Acronis Advanced EDR Troubleshooting Guide | Resolve Agent and Security Issues

Acronis Advanced EDR Troubleshooting

This document provides troubleshooting steps for common Acronis Advanced EDR issues, including agent connectivity problems, protection failures, scan issues, false positives, and endpoint performance concerns.

Platform: Acronis Cyber Protect Cloud

1. EDR Agent Is Offline

Resolution

  1. Log in to the Acronis Cyber Protect Cloud console.
  2. Navigate to:

    Devices
  3. Select the affected endpoint.
  4. Check the agent status and last communication time.
  5. Verify the endpoint:
    • Is powered on
    • Has network connectivity
    • Can communicate with Acronis Cloud services
  6. Restart the Acronis agent service.

Windows:

Services → Acronis Managed Machine Service → Restart

Linux:

systemctl restart acronis_mms
  1. If the issue persists, reinstall the EDR agent.

2. Endpoint Is Not Reporting Events

Resolution

  1. Verify the endpoint status shows Online.
  2. Confirm the EDR protection module is enabled.
  3. Check that the agent services are running.
  4. Verify network connectivity to Acronis services.
  5. Restart the Acronis agent service.
  6. Update the EDR agent if required.
  7. Reinstall the agent if event reporting does not resume.

3. Malware Scan Is Not Running

Resolution

  1. Open the affected Protection Plan.
  2. Verify antivirus and malware protection are enabled.
  3. Check the configured scan schedule.
  4. Confirm the endpoint is online during the scan window.
  5. Restart the Acronis agent service.
  6. Run a manual malware scan.
  7. Review activity logs for scan errors.

4. Endpoint Isolation Failed

Resolution

  1. Confirm the endpoint is online.
  2. Verify the EDR agent is communicating.
  3. Retry the isolation action.
  4. Check endpoint permissions and agent status.
  5. Restart the agent service.
  6. Update the EDR agent if required.
  7. Use network controls as an alternative containment method if isolation remains unsuccessful.

5. Quarantine Action Failed

Resolution

  1. Verify the file still exists on the endpoint.
  2. Check that the EDR agent is online.
  3. Retry the quarantine action.
  4. Confirm the agent has required permissions.
  5. Restart the agent service.
  6. Manually remove the threat if automated quarantine continues to fail.

6. Agent Update Failed

Resolution

  1. Verify the endpoint has internet connectivity.
  2. Check available disk space on the endpoint.
  3. Confirm the device is online in the Acronis console.
  4. Retry the agent update.
  5. Restart the endpoint if required.
  6. Reinstall the latest EDR agent if the update continues to fail.

7. Protection Plan Is Not Applied

Resolution

  1. Navigate to:

    Devices → Select Endpoint
  2. Check the assigned protection plan.
  3. Verify the protection plan is enabled.
  4. Confirm the device license is available.
  5. Reassign the protection plan.
  6. Restart the Acronis agent service.
  7. Verify the protection status updates.

8. High CPU Usage Due to EDR Agent

Resolution

  1. Check CPU usage from the endpoint.
  2. Identify Acronis-related processes consuming resources.
  3. Review active scans or security analysis tasks.
  4. Schedule scans during non-business hours.
  5. Configure appropriate scan exclusions for trusted applications.
  6. Update the EDR agent to the latest version.
  7. Contact support if high CPU usage continues.

9. Application Blocked Due to False Positive

Resolution

  1. Open the security incident.
  2. Review the blocked application details.
  3. Verify:
    • Application name
    • File hash
    • Publisher information
    • Execution behavior
  4. Confirm the application is legitimate.
  5. Add the application to security exclusions or allow lists.
  6. Restore the application if it was quarantined.
  7. Test application functionality.

10. Handle an EDR False Positive

Resolution

  1. Open the detected security incident.
  2. Review the detection details.
  3. Analyze:
    • File reputation
    • Process behavior
    • User activity
    • Application source
  4. If confirmed safe:
    • Add an exclusion
    • Create an allow indicator
    • Restore quarantined files
  5. Document the false positive reason.
  6. Monitor future detections.
    • Related Articles

    • Acronis Advanced EDR Configuration

      This document explains how to enable and configure Acronis Advanced Endpoint Detection and Response (EDR), including agent installation, protection plans, malware protection, antivirus scheduling, and security exclusions. Platform: Acronis Cyber ...
    • Acronis Advanced EDR Incident Investigation

      This document explains how to investigate security incidents using Acronis Advanced EDR, including reviewing alerts, analyzing attack timelines, examining endpoint activity, and investigating common security threats. Platform: Acronis Cyber Protect ...
    • Acronis Advanced EDR Incident Response Actions

      This document explains how to perform incident response actions using Acronis Advanced EDR, including endpoint isolation, threat removal, indicator management, incident closure, and documentation. Platform: Acronis Cyber Protect Cloud 1. Isolate an ...