As I understand it, synchronization with Active Directory and SharePoint Online is performed automatically according to the system schedule.
However, I noticed that once Active Directory or SharePoint Online is connected, the system automatically creates a scan schedule, and scans are subsequently performed based on that schedule.
Could you please explain the design rationale behind this approach?
Many customers in Korea prefer either real-time detection or the ability for administrators to manually initiate a scan whenever necessary. For this reason, I was curious why Netwrix adopted an automatic scheduled scanning approach rather than a manual on-demand scanning model.
I believe that many security administrators in Korea are likely to have the same question. It would be very helpful if you could share the design rationale behind this approach so that we can provide a clear explanation to our customers.
In addition, are there any plans to introduce a manual on-demand scanning feature in the future, alongside the current automatic scheduled scanning approach?
I would appreciate it if you could review my questions and share your thoughts.
The intent behind scheduled scans is to give admins a “near real-time” view of their environment automatically, without needing to manually trigger a scan to keep the data accurate. This is designed to scale well across large environments, where relying on admins to remember to run scans manually could actually leave bigger gaps in visibility.
That said, we recognize there are cases where an admin wants to confirm the current state of the data right now rather than wait on the schedule. So in the near term, we’re planning to introduce:
A “Scan Now” option to manually trigger a scan on demand
Better visibility into scan status and last-scan time, so admins can see how fresh the data is and decide for themselves when a manual scan is needed
We don’t have a firm date to share yet, but wanted to confirm this is a direction we’re actively working toward.
I have one follow-up question regarding the scheduled scan behavior.
You mentioned that the scheduled scan is intended to provide a “near real-time” view of the environment. However, when I checked the automatically created scan schedule, the next scheduled scan appears to be set approximately one week after the initial scan.
Given this behavior, would it still be accurate to consider the current scan mechanism as “near real-time”? A scan interval of about one week seems significantly different from what most administrators would typically interpret as near real-time monitoring.
Alternatively, is it possible that the weekly scan interval is caused by a configuration issue on my server, or is this the default behavior by design?
I would appreciate it if you could clarify whether this scan interval is expected behavior or if there is something that should be adjusted in our environment.
Thank you again for your help, and I look forward to your clarification.