DriveLock Product Feedback & Ideas
Share your ideas for DriveLock.
Teilen Sie Ihre Ideen mit DriveLock.
77 results found
-
Reports should also have a Excel export choice.
I've now seen a few clients who want a report in XLSX format. That they can forward to another department for automating some feature of the rollout software. As far as I know, only PDF is possible, but I could be wrong, of course.
5 votes -
Erweiterung der unterstützten Dateitypen
Um die Kontrolle bezüglich Dateityp-Definitionen zu erweitern, wäre es hilfreich, wenn Drivelock folgende Archive unterstützt:
- .TAR
- .GZ
- .TAR.GZ
Wenn keine Kontrolle möglich ist, würde nur eine Sperrung übrig bleiben, welches die Funktionalität im Daily-Business einschränkt6 votes -
Notification when Files are moved to %LocalAppData%\Temp\DlDeleted
When ZIP files that contain prohibited files (File Filter) are cut and pasted (Strg+X -> Strg+C) to a USB mass storage device, DriveLock moves them to %LocalAppData%\Temp\DlDeleted instead. This is done to prevent data loss, since the files are deleted by Strg+X and cannot arrive at the destiniation due to the blocking of the file transfer
We would appreciate the following Changes:
a) Instead of moving it to %LocalAppData%\Temp\DlDeleted, the file should be moved back to its original location
b) If a) is technically infeasible, the user should be notified by DriveLock that their file has been moved to %LocalAppData%\Temp\DlDeleted.…4 votes -
Support for more Archive-Formats in File Filter
can only examine the contents of .ZIP, .7z and .rar archives.
We would like DriveLock to support more archive and compression formats like: .gz, .tar, .bz2, .xz and .zst.
Support of disk images like .iso files would also be appreciated4 votes -
Reporting of 651 Events
Even if 651 events are configured to be reported, they do not show up in the Windows Event Log or the central DES-Log. These events only show up in logs once an ABC-Rule rule is created that:
- Monitors the relevant Skript Executions
- Is configured to generate events when DriveLock approves the Skript executionsThis behavior of DriveLock is not documented anywhere.
All other events that I have come across don't work this way and get reported if they are appropriately configured in the "Events & Alerts" section of the policy. The additional ABC-Rule seems to be only necessary…
3 votes -
Cleanup deleted Accounts
Hi,
Currently, there is no automatic cleanup within the DOC.
There are users within the DOC who have the “Active Directory Account” type. As soon as Drivelock's sync with AD detects that this account no longer exists, the account should also be deleted within the DOC, with a corresponding log entry.
This would help keep the environment clean without the need for custom scripting.3 votesThanks for the suggestion. As a first step, we plan to provide a manual delete option for users in the DOC. This would allow administrators to remove obsolete Active Directory accounts directly without requiring custom scripts.
Automatic cleanup could be considered separately, as this requires additional handling for references such as user group memberships.
-
Collect "DLL started" and "DLL blocked" events without blocking them while Application Control Whitelisting of EXE files is still active
In a customer environment, where only the launch of EXE files is controlled by DriveLock, it is currently not possible to collect information about how Application Control would handle DLLs with the current policy set.
In order to collect "DLL started" and "DLL blocked" events, you have to change the "Scan- and Block-Mode" to include DLLs. This forces you to choose between Simulation Mode, which also affects the handling of EXE files, or "Active"-Mode, which would block all unknown DLLs immediately.
We would appreciate a feature that allows us to determine which DLLs would be blocked in our environment before…4 votes -
PBA externe Monitore
Hallo DriveLock-Team,
aktuell führen wir in unserem Unternehmen eine Umstellung von Desktop-PCs auf Notebooks mit Dockingstationen durch. Alle betroffenen Geräte sind mit der DriveLock Pre-Boot Authentication (PBA) ausgestattet.
Bei dieser Umstellung ist uns ein wiederkehrendes Problem aufgefallen: In bestimmten Konfigurationen – insbesondere bei Notebooks, die über USB-C oder Thunderbolt mit externen Monitoren oder Dockingstationen verbunden sind – wird die PBA ausschließlich auf dem internen Notebook-Display angezeigt, nicht jedoch auf dem externen Monitor.Unser Anliegen:
Wir bitten Sie dringend zu prüfen, ob eine Erweiterung der PBA möglich ist, die eine Anzeige auf externen Monitoren ermöglicht bzw. die externe Ausgabe via USB-C/Thunderbolt…1 vote -
Import von IoC-Hashwerte
Vorschlag für eine neue Funktion in DriveLock – Import von IoC-Hashwerten
Wir erhalten vom CERT NRW regelmäßig Listen mit sogenannten Indicators of Compromise (IoCs), die unter anderem Hashwerte von betroffenen bzw. potenziell schädlichen Dateien und Programmen enthalten. Diese Dateien sollen auf unseren Systemen möglichst schnell erkannt und blockiert werden.
Die bereitgestellten Listen können bis zu 100 oder mehr Hashwerte enthalten. Aktuell besteht in DriveLock – sofern überhaupt möglich – nur die Möglichkeit, die Hashwerte einzeln einzupflegen. Bei größeren Listen ist dies entsprechend aufwendig und zeitintensiv.
Wir benötigen daher eine Möglichkeit, eine Datei mit einer größeren Anzahl von Hashwerten zentral in…
1 vote -
Policy Management mit REST API & ServiceNow Integration für Automatisierung
REST API für ServiceNow-Integration, um das Management von DriveLock Policies vollständig zu automatisieren und in bestehende Enterprise-Prozesse zu integrieren.
Dabei sollte die automatisierte Erstellung und Änderung von Policies, einzelner Policy-Einstellungen und Whitelist-Regeln sowie die Zuweisung von Policies möglich sein.
Für Enterprise-Organisationen ist es entscheidend Automatisierung und Orchestrierung zu ermöglichen.
1 vote -
Bitlocker-Wiederherstellungskennwörter im Stapel für alle Clients exportieren
Die Schaffung einer Möglichkeit alle Bitlocker-Wiederherstellungskennwörter im Stapel aus Drivelock zu exportieren zu exportieren?
1 vote -
Zertifikatsablaufdatum soll angezeigt werden
Das Ablaufdatum bzw. die Eigenschaften eines Zertifikats (Gültig von... bis) soll als Spalte auswählbar sein. Zum einen in der Eventansicht, aber ebenfalls unter Security Controls - Applications - Certificates um eine Auswertung der bald-ablaufenden Applikationen zu erstellen.
Ein Warnhinweis für bald-ablaufende Zertifikate die in einer Regel verwendet werden, wäre optimal um Sperrungen zu verhindern.
1 vote -
Zertifikatsablaufdatum soll angezeigt werden
Das Ablaufdatum bzw. die Eigenschaften eines Zertifikats (Gültig von... bis) soll als Spalte auswählbar sein. Zum einen in der Eventansicht, aber ebenfalls unter Security Controls - Applications - Certificates um eine Auswertung der bald-ablaufenden Applikationen zu erstellen.
Ein Warnhinweis für bald-ablaufende Zertifikate die in einer Regel verwendet werden, wäre optimal um Sperrungen zu verhindern.
1 vote -
Automatic alerts for expiring API-Keys and Information regarding last API-Key Usage
We need the capabilities to send out notifications about API keys which are expiring in X days or weeks.
Also an overview about the last usage of an api key would be very helpful.
These two options would help us to fulfill compliance and security standards.2 votes -
Automatic Recovery Key Backup in EntraID
It would be nice if the Drivelock agent would initiate the Powershell command "BackupToAAD-BitLockerKeyProtector" everytime the agent sets or changes the recovery key.
This would help to utilize the self-service from myaccount.microsoft.com for the end user to get their recovery keys via another device on their own.1 vote -
Erweiterung der zeitlichen Steuerung für temporäre Freigaben in Device/Drive Control (DOC)
Im Zuge der Migration von Funktionen aus der DMC nach DOC ist uns aufgefallen, dass temporäre Freigaben für Geräte und Laufwerke aktuell auf 35.700 Minuten begrenzt sind. In der DMC konnte der Zeitraum frei gewählt werden. Ist das so gewollt oder gibt es einen techn. Erklärung?
Gerade für längerfristige Ausnahmen (z. B. Smartphones, USB Drives für den tägl. Gebrauch oder ext. HDD's, die jeweils jährl. rezertifiziert werden müssen) ist diese Einschränkung unpraktisch und führt zu unnötigem Verwaltungsaufwand.
Alternativ wäre es auch möglich, wenn Regeln selbst auch zeitlich befristet werden könnten (Start- und Enddatum). Nach Ablauf des definierten Zeitraums sollten sie…
1 vote -
Verbesserung der Barrierefreiheit von Windows-Toast-Benachrichtigungen in Application Control und Port Control
Im Rahmen der Barrierefreiheitsanforderungen möchten wir einen Feature Request für DriveLock Application Control und Port Control einreichen.
Aktuell werden die Windows-Toast-Benachrichtigungen von DriveLock nicht von Screenreadern (z. B. NVDA) vorgelesen, sofern die Benachrichtigung nicht im Fokus ist.
Dadurch können sehbehinderte oder blinde Anwender sicherheitsrelevante Benachrichtigungen nicht wahrnehmen.
Wir wünschen uns daher eine Anpassung der Implementierung, sodass die von DriveLock erzeugten Windows-Toast-Benachrichtigungen von gängigen Screenreadern zuverlässig erkannt und vorgelesen werden, ohne vorher durch ein Klick das Fenster in den Fokus gerät.
Die Umsetzung dieses Anliegens ist für uns von hoher Priorität. Daher würden wir uns über eine Einschätzung freuen, mit welchem…
1 vote -
Feature Request – Native Let's Encrypt / ACME-Integration für automatisierte Zertifikatsrotation (90-Tage-Zyklen)
Beantragt wird die Implementierung einer nativen oder offiziell unterstützten Automatisierungsschnittstelle für das ACME-Protokoll (z. B. Let's Encrypt) zur automatischen Beantragung, Erneuerung und Bindung von SSL/TLS-Zertifikaten für den DriveLock Enterprise Service (DES) und das DriveLock Operations Center (DOC).
DriveLock sollte den Prozess durch eine integrierte Automatisierungslogik übernehmen, die im Hintergrund nahtlos mit ACME-Clients wie win-acme interagiert oder einen nativen ACME-Client in den DES integriert.
Eine robuste Umsetzung sollte folgende Kernfunktionen umfassen:
Zertifikats-Beantragung & Renewal-Triggering: Ein konfigurierbarer Job innerhalb der DriveLock-Konsole, der (ähnlich wie win-acme per Scheduled Task) rechtzeitig vor Ablauf (z. B. an Tag 60) die Erneuerung anstößt.
Unterstützung für DNS-01…
1 vote -
Choose modules/options which are allowed for temporary unlock
We have a role-based setup in our company that allows the Helpdesk role to grant temporary unlocks in urgent situations. However, certain options and modules should not be accessible to this role.
In particular, for Application Control, it is critical that the Helpdesk can perform only a standard Application Control unlock. The options under “Executable files to add to the local hash database”, specifically:
Files written to the computer during the unlock period
Executables (and DLLs) launched during the unlock periodmust not be available to the Helpdesk role. These capabilities should be restricted exclusively to the Administrator role.
A…
3 votes -
Self Service
Hi,
when using Self Service for application control, we have communicated the following settings to our administrative users, when installing software.1) Start Self-Service before starting the installation proccess
2) Disable Application Control during Unlock Period, Add Application launched... (checked), Executable files added to the local hash database: FIles written during unlock period (checked), Require user approval .... (checked)
3) Timespan and reason givenAppControl is now unlocked and the software will be installed
When ending the Self Service of AppControl, a list of files is displayed, where the files can be selected from, which have to be added to…
1 vote
- Don't see your idea?