Troubleshooting¶
A device isn't reporting¶
The device is missing from the Fleet, or shows Overdue.
-
Check the scan task on the device:
Get-ScheduledTaskInfo -TaskName 'Trimtab Lookout Scan' | Select-Object LastRunTime, LastTaskResult0means success. Anything else usually means the task was blocked or the device wasn't elevated during install. -
Check the queue. Files in
C:\ProgramData\Trimtab\output\outboxmean scans ran but couldn't upload. -
Check the network. From the device:
Test-NetConnection app.trimtabsec.com -Port 443Allow outbound HTTPS to
app.trimtabsec.comthrough any firewall, proxy, or web filter. -
Check the credential. If the device was revoked in the Bridge, re-run the installer with a current enrollment key.
-
Run a scan manually and watch for errors:
powershell.exe -ExecutionPolicy Bypass -File 'C:\Program Files\Trimtab\agent\Invoke-ComplianceScan.ps1' -Upload
Lookout is blocked by application control¶
Tools such as ThreatLocker block unknown PowerShell scripts by default. Allow:
powershell.exerunning scripts fromC:\Program Files\Trimtab\as SYSTEM- The scheduled tasks Trimtab Lookout Scan and Trimtab Lookout Upload
- The installer, from wherever you stage it, during rollout
See Files and schedule for the exact commands.
The installer fails¶
| Message | Fix |
|---|---|
| Run this script elevated | Open PowerShell with Run as administrator, or run it as SYSTEM from your RMM. |
| running scripts is disabled on this system | Run it with powershell.exe -ExecutionPolicy Bypass -File … as shown in the guides. |
| Invalid or revoked enrollment key | The key was revoked or mistyped. Create a new key under Clients. |
| Server URL must use https | Use https://app.trimtabsec.com. |
Many checks show Error¶
Scans that run without administrator rights can't read some settings. Run scans through the Trimtab Lookout Scan task, which runs as SYSTEM, rather than from a normal PowerShell window.
Microsoft 365¶
| Symptom | Cause and fix |
|---|---|
| Consent page shows unverified | Expected until publisher verification is complete. All permissions are read-only. |
| Need admin approval during consent | Sign in as a Global Administrator of the client's tenant. |
| Exchange checks show not evaluated | Assign the Global Reader role to Trimtab M365 Scanner, wait up to an hour, then select Scan now. See Enable Exchange checks. |
| MFA registration and inactive accounts show not evaluated | These need Microsoft Entra ID P1. They don't affect the score. |
| The first scan doesn't appear | Microsoft can take a few minutes to set up the app in a new tenant. Trimtab retries automatically; select Scan now after a few minutes. |
A score changed without a new scan¶
Changing a client's standards recalculates every score for that client, including past scans.
Still stuck?¶
Email hello@gettrimtab.com with the device name or tenant, what you tried, and any error message.