Failed to remove Windows Defender Advanced Threat Protection ETW autologger. Failure code: 0xD0000121

Rahim CELIK 21 Reputation points
2023-04-19T11:30:26.3033333+00:00

Hello, When I run the 365 Defender "offboarding" script, it shows that it has been successfully removed and the Defender dashboard is active. When I examine the Windows Event Log, I get the error "Failed to remove Windows Defender Advanced Threat Protection ETW auto-logger. Error code: 0xD0000121".d1

ed2

Microsoft System Center
Microsoft System Center
A suite of Microsoft systems management products that offer solutions for managing datacenter resources, private clouds, and client devices.
894 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,665 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
{count} votes

1 answer

Sort by: Most helpful
  1. VasimTamboli 4,780 Reputation points
    2023-05-11T19:37:35.7966667+00:00

    The error message "Failed to remove Windows Defender Advanced Threat Protection ETW autologger. Failure code: 0xD0000121" indicates that there was an issue removing the ETW (Event Tracing for Windows) autologger for Windows Defender Advanced Threat Protection (ATP). Here are a few steps you can try to troubleshoot and resolve this issue:

    Run the script with administrative privileges: Ensure that you are running the "offboarding" script with administrative privileges. Right-click on the script and select "Run as administrator" to ensure proper permissions.

    Disable Windows Defender ATP manually: If the script fails to remove the ETW autologger, you can try disabling Windows Defender ATP manually. Open an elevated Command Prompt and run the following command:

    bashCopy code
    wdavideoconfig.exe -disable
    

    This command disables Windows Defender ATP by stopping the Windows Defender ATP service.

    Check for conflicting security software: If you have any other security software or antivirus solutions installed on your system, they might conflict with the removal process. Temporarily disable or uninstall any third-party security software and then run the "offboarding" script again.

    Update Windows Defender ATP: Ensure that you have the latest updates installed for Windows Defender ATP. Check for and install any available Windows updates, including security updates and feature updates.

    Contact Microsoft Support: If the issue persists and you are still unable to remove the ETW autologger for Windows Defender ATP, it's recommended to contact Microsoft Support for further assistance. They can provide you with specific guidance and troubleshooting steps based on your environment and the specific error code you are encountering.

    Please note that modifying or disabling security features like Windows Defender ATP should be done with caution, and it's important to have alternative security measures in place to protect your system against threats.