Support & Resources
Common Support Issues
Local Admin Passwords Not Rotating
Search terms: local admin password not rotating, stale password, rotation pending, Microsoft LAPS, Windows LAPS, minimum password age, password complexity, firewall, allowlist
This issue may occur when a local administrator password remains stale or unchanged, or when the rotation status does not update as expected.
Confirm whether Microsoft LAPS is managing the same local administrator account because it may override or conflict with Evo rotation. In the Evo Portal, verify that the Local Account Password Length policy meets the environment’s requirements. If Windows or Active Directory enforces a one-day minimum password age, configure Evo rotation for one day or longer.
Confirm the endpoint can reach the required Evo services. Collect logs when rotation triggers but never completes, is intermittent across multiple devices, or firewall, proxy, antivirus, or EDR interference is suspected.
Example: Compare the Evo rotation interval for <LOCAL_ADMIN_ACCOUNT> with the Windows minimum password age.
Windows Login Error: c000006
Search terms: c000006, Windows login error, elevated login fails, invalid credentials, Entra ID, Azure AD, elevation assignment, tenant access, role, allowlist
This issue occurs when an elevated login fails with c000006 or produces invalid-credentials behavior even though the user can sign in to other services.
The most common cause is a username or password mismatch. For a user synced from Microsoft Entra ID or Azure AD, confirm the credentials entered for Evo elevation are correct and match the credentials expected by the Evo workflow. Evo does not pull passwords down from Entra ID.
Confirm the user is licensed, has the correct Elevation Assignment, and has the Tenant Access and role required for the action. Confirm the endpoint can reach the required Evo services.
Collect logs if the credentials and portal configuration are confirmed but the failure continues, the issue occurs only on certain networks, or OTP works but push does not.
Example: Confirm <USER_EMAIL> is licensed, belongs to <ELEVATION_ASSIGNMENT>, and has access to <TENANT_NAME>.
Technician Unable to Access the Evo Portal
Search terms: technician cannot access Evo Portal, portal access denied, missing tenant visibility, convert user to admin, Evo Admin, registered device, MFA push failure
This issue may occur when a technician cannot sign in to the Evo Portal, receives access denied, or cannot see the expected tenant.
Confirm the technician has been converted to an Evo Admin because portal access requires an Admin account. Check the user record for a registered mobile device. If no device is registered, the user may also experience MFA or push-notification failures.
Example: Open <USER_EMAIL>, confirm the user type is Admin, and verify a mobile device is registered.
User Not Receiving MFA or Push Notifications
Search terms: push notification not received, MFA push missing, notification only appears in app, cannot scan QR code, QR code clipped, no registered device, stale device, reinstall Evo Authenticator, Face ID, biometrics
Confirm the user is synced into Evo, is properly licensed, and has a registered device. Confirm notifications are enabled for Evo Authenticator at the phone operating-system level and within the app permissions. Ask the user to open the app and check whether the request is present but not appearing as a phone notification.
If no device is registered, uninstall and reinstall Evo Authenticator. On Android, rebooting after uninstalling may help clear remaining app data. Resend the welcome email and complete enrollment again. MFA-only users generally should not attempt to sign in to the Evo Portal because portal access requires an Admin account.
For QR-code issues, confirm biometrics or Face ID is enabled when required by the device and that the complete QR code is visible and not clipped by the email client, browser zoom, or RMM scaling.
To refresh registration, delete the device under the user in the Evo Portal, force close Evo Authenticator, and reopen it to register again.
Example: Remove <STALE_DEVICE> from <USER_EMAIL>, resend the welcome email, and scan the complete QR code.
API or Authentication Error: 401 Unauthorized
Search terms: 401 Unauthorized, API 401, token unauthorized, invalid token, expired token, incorrect credentials, unlicensed user, missing role
This issue occurs when an API request or token-based operation fails with 401 Unauthorized.
Confirm the token is valid, has not expired, and is being used correctly. Confirm the associated credentials are correct. Also confirm the user is licensed and has the role required for the elevated login or requested action.
Example: Confirm <TOKEN_NAME> is valid and <USER_EMAIL> has the required license and role for <REQUESTED_ACTION>.
API or Authentication Error: 403 Forbidden
Search terms: 403 Forbidden, API 403, access token accepted but blocked, access denied, expired access token, secret token, recreate token, Endpoints Access Token
This issue occurs when an API request fails with 403 Forbidden or the Access Token is accepted but the action is blocked.
Go to Endpoints > Access Token and confirm the Access Token and Secret are correct and the token has not expired. If the token is not expired and the request still fails, recreate the token and test again.
Example: Review <ACCESS_TOKEN_NAME> under Endpoints > Access Token and recreate it if it continues to return 403 Forbidden.
Domain Admin Password Not Rotating
Search terms: domain admin password not rotating, PASSWORD ROTATION PENDING, rotation timing inconsistent, one-hour rotation, Entra password policy, Active Directory GPO, minimum password age
This issue may occur when a domain administrator password remains in PASSWORD ROTATION PENDING or when rotation timing is inconsistent.
Avoid an extremely frequent rotation interval. A one-hour interval can leave password rotation in a continuous pending state in some environments. The recommended rotation frequency is one day.
Review the applicable Microsoft Entra ID, Azure AD, or Active Directory password policies. Confirm minimum password age, password length, complexity, and other Group Policy requirements do not conflict with the Evo rotation schedule.
*For LDAP clients, if the password rotation continues to fail. Ensure your DC’s AD computer entry has the “Domain Admin” permission on that record. Attempt rotation again after making that change.
Example: If the domain minimum password age is one day, configure <DOMAIN_ACCOUNT> to rotate no more frequently than once per day.
Office 365 SAML Metadata Reference
Search terms: Office 365 SAML metadata, Microsoft 365 federation metadata, SAML XML, Microsoft federation metadata URL, nexus microsoftonline-p
Use the following Microsoft federation metadata XML URL when an Office 365 or Microsoft 365 SAML configuration requires Microsoft federation metadata:
Evo LDAP Agent New Groups Not Syncing
Search terms: LDAP group not syncing, new Active Directory group missing, AD group not appearing, LDAP Agent sync groups, stop LDAP service, CTRL Sync, manual full sync
Open the Evo LDAP Agent Settings Editor and stop the LDAP Agent service. Select the Active Directory group or groups that should sync, apply the changes, and start the service again. Hold CTRL and select Sync to run a manual full sync.
Example: Select <AD_GROUP_NAME>, apply the settings, start the service, then hold CTRL and select Sync.
Evo Agent Installation Error: “Requires an Active Internet Connection”
Search terms: requires an active Internet connection, installer fails immediately, network configuration, proxy settings, firewall blocked, antivirus, EDR, SentinelOne, S1, Evo allowlist
The installer may display: “Evo Agent requires an active Internet connection for installation. Please check your network configuration and proxy settings.”
The error may be caused by a firewall or proxy blocking required Evo endpoints or by antivirus or EDR software blocking the installer or its traffic.
Confirm whether an antivirus or EDR product could be blocking the installer. If SentinelOne is installed, confirm its agent version and exclusions because older agents or restrictive configurations may interfere with installation. Validate the Evo firewall and network allowlist requirements.
Example: Check <EDR_PRODUCT> for a block event involving the Evo installer on <DEVICE_NAME>.
Password Rotation Frequency Recommendation
Search terms: recommended password rotation frequency, one-day rotation, hourly rotation, rotation pending, operational issues
The recommended password rotation frequency is one day. Hourly rotation is not recommended because it may cause operational issues or leave rotation pending in some environments.
Example: Set Rotation Frequency = 1 day for <LOCAL_OR_DOMAIN_ACCOUNT>.
Clear the Offline End User Elevation Rule Cache
Search terms: clear EUE rule cache, offline database, evoagent.db, old rule still applies, deleted rule still active, prompted for a reason, rule should auto approve
Use this procedure when an End User Elevation rule was changed or removed but the endpoint continues to use the old rule, or the user is prompted for a reason even though a rule should automatically approve the application.
Run the following commands from elevated PowerShell:
Stop-Service -Name "EvoSecureLoginAgent"
Remove-Item -Path "C:\ProgramData\EvoSecurity\SecureLogin\evoagent.db" -Force
Start-Service -Name "EvoSecureLoginAgent"Within approximately 10 minutes, the endpoint should refresh the rule cache and apply the latest rules.
Example: Run the commands on <DEVICE_NAME>, then retest <APPLICATION_NAME> after the refresh.
Duo and Evo Installation Order
Search terms: Duo with Evo, Duo installed before Evo, Evo installed before Duo, credential provider order, Duo detection
The Evo installer detects Duo and can automatically enable the expected settings when Duo is installed before Evo. If Duo is installed after Evo, the same automatic detection may not occur.
When Duo is part of the standard build, install Duo first and then install Evo.
Example: Install Duo <DUO_VERSION> before Evo Agent <EVO_VERSION>.
macOS Agent MFA Enforcement and Fail-Safe Account
Search terms: macOS Evo Agent, MFA enforcement, fail-safe account, failsafe user, Mac local administrator, bypass MFA, locked out of Mac
Confirm that the user intended to receive Evo MFA enforcement is not configured as the Fail-Safe account. Configure a dedicated local administrator as the Fail-Safe user so a recovery account remains available.
Example: Fail-Safe user = <DEDICATED_LOCAL_ADMIN>; enforced user = <STANDARD_USER>.
Install the Evo Agent Locally with an MSI and Deployment Token
Search terms: local Evo Agent install, MSI install, EvoAgentSetup.msi, DEPLOYMENT_TOKEN_VALUE, deployment token, command prompt, silent deployment
Use the following command to install the Evo Agent locally with an MSI and a Deployment Token:
.\EvoAgentSetup.msi DEPLOYMENT_TOKEN_VALUE="<YOUR_DEPLOYMENT_TOKEN>"Replace <YOUR_DEPLOYMENT_TOKEN> with the Deployment Token created for the required tenant and configuration.
Example: .\EvoAgentSetup.msi DEPLOYMENT_TOKEN_VALUE="<TENANT_DEPLOYMENT_TOKEN>"
Clean Uninstall and Reinstall of the Evo Agent
Search terms: clean uninstall Evo Agent, reinstall Evo Agent, delete EvoSecurity folder, delete EvoSecurity registry key, remove endpoint, remove local accounts, redeploy, force sync
Use the following process to fully clean up and redeploy the Evo Agent:
- Uninstall the Evo Agent from the device.
- Delete or rename C:\ProgramData\EvoSecurity.
- Delete HKEY_LOCAL_MACHINE\SOFTWARE\EvoSecurity.
- Remove the device under Endpoints > Computers in the Evo Portal.
- Under Vault > Local Accounts, select the affected accounts, choose Delete, and select Delete from Portal.
- Redeploy the Evo Agent.
- Wait for automatic account synchronization, or open the Evo Settings Editor, hold CTRL, and select Sync.
- Re-enable password rotation for the affected accounts.
- Test Technician Elevation after the passwords rotate.
If the issue continues, collect the environment details and logs for further investigation.
Example: Reset <DEVICE_NAME>, redeploy it with <DEPLOYMENT_TOKEN>, sync the accounts, and retest elevation.
User Status Shows Staged
Search terms: user status staged, Active column shows Staged, user not active, MFA SSO license missing, synced user unlicensed
Staged in the Active column means the user has been added or synced into the Evo Portal but an MFA and SSO license has not been applied.
Assign the appropriate license. After it is applied, the status will change from Staged to Active.
Example: Assign an MFA and SSO license to <USER_EMAIL> and confirm the status changes to Active.
Allowlist Policy
Search terms: allowlist policy, IP allowlist, approved IP address, blocked IP, office public IP, VPN egress IP, trusted network, cannot access Evo
The Allowlist policy restricts Evo access to approved IP addresses. When enabled, only IP addresses added to the allowlist are permitted to access Evo; all others are blocked by default.
Before enabling the policy, add every required public IP address, including office locations, VPN egress IPs, and other trusted networks from which users or administrators access Evo.
Example: Add <OFFICE_PUBLIC_IP> and <VPN_EGRESS_IP> before enabling the policy.
Internal Server Error in the Evo Portal for an LDAP Client
Search terms: Internal Server Error, Evo Portal LDAP error, LDAP client error, LDAP Agent service stopped, primary domain controller, user sync unavailable
If the Evo Portal displays Internal Server Error for an LDAP client, confirm the Evo LDAP Agent services are installed and running on the primary domain controller for that tenant.
Example: On <PRIMARY_DOMAIN_CONTROLLER>, confirm the Evo LDAP Agent service for <TENANT_NAME> is running.
EvoConsentUI Blocking UAC Prompts
Search terms: EvoConsentUI blocking UAC, UAC prompt blocked, secure desktop frozen, black screen, elevation blocked, cannot uninstall Evo Agent, Microsoft .NET Desktop Runtime
This issue can occur when the required Microsoft .NET Desktop Runtime is not installed before the Evo Agent. EvoConsentUI may appear on the secure desktop and block UAC prompts, elevation, updates, or normal agent removal.
For workstations, boot into Safe Mode, uninstall the Evo Agent, install the required .NET Desktop Runtime, and reinstall the latest Evo Agent.
For Windows Servers, Safe Mode may still trigger the blocked prompt. Connect through an elevated remote shell or RMM tool, stop or suspend the Evo services and processes so they cannot restart, uninstall the agent, install the required runtime, and reinstall Evo.
After rebooting, confirm Windows UAC prompts and Evo elevation function normally.
Mobile Enrollment Error: “Failed to get JWT for key”
Search terms: Failed to get JWT for key, device already registered, QR code already used, mobile enrollment stuck, incomplete registration, stale registration, iOS, Android
This issue can occur when the first QR-code scan creates an incomplete or stale registration between the Evo Portal and Evo Authenticator. The user may appear enrolled while the app displays Failed to get JWT for key, reports the device is already registered, or becomes stuck.
Remove the user from the directory sync group and confirm the user is fully removed from the Evo Portal. Delete Evo Authenticator from the phone, add the user back to the sync group, and allow the account to be recreated. Resend the welcome email, reinstall Evo Authenticator, and enroll with the new QR code.
Example: Remove <USER_EMAIL> from <DIRECTORY_SYNC_GROUP>, sync, add the user back, resend the welcome email, and enroll again.
