Troubleshooting

This VaultPilot troubleshooting guide covers five common failures: MSI installation, server start, DC Agent connection, extension pairing, and a stuck update. Each section lists the states, logs, and settings to check first.

MSI installation fails

Check:

  • Is the MSI running as Administrator?
  • Is the port already in use?
  • Is there an installer log in the VaultPilot log folder (see Windows Server installation)?
  • What is the Windows service state?

Server does not open

  1. Open VaultPilot in a browser on the server itself.
  2. Check the VaultPilotServer service state.
  3. Verify firewall and port routing.
  4. Review server logs with sensitive values redacted.

DC Agent cannot connect

  • Test <VAULTPILOT_URL> from the agent machine.
  • Use -Status to view config, service, and log state.
  • Use a domain-qualified bind username.
  • Do not write token or password values to logs.

Extension pairing stays pending

  • The pairing code may have expired.
  • The wrong username may have been entered.
  • The user may not have an unlocked vault.
  • The device may still be waiting for approval in VaultPilot.

Update stays around 76 percent

The MSI may be restarting the service. When the service returns, Update Center checks the target version, installer log, and running version and updates the job. If the job stays blocked, review the Windows Installer logs.

Back to Documentation