Defender for Identity re-install error "value cannot be null. parameter name path1"

Darryl 256 Reputation points
2023-10-25T11:06:15.5766667+00:00

One of our MDI sensors stopped communicating last night, maybe linked to a windows update, I tried restarting the services and rebooting when that didn't work. I then tried uninstalling and reinstalling the sensor, it looks like the senosr is now part uninstalled as although its still in the list of programs in add/remove programs when i try to uninstall it says it is alrady uninstalled. I've downloaded the latest sensor from the portal and ran it as an Administrator and get the error "Defender for Identity re-install error "value cannot be null. parameter name path1"" Any ideas what that means?

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Darryl 256 Reputation points
    2023-10-25T12:33:36.5833333+00:00

    Followed these steps and its installed again:

    1. On the domain controller where the ATP Sensor had failed, I searched the registry for "Azure Advanced" (without the quotes), and deleted all keys and subkeys where this was found.   I just made sure it was referencing the sensor.  There were several keys that needed to be deleted from HKCR and HKLM.   Just to be sure to be sure....make a backup of the registry before you delete the keys.

     

    1. I deleted the folder C:\Program Files\Azure Advanced Threat Protection Sensor

     

    1. Manually re-installing the sensor worked and it is reporting as expected in the portal.   

    https://techcommunity.microsoft.com/t5/microsoft-defender-for-identity/manually-uninstall-the-azure-atp-sensor/m-p/238344