Frequently Asked Questions | Endpoint Central
Server
Server Migration
Build Number and Versions
Click the profile icon at the top-right of the console. Your build number appears in the panel that opens — for example, Build: 11.5.2605.01. Click the build number itself to open the Version Details panel, which shows the individual version installed for each component: Central Server, Distribution Server, and each agent type (Windows, Mac, and Linux).
Click the profile icon at the top-right of the console. If a newer build is available, an upgrade prompt appears in that same panel alongside your current build number. For a broader view to plan the upgrade ahead, the ManageEngine's Endpoint Central lists the latest released build and the recommended upgrade sequence for your version but rather wait for the in-console upgrade notification.
A Service Pack is a cumulative release that consolidates all fixes from prior builds into a single new baseline. Every customer upgrading beyond it must pass through it — there is no way to skip it. In the build string, the SP level is the second digit: in 11.5.2605.01, the 5 denotes SP5. An SP release also significantly reduces the size of subsequent PPM files, because older patch-handling code gets cleaned up during consolidation.
A Hotfix is smaller and targeted — it addresses specific bugs found after the last SP and applies on top of it. Hotfixes can be applied incrementally and are lighter than a full Service Pack.
The practical rule: install the SP first to establish the baseline, then apply hotfix builds on top as they are released.
This is a custom fix or specialised hotfix build — not a general release. ManageEngine engineers assign a version number at the time a custom fix is compiled, which can produce a service-pack segment (2534) that appears numerically higher than the current public GA release (2528). This does not mean your environment has a "newer" or superior build — it means it's on a non-standard release branch.
Implications for upgrades:
- Standard PPM files for the GA release path (
2528.x) will likely be rejected by your Update Manager, because the installer detects a higher version number already installed. - Standard in-product upgrade notifications may not appear, since the server knows it deviates from the GA release path.
- You must not attempt to downgrade or apply a lower-versioned PPM without Support guidance.
Recommended action: Contact ManageEngine Support and provide:
- Your current build number as shown in the console
- The contents of
<UEMS_CentralServer>\conf\fixes_id.properties
Support will confirm your correct upgrade path — typically a custom-to-GA consolidation PPM — and whether the fix from your custom build has been merged into the current GA release.
Internet access alone does not guarantee that the upgrade notification will appear. There are four distinct causes, each requiring a different resolution. Work through the table below to identify which applies to your environment before resorting to a manual PPM download.
| Cause | How to Identify | Resolution |
|---|---|---|
| Customised or Hotfix Build Installed | Console build number ends in an unusual patch suffix (e.g., .12 on a build not listed on ME's official website). The server knows it deviates from the standard release path and suppresses standard notifications. | Contact ManageEngine Support with your current build number. They will confirm the correct next step and whether a standard notification will appear once you return to the standard build path. |
| AMS (Annual Maintenance & Support) Subscription Expired | Navigate to Admin → License. If the AMS expiry date is in the past, notifications for builds released after that date are suppressed. | Renew your AMS subscription via your ManageEngine account manager. Notifications will resume once the subscription is active and the console re-contacts the update server. |
| Proxy or Firewall Blocking Update Server | From the server, try to reach autoupgrade.manageengine.com on port 443 using a browser or curl/telnet. If the connection times out, outbound traffic is being blocked despite general internet access being available. | Whitelist autoupgrade.manageengine.com and downloads.manageengine.com on port 443 in your firewall or proxy. After whitelisting, click "Check for updates" again in the console. |
| In-Product Notification Setting Disabled | Navigate to Profile Icon → Build Version → Settings. Check whether "Display in-product notifications about updates" is disabled. | Enable the notification setting and save. The notification will appear at the next update-check interval (typically within a few minutes). |
If none of the above causes apply and notifications are still missing, download the PPM manually from ME's official website using the build number shown in your console and apply it via UpdateManager.bat. Refer to the Downloading the PPM section for instructions.
The position and digit count of each segment tells you the upgrade type required:
| Segment | Position | Example | Upgrade Type Required |
|---|---|---|---|
| Service Pack | 3rd (4 digits) | 2528 | Manual PPM download + planned downtime required |
| Minor Patch | 4th (2 digits) | 21 | Auto Upgrade eligible — no PPM download or downtime needed |
Side-by-side comparison examples:
11.4.2528.19→11.4.2528.21— only Segment 4 changed → Minor Version → Auto Upgrade eligible11.4.2516.39→11.4.2528.21— Segment 3 changed → Service Pack → manual PPM required11.4.2528.21→11.5.2528.21— Segment 2 changed → Major version upgrade → check ME's upgrade path guide first
Practical rule: Compare builds left-to-right. If only the last two digits changed, it's a minor patch. If the 4-digit segment changed, plan a maintenance window. If Segment 1 or 2 changed, verify the full upgrade path on ME's official website before proceeding.
PPM Upgradation
A Service Pack (SP) is a major cumulative release that consolidates all fixes and changes up to that point into a single unified build. It is introduced primarily for code maintenance and to establish a common baseline across all customers. Any customer wishing to upgrade to a build beyond the SP must pass through the SP first — it cannot be skipped. In the build number format, the Service Pack level is indicated by the second digit (for example, in 11.5.2605.01, the 5 denotes the Service Pack). An SP release also significantly reduces the PPM file size and the time taken to apply it, since all prior patch-handling code is consolidated and cleaned up.
A Hotfix is a smaller, targeted release that addresses specific bugs or issues identified after the last SP. Hotfixes can be applied incrementally on top of the SP baseline and are lighter in size compared to a Service Pack.
In summary: Apply the SP first to establish the baseline, then apply hotfix builds on top to stay current.
Backup
No. Scheduled backup is an online backup — the Endpoint Central server stays fully operational while the backup runs in the background.
The backup will not run. There is no retry — it will only attempt again at the next scheduled time. Make sure the EC service is running.
At least 2—2.5× the current database size of free space on both the local drive and your backup destination. For example, if your DB is 10 GB, keep at least 20—25 GB free.
Yes. Ensure the Endpoint Central service account has write access to the network folder. For MSSQL, the SQL Server service account also needs write access. Test the connection before relying on it.
It depends on your database size and storage speed. Network backups are slower than local ones. For Remote PostgreSQL, the backup runs over the network — speed depends on bandwidth between the EC server and the remote DB server. Schedule backups during off-peak hours to minimize impact.
Every 45 days, a recovery key is emailed to all administrators. This key lets you restore a backup even if you forget your custom password. Do not delete these emails.
No. Backups are never automatically disabled. If 3+ consecutive failures occur, a dashboard warning appears, but backups continue to run on schedule. Fix the underlying issue (disk space, permissions, or network access) and the next run should succeed.
It is not recommended. VM snapshots and SQL-only backups do not cover application files . We recommend keeping Endpoint Central's built-in backup enabled for complete protection.
Yes. The system automatically creates a pre-upgrade backup before every update or patch.
No, it is not safe to delete files in the ScheduledDBBackup folder manually. It is recommended to have atleast 7 days of backup files in the folder. The system automatically manages the backup files based on the retention count you set in the Admin → Database Settings → Database Backup section. Deleting files manually can lead to loss of critical backup data and may affect your ability to restore in case of an issue.
Restore
No. The backup must be from the exact same build number. If you need to restore on a newer build, install the matching version first, restore, then upgrade.
Yes, always. The restore will not proceed if the service is running. Stop the service via Windows Services before starting the restore.
Yes. Restoring replaces all current data with the backup data. Any changes made after the backup date will be lost.
Use the recovery key emailed to all administrators every 45 days. Check your email archive for a message from Endpoint Central containing the key. If you can't find it, contact ManageEngine Support.
Only if you're restoring on a new server. On the same server, just stop the service and run the restore utility — no reinstallation needed.
Yes, if the server hostname and IP address remain the same. Agents reconnect automatically within few minutes.
No. Cross-type restore is not supported. The backup must match the exact database type of your installation (e.g., you cannot restore a Remote PostgreSQL or MSSQL backup on a Bundled PostgreSQL setup).
Yes. Install the exact same version on the new server, copy the backup file, and restore. The build number, database type, and architecture (32-bit/64-bit) must all match.
VM snapshot restore not recommended, in Endpoint Central files and database should be in sync so restoring either files or database alone separately using VM snapshot might lead to inconsistency, so always use the Backup-Restore Utility instead of VM snapshots.
Contact support with your backup file details. They can help you locate the exact build installer matching your backup so you can install it on the new server and restore.
Go to Admin → Database Settings → Database Backup → Backup Protection. The new password applies only to future backups. For existing backups, use the original password or the recovery key.
Go to Admin → Database Settings → Database Backup. You can change the backup time, retention count, and destination path. After saving, new backups use the updated settings. Existing backups at the old location are not moved automatically.
Go to Admin → Database Settings → Database Backup. Update the email addresses under the failure notification section. A working mail server must be configured in Admin → Mail Server Settings.
<Install Dir>\UEMS_CentralServer\ScheduledDBBackup\. We strongly recommend changing this to a different drive or network share.
Go to Admin → Database Settings. The database type (Bundled PostgreSQL, Remote PostgreSQL, or Microsoft SQL Server) is displayed on this page.
Backups should always be performed on the primary server. The Failover Server does not run independent backups. After restoring on the primary, run SyncSecondary.bat Restore from the primary server's bin folder to sync the secondary server.
Kingbase Database
No. Unlike PostgreSQL migration, the KingBase migration tool does not create the database. The database must be pre-created on the KingBase server before migration.
The migration tool only supports KingBase V9R1C10. If you have a different version, you must upgrade or install V9R1C10 before proceeding.
The kbcrypto extension provides SM4 symmetric encryption functions. Endpoint Central uses SM4 encryption for sensitive columns in the database. Without this extension, encrypted columns cannot be read or written.
KingBase supports multiple compatibility modes (PostgreSQL, Oracle, MySQL). Endpoint Central requires PostgreSQL compatibility mode (database_mode=pg). The migration tool will block the migration if the mode is incorrect.
If migration fails, the database_params.conf file is not updated. The server remains on the original database. You can safely retry the migration after resolving the issue. It is recommended to drop and recreate the KingBase database before retrying (as it may contain partial data).
Yes. You can migrate from one KingBase instance to another (e.g., moving to a different server). The process is the same — select KingBase in the migration tool and provide the new connection details.
SSL/TLS is strongly recommended for production environments but is optional. Without SSL, all JDBC traffic (including credentials and SQL queries) is transmitted in plaintext over the network. Configure SSL on the KingBase server and the product will automatically detect and use it.
The ci_x_icu collation provides ICU-based case-insensitive text comparison. Endpoint Central requires this for case-insensitive search operations on certain columns. This must be available in the KingBase instance before migration.
Endpoint Central connects to KingBase using username + password authentication (scram-sha-256 recommended in sys_hba.conf). Trust authentication (no password) is detected and blocked by the product at startup.
Mail Server Settings
Network Settings
Agent
Agent Installation
Endpoint Central supports multiple agent installation methods — manual install, GPO push, AD-based automatic install, push via CLI, Azure/Intune, and bulk install for AWS instances. Refer to the Agent Installation guide for the complete list of methods.
Use the automatic agent push installation method. Details are available in the Agent Installation guide.
Use any of the supported remote installation methods documented here. Push install via CLI or self-install URL are common choices for remote endpoints.
Yes. Linux agents are not tied to a single distribution. Refer to Managing Linux computers.
Refer to Windows Autopilot enrollment. Intune licenses are required for each user when using Azure Autopilot.
Yes. The agent can be installed via imaging or as a post-deployment step in OS Deployment. See the Agent Installation guide.
Agent Troubleshooting Tool
Windows: Right-click the agent tray icon in the system tray → select Agent Troubleshoot > Troubleshoot → click Start Troubleshooting. Alternatively, run the executable directly from C:\Program Files (x86)\ManageEngine\UEMS_Agent\bin\agent_troubleshooting_tool.exe.
Linux (v2203+): Open Terminal, navigate to /usr/local/manageengine/uems_agent/bin and run sudo ./dctroubleshootingtool.
macOS (v11.4.2544.01.M+): Click the agent menu bar icon → Tray Icon > Troubleshoot > Run troubleshooting tool. Or open Terminal and run /Library/ManageEngine/UEMS_Agent/bin/troubleshoot.
Windows: Open Command Prompt and run: "C:\Program Files (x86)\ManageEngine\UEMS_Agent\bin\agent_troubleshooting_tool.exe"
Linux:cd /usr/local/manageengine/uems_agent/bin then sudo ./dctroubleshootingtool
macOS:/Library/ManageEngine/UEMS_Agent/bin/troubleshoot. To view all available options, run troubleshoot --help.
Windows: Agent Service status, Agent Identity (machine UUID and OS details), Agent Binaries integrity, WMI connectivity, Active Directory connection, Antivirus software installed, Server connection (ping and port), Distribution Server connection (if applicable), Notification Server idle connection, and RDS connectivity.
Linux: Product details (version, directory, remote office name), machine hostname/FQDN/IP/MAC, server connectivity (Central Server, Distribution Server, on-demand, remote control), patch tool availability (apt/yum/zypper), minimum 20 GB free space check, vendor connectivity (cloud agents only), and dcservice/process status.
macOS: Server connection, Distribution Server connection (if applicable), on-demand action capability, service and process health, agent version, server address, and MDM enrollment status.
- Windows:
C:\Program Files (x86)\ManageEngine\UEMS_Agent\logs\ - Linux:
/usr/local/manageengine/uems_agent/logs/ - macOS:
/Library/ManageEngine/UEMS_Agent/logs/ - macOS dump (--dump):
/Library/ManageEngine/UEMS_Agent/logs/UserLogs/dumps/
troubleshoot --dump. The dump is saved to /Library/ManageEngine/UEMS_Agent/logs/UserLogs/dumps/.telnet <Server Address> <Server Port> in Command Prompt on the agent machine. A blank screen indicates a successful connection. You can also verify file download connectivity by opening https://<Server_Address>:<Server_Port>/client-data/ns-status-details.xml in a browser on the agent machine — if an XML file loads, the connection is successful./usr/local/manageengine/uems_agent/bin and run sudo ./dctroubleshootingtool. For quick manual checks without the tool:- Test server port connectivity:
curl -sk https://<server>:8383/dcapi/agentInfo - Check agent service status:
systemctl status uems-agent - View last communication log:
tail -50 /usr/local/manageengine/uems_agent/logs/AgentComm.log | grep heartbeat
systemctl status uems-agent— checks if the agent service is runningps aux | grep uems— lists running agent processessudo systemctl restart uems-agent— restarts the agent service if it is stopped
Scope of Management
Distribution Server
Tools
- Navigate to Announcement → User/Computers.
- Select the existing announcement.
- Under Actions, click Save As New.
- Make changes and click Save.
Remote ControlWhich ports must I open to use the Remote Control feature? The following ports must be open in the endpoint where the Endpoint Central server is installed to use the Remote Control feature:
- 8443 — for secure connections
- 8444 — for normal connections
By default, the Remote Control feature uses a secure connection.Which ports must I open to use the File Transfer feature during a remote control session? To use the File Transfer feature during a remote control session, open the following ports in the endpoint where the Endpoint Central server is installed:
- 8443 — for secure communication
- 8444 — for normal communication
The File Transfer and Remote Control features use the same port.Can I view multiple monitors of a remote computer simultaneously? Yes, you can view multiple monitors of a remote computer simultaneously by using the Remote Control feature. You can switch between monitors using the multi-monitor icon available in the Active X viewer. Viewing multiple monitors simultaneously is currently not supported in a Java viewer. To know more about viewing multiple monitors during a remote session refer to this page.The UI-rendering while using the Remote Control feature is slow. How can I improve its speed? To enhance page-rendering speed, set the compression level to Fast while using the Remote Control feature. Although this setting increases bandwidth consumption compared to the Best compression level, it provides faster page rendering.What is the difference between Fast and Best Compression levels? When you set the compression level to Fast, the compression ratio is lower, resulting in an increase in the speed of the rendering of the UI. This is recommended when the computer that you are connecting remotely to is in the same LAN as the computer you are connecting from.
When you set the compression level to Best, the compression ratio is higher, resulting in a decrease in the consumption of the bandwidth. However, the rendering of the UI will be comparatively slower. This setting is recommended when the computer that you are connecting to remotely is at a different geographical location.On which browsers can I use the Remote Control feature? You can use the Remote Control feature on the following browsers:- Mozilla Firefox
- Google Chrome
- Microsoft Internet Explorer
- Zoho Ulaa
Is it possible for multiple users to login remotely to a computer at the same time? Yes, it is possible for multiple users to login remotely to a computer at the same time. However, only one of the users who has logged in can take control. The other users can only view the changes that are being made.How do I lock a keyboard or a mouse or blacken the display on a remote computer? To lock the remote computer's keyboard and mouse, click the Lock Keyboard/Mouse icon from the viewer.
To blacken the remote monitor, click on the Blacken Monitor icon from the viewer. You can blacken the monitor of a remote computer when you do not want the user to view the changes that you are making.What will happen when I take a remote session of a Virtual Computer? When you take a remote session of a Virtual Computer, the session behavior depends on the virtualization platform. The Remote Control feature connects to the guest OS running inside the virtual machine in the same way it connects to a physical computer. Ensure the virtual machine is powered on and the Endpoint Central agent is running inside the guest OS before initiating the session.How to locate the file where the remote control session is recorded? To locate the file where a remote control session is recorded, first navigate to the directory where the Endpoint Central server is installed. Then, go to:
<Installed_Directory>\DesktopCentral_Server\webapps\DesktopCentral\server-data\<customerID>\rds\scr-rec
- 8443 — for secure connections
- 8444 — for normal connections
- 8443 — for secure communication
- 8444 — for normal communication
When you set the compression level to Best, the compression ratio is higher, resulting in a decrease in the consumption of the bandwidth. However, the rendering of the UI will be comparatively slower. This setting is recommended when the computer that you are connecting to remotely is at a different geographical location.
- Mozilla Firefox
- Google Chrome
- Microsoft Internet Explorer
- Zoho Ulaa
To blacken the remote monitor, click on the Blacken Monitor icon from the viewer. You can blacken the monitor of a remote computer when you do not want the user to view the changes that you are making.
<Installed_Directory>\DesktopCentral_Server\webapps\DesktopCentral\server-data\<customerID>\rds\scr-recChat
- Click Tools Tab and select Chat
- Under History click on Chat History Settings
- Specify the number of days to maintain the chat history, so that the previous chat history will be deleted.
- Stop the Endpoint Central server.
- Click start
- Point to Programs>ManageEngine Endpoint Central
- Click Stop DesktopCentral
- Open the websettings.conf located in <Install_Dir>\DesktopCentral_Server\conf. For
example, C:\Program Files\DesktopCentral_Server\conf. - Change the port numbers of the following key with the required values:
- httpnio.port
- Save the file and close it
- Start the Endpoint Central server.
- Click start
- Point to Programs>ManageEngine Endpoint Central
- Click Start DesktopCentral
- Agent not reachable in the client computer
- If the user is inactive in the computer
- If the "chat connection" session is time-out
- During 90 minutes refresh interval while the agent communicates with the server.
- During every user log on if it is configured in the User Logon Settings.
- During every user logoff.
To maintain consistency, it is recommended for a single administrator or a small group of authorized users to manage these rules, preventing duplication and ensuring standardized data collection.
Integration
Service Desk Plus Integration
Analytics Plus Integration
- Daily: Synchronizes data once every day at a specified time.
- Hourly: Synchronizes data every 3, 6, or 12 hours, based on your selected interval.
- Copying the files to the client computer.
- Setting the working directory for installation.
- To make sure that there are no issues with the created software package, try deploying it via the command line.
- The application to be installed can be user or system specific. Ensure that you have deployed the right configuration type (user/computer based) accordingly.
- The application may need admin rights to install, so try deploying it with the RUN AS ADMIN option.
License
Server Licensing
Currently, if the operating systems meet any of the following criteria, we consider them as server machines:
- If the machine has Windows server operating system
- If the machine with Red Hat Enterprise Linux OS has a Server subscription
- If the machine has Oracle Linux OS
- If the virtual machines have any of the above OS' installed
We recommend purchasing server licenses for any Linux machine when deploying them as servers within the organization.

Below are some capabilities that are offered in the server management space:
- Correlate vulnerability intelligence with corresponding patches for seamless remediation.
- Pre and post deployment scripts for orchestrating server patching.
- Customizable self-service portal for patches and software for servers.
- Customized deployment policies specific to servers.
- Test and approve patches before deployment for ensuring quality and reliability.
- Comprehensive support for server applications.
- Efficient and customizable folder backup solutions.
- Centralized registry controls for server configurations.
- 12+ system tools for server maintenance.
- Inbuilt remote control and troubleshooting capabilities.
- Server OS imaging and deployment capabilities.
- Unified product for server administrators and end-user computing, tailored with scope and technician segregation.
- User logon details to keep in line with audit requirements.
- Granular control over the services and processes running on a server.
UEM Edition
The license consumption count is based on the number of endpoints managed. When the Endpoint Central agent/MDM profile is installed on an endpoint, it automatically detects the MAC address, and is accounted as a license consumed.
Let's consider an organization that has bought 1000 Endpoint Central UEM licenses, and they're looking to manage workstations (including OS imaging and deployment) and mobile devices. Assume they have to manage
- 100 workstations (with OS deployment)
- 200 workstations (without OS deployment)
- 200 mobile devices
In this scenario, a total of 500 licenses are consumed, with the other 500 still remaining.
If the org decides to retire 100 devices, they can uninstall the agent and remove those machines from the Endpoint Central server. By doing so, these 100 licenses can be reused to manage other devices. Now, there are 600 licenses left for the org to use. However, OS deployment cannot be performed on these retired machines.
- OEM license: If the Windows OS version of the image is the same as the OEM license, then the license will be automatically activated.
- Volume-based license: Let us assume you've created an image by imaging a machine with a volume-based license. Depending on the availability of the license, if you deploy it to another machine the license will be automatically activated.
To resolve the “Insufficient space for creating image” issue, please increase the available free space in the existing image repository. Alternatively, you can create a new image repository at a different location with sufficient free space and use that repository to create the new image.
- Navigate to the server installed directory: Server Installed Directory\webapps\DesktopCentral\agent
- Locate the zip file named "USMTComponents.zip". If the size of the file is 1kb, it indicates that its empty.
- Delete the USMTComponents.zip file and initiate USMT again. The zip must be recreated with required files.
- Download the target machine's model specific rapid storage driver. Extract the driver files and add them to your driver repository.
- Once drivers were added, do a scan for the driver repository and try deployment.
- Alternatively access the BIOS settings of one of the target machines affected by the BSOD.
- Change the SATA configuration to AHCI or AHCI to RAID mode vice versa and attempt to boot the machine into Windows.
- Verify whether the system successfully boots into Windows.
If the issue persists, kindly contact support.
Software Deployment Integration in OS Deployment
Open or create a deployment template via OS Deployment → Customize → Deployment Templates. In the template editor, scroll to Configure Post-Deployment Details, click Select Software Packages, and select the required packages. Save the template to apply changes to all future deployments using it.
Packages install in the order shown in the Package Install Order list — top to bottom. Drag the handle to reorder. Place dependencies above the applications that require them.
Auto-Update makes the deployment pull the latest published version of a package instead of the version saved in the template. Enable it for frequently updated apps (browsers, PDF readers). Disable it for compliance-pinned or compatibility-sensitive packages.
The OS deployment is not rolled back. The failure is recorded against the individual package in the Software Deployment Packages tab under Deployment Status. Review the error details or refer to the Software Deployment Knowledge Base for remediation steps.
No. Only Windows software packages are supported for OS deployment integration.
A minimum of Software Deployment Read permission is required. Refer to User Roles for the full permissions matrix.
Yes. Remote Office deployments automatically pause until all required software packages have been replicated to the local Distribution Server. Installation begins only after replication is confirmed.
No. Only Windows Software Package installation is supported for OS Deployment integration.