Device reports showing rights / settings that differ from inherited / global

Which aspect of EPP are you submitting for?

Endpoint Protector Server

What is a one sentence summary of your feature request?

device reports showing rights / settings that differ from inherited / global

Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.

We have a few admins with the rights to make changes in Device Control. We have all the USBs, serial ports, local printers locked down. Once approved one of the admins will whitelist the device for that computer/user. But sometimes someone will change the computer rights from preserve global to allow access. There might be a legit reason for that or more training might be required. But either way we need a way to run a report on all devices with custom rights/settings and what setting differs from the inherited setting. If possible what admin did it and when would be nice.

How do you currently solve the challenges you have by not having this feature?

click on a computer that shows custom, see whats different, go back to and click the next one. over. and. over. and. over again

Hi Phil,

Thank you — this is a well-described pain point and the manual workaround you’re living with (clicking through each computer one by one) makes the value of this report immediately obvious.

The ability to surface computers or users with custom rights that deviate from the inherited/global baseline — ideally with the admin and timestamp — is a solid addition to Device Control reporting. We’re planning to invest in the settings and rights management areas of Endpoint Protector over the next twelve months with a focus on usability, and this type of delta reporting fits well within that scope.

No firm commitment on timing yet, but this is the kind of request that lands at the right moment. We’ve logged it and will revisit it as that work takes shape.

1 Like