---
title: "Checking Endpoint Status"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35374388/Checking%20Endpoint%20Status"
format: markdown
---
After you have successfully installed the Endpoint application and registered with the <span style="color: #000000">Infoblox </span>Portal, you can check the status of the service to ensure that your device is protected against malicious domains.

Endpoint uses three status icons to provide visual indication of the protection status: **Protected **and **Unprotected**. For Mac users, the status icon is displayed on the menu bar at the top of your desktop (Mac OSX). On the Windows platform, a tooltip is displayed when placing the mouse cursor on the icon. 

In normal operation mode, the protection status is refreshed every 30 seconds. When the Control Application starts or in error condition, the status is refreshed every 10 seconds.

Endpoint displays one of the following status icons on your device:  


** **> Macro (inline-media-image)

** Protected  **

- Endpoint actively secured by Infoblox. Endpoint is running properly, and your device is fully protected against malicious attacks by Infoblox Endpoint.   
This icon is displayed for the following states:
  - DNS queries are encrypted and are being sent to the Infoblox DNS Server.
  - DNS queries are being sent to the Infoblox DNS Server.

 **Protected - OnPrem**

- Endpoint actively secured using corporate network DNS. If your device is connected to the corporate network and Endpoint is secured using corporate network DNS., it is protected against malicious attacks by the corporate network.   
This icon is displayed for the following states:
  - When the endpoint is connected to the corporate network, the DNS queries are being sent to the corporate DNS servers.
  - If you have configured an on-prem DNS forwarding proxy, the DNS queries are being sent to the proxy.

** **> Macro (inline-media-image)

** Unprotected  **

- Endpoint is not secured by Infoblox. The application is currently not running or cannot be reached, and your device could become vulnerable to malicious attacks.   
The following are some possible causes:
  - The service cannot be contacted: Your protection level cannot be determined because the Infoblox Endpoint Service cannot be contacted for the moment.
  - No organization identifier has been provided: Your company account identification is missing.
  - Organization identifier is not valid: Your company account identification is not valid.
  - Email address has not been provided: You have not registered with Infoblox Threat Defense yet.
  - Registration has failed: The registration of your account has failed.
  - Problem with the user account: Your account has a problem.
  - Problem with the <span style="color: #000000">Infoblox </span>Portal: There is a problem with our portal.
  - Testing connectivity to the DNS Server: The connectivity to the Infoblox DNS Server is being tested. So, your device is not being protected yet.
  - Problem with the DNS Server: The Infoblox DNS Server cannot be reached.
  - No active network card: There is no active network card detected on the computer.
  - Problem with the DNS Proxy module: There is a malfunction in the DNS Proxy module.
  - You are not being protected by Infoblox Endpoint because other VPN software intercepts DNS requests on this computer.

> Macro (inline-media-image)

** Unprotected - OnPrem**

- Endpoint is not secured using corporate network DNS. The application is currently not running or cannot be reached, and your device could become vulnerable to malicious attacks.   
The following are some possible causes:
  - The service cannot be contacted: Your protection level cannot be determined because the Infoblox Endpoint Service cannot be contacted for the moment.
  - No organization identifier has been provided: Your company account identification is missing.
  - Organization identifier is not valid: Your company account identification is not valid.
  - Email address has not been provided: You have not registered with Infoblox Threat Defense yet.
  - Registration has failed: The registration of your account has failed.
  - Problem with the user account: Your account has a problem.
  - Problem with the <span style="color: #000000">Infoblox </span>Portal: There is a problem with our portal.
  - Testing connectivity to the DNS Server: The connectivity to the Infoblox DNS Server is being tested. So, your device is not being protected yet.
  - Problem with the DNS Server: The Infoblox DNS Server cannot be reached.
  - No active network card: There is no active network card detected on the computer.
  - Problem with the DNS Proxy module: There is a malfunction in the DNS Proxy module.
  - You are not being protected by Infoblox Endpoint because other VPN software intercepts DNS requests on this computer.

 **Offline Protection**

- Endpoint is partially protected. If the queries are not reachable or responded by Infoblox Endpoint Cloud Anycast IP addresses on Port 53, Infoblox Endpoint goes to offline Protection state  
This icon is displayed for the following states:
  - Offline Protection flag is enabled at endpoint group level:
    If the queries are not reachable or responded by Infoblox Endpoint Cloud Anycast IP addresses on Port 53. Infoblox Endpoint moves to offline protection and the domains present in the Default Block list will be blocked using the network resolver present in the client.
  - Offline Protection flag and Fallback DNS resolvers are enabled at endpoint group level:
    If the queries are not reachable or responded by Infoblox Endpoint Cloud Anycast IP addresses on Port 53. Infoblox Endpoint moves to offline protection and the domains present in the Default Block list will be blocked using the fallback DNS resolvers mentioned in the Infoblox Portal (CSP).
  - Fallback DNS resolvers are enabled at endpoint group level:
    If the queries are not reachable or responded by Infoblox Endpoint Cloud Anycast IP addresses on Port 53. Infoblox Endpoint moves to offline protection, and the all the queried domains will be forwarded using the fallback DNS resolvers mentioned in the Infoblox Portal (CSP).

**Disabled  **

- Disabled <span style="color: #1d1c1d">is a sub-status of </span>**Unprotected. **When Infoblox Endpoint is disabled by the administrator, your device is not being protected by Infoblox Endpoint. If Infoblox Endpoint is disabled, the following message will be displayed on the <span style="color: #000000">Infoblox </span>Portal's *Endpoint Groups* page.

**Unknown**

- Infoblox Endpoint may display an **UNKNOWN** status under certain conditions where the protection state cannot currently be verified. Possible reasons include the following:
  - Infoblox Endpoint cannot connect to the Infoblox Portal (csp.infoblox.com) due to network connectivity issues.
  - The machine is powered off or in Sleep/Standby state.
  - Endpoint Status in the Infoblox Portal may take up to 10 minutes to update, which can cause a temporary mismatch between the machine’s actual state and the portal display.