unknown PowerShell scripts by default. Allow:

  • powershell.exe running scripts from C:\Program Files\Trimtab\ as SYSTEM
  • The scheduled tasks Trimtab Lookout Scan and Trimtab Lookout Upload
  • The installer, from wherever you stage it, during rollout

See Files and schedule for the exact commands.

The installer fails

Message Fix
Run this script elevated Open PowerShell with Run as administrator, or run it as SYSTEM from your RMM.
running scripts is disabled on this system Run it with powershell.exe -ExecutionPolicy Bypass -File … as shown in the guides.
Invalid or revoked enrollment key The key was revoked or mistyped. Create a new key under Clients.
Server URL must use https Use https://app.trimtabsec.com.

Many checks show Error

Scans that run without administrator rights can't read some settings. Run scans through the Trimtab Lookout Scan task, which runs as SYSTEM, rather than from a normal PowerShell window.

Microsoft 365

Symptom Cause and fix
Consent page shows unverified Expected until publisher verification is complete. All permissions are read-only.
Need admin approval during consent Sign in as a Global Administrator of the client's tenant.
Exchange checks show not evaluated Assign the Global Reader role to Trimtab M365 Scanner, wait up to an hour, then select Scan now. See Enable Exchange checks.
MFA registration and inactive accounts show not evaluated These need Microsoft Entra ID P1. They don't affect the score.
The first scan doesn't appear Microsoft can take a few minutes to set up the app in a new tenant. Trimtab retries automatically; select Scan now after a few minutes.

A score changed without a new scan

Changing a client's standards recalculates every score for that client, including past scans.

Still stuck?

Email hello@gettrimtab.com with the device name or tenant, what you tried, and any error message.