DriveLock Product Feedback & Ideas
Share your ideas for DriveLock.
Teilen Sie Ihre Ideen mit DriveLock.
68 results found
-
SB-Freigabe weiter einschränken als Geräte-Typ
In den Eigenschaften einer SB-Freigabe ist es lediglich möglich einzuschränken, ob Laufwerke / Geräte / Smartphones etc. freigegeben werden können. Es kann nicht weiter differenziert werden, welche Geräteklassen freigegeben werden können z.B. sollen nur USB-Controller freigegeben werden dürfen nicht aber Smartcard readers o.ä. .
8 votes -
Inventory Daten dediziert löschen
DriveLock sollte die Möglichkeit besitzen, Inventorydaten dediziert zu löschen. Hierbei sollten zwischen Drives / Devices / Applikationen usw. unterschieden werden können.
In Kundenumgebungen die schon über mehrere Versionen hinweg bestehen, ist die Auswertung der Daten derzeit einfach zu unübersichtlich. DIe Möglichkeit den Rechner aus dem Operations Center zu löschen und danach das Inventar neu einzulesen ist m.E. nicht ausreichend.8 votes -
SB-Freigabe von USB-Sticks auf "Nur lesbar" zu setzen
Bei der SB-Freigabe von USB-Datenträgern sollte es möglich sein, diese auf "Nur lesbar" zu setzen damit ein Datenabzug verhindert werden kann, es aber trotzdem möglich ist, Daten vom Datenträger zu lesen. Nötig z.B. bei einem Clickshare Gerät wo die Software aufgerufen werden muss.
7 votes -
Self-service unlock
The self-service unlock sometimes already corresponds to the desire of our customers. The customers who are traveling around the world also want to limit the unlock to time (outside working hours, weekends) etc. so that it is only valid for certain groups or people when the regular help desk is not in place. I think this is not possible in 7.9.6. Also, with unlock the 24/7 worldwide time zones should work fine.
6 votesWe will pursue this idea further, taking into account the voting in this forum, among other aspects, before including it in the detailed product backlog for the next version.
-
Reports should also have a Excel export choice.
I've now seen a few clients who want a report in XLSX format. That they can forward to another department for automating some feature of the rollout software. As far as I know, only PDF is possible, but I could be wrong, of course.
5 votes -
Drivelock Firewall logs
The computer logs should be extended by a special firewall event list. the list should have columns and layout like in common firewalls from sophos, fortinet, etc..
The list should contain source ip, hostname, port
destination ip, hostname, port
requested url
timestampsthese events should be available in computer details and in a global list where I can search for computer name, port, etc...
our hardware firewalls can only monitor traffic (allowed and denied request) between firewall zones. drivelock could fill the gap and list traffic between hosts in a zone.
also it is much easier to find blocked ports…
5 votes -
Defender Management - Identify outdated AV signatures correctly
The defender dashboard should not flag hosts as having an "outdated antivirus definition" when the "Last contact (DriveLock Agent)" is overdue as well.
This indicates an "offline" wokstation rather than a not working antivirus-update and is therefore confusing.
5 votes -
Collect "DLL started" and "DLL blocked" events without blocking them while Application Control Whitelisting of EXE files is still active
In a customer environment, where only the launch of EXE files is controlled by DriveLock, it is currently not possible to collect information about how Application Control would handle DLLs with the current policy set.
In order to collect "DLL started" and "DLL blocked" events, you have to change the "Scan- and Block-Mode" to include DLLs. This forces you to choose between Simulation Mode, which also affects the handling of EXE files, or "Active"-Mode, which would block all unknown DLLs immediately.
We would appreciate a feature that allows us to determine which DLLs would be blocked in our environment before…4 votes -
Support für Yubikeys 2FA DOC
Sehr geehrte Damen und Herren,
wir nutzen aktuell Yubikeys als 2. Faktor für unsere Admin PCs.
Das gleiche benötigen wir für das DOC.
Könnten Sie im DOC Support für Smartcards hinzufügen?
Die Yubikeys sind hier sehr viel praktischer, als die Token App.4 votes -
Syntax-basierte Benachrichtungsregeln - DOC
Aktuell können Benachrichtigungsregeln (E-Mail) im DOC nur auf Basis der Event ID getriggert werden.
Sinnvoll wäre die Möglichkeit, innerhalb der ID auf spezifische Syntaxinhalte filtern und alarmieren zu können.
BSP: EVENT ID 130 - The device HP LaserJet Pro M404-M405 was connected to the computer.;Device type: Media player.
Alle anderen Events zur ID130 sollen dann keine E-Mail Benachrichtigung im DOC zur Folge haben.
Filterung im Bereich der Eventgenerierung selbst, würde die ID nur einschränken. Es würden Informationen verloren gehen.4 votes -
new computer attribut to identify location
thanks to MQTT implementation it is now possible to know in the DOC if computers are alive and to communicate with them whereever they are (LAN, intertnet, home, ...). It would be nice to have a computer attribute available in the DOC computer view to identify where the PC is. The policy definition "network location" could be used for this.
4 votes -
DOC Should integrate AD attributes first- and last-
For company using number as login name it is not easy for DOC admin to identifiy on which PC a user is working. The DOC should integrates in the views operation>computers and operation>users the AD attributes firstname and lastname in order to be able to quickly identify loginname with real user. The column chooser functionallity should of course offers this two new attributes to be shown.
4 votes -
Alert frequency based rule
DriveLock should allow the creation of alert based on frequency and time. Ideally with boolean logic f.e:
-if event happens (more¦less) X time within Y minutes (most important one)
-if event happens between X am and Y pm
-if event does not happen between X am and Y pm
-if event happened at least X minutes after the last event
-if event not happened after X minutes of the previous event4 votesEvent happens more than x times in y seconds is already possible
-
Cleanup deleted Accounts
Hi,
Currently, there is no automatic cleanup within the DOC.
There are users within the DOC who have the “Active Directory Account” type. As soon as Drivelock's sync with AD detects that this account no longer exists, the account should also be deleted within the DOC, with a corresponding log entry.
This would help keep the environment clean without the need for custom scripting.3 votesThanks for the suggestion. As a first step, we plan to provide a manual delete option for users in the DOC. This would allow administrators to remove obsolete Active Directory accounts directly without requiring custom scripts.
Automatic cleanup could be considered separately, as this requires additional handling for references such as user group memberships.
-
Choose modules/options which are allowed for temporary unlock
We have a role-based setup in our company that allows the Helpdesk role to grant temporary unlocks in urgent situations. However, certain options and modules should not be accessible to this role.
In particular, for Application Control, it is critical that the Helpdesk can perform only a standard Application Control unlock. The options under “Executable files to add to the local hash database”, specifically:
Files written to the computer during the unlock period
Executables (and DLLs) launched during the unlock periodmust not be available to the Helpdesk role. These capabilities should be restricted exclusively to the Administrator role.
A…
3 votes -
Übermitteln der Seriennummern von angeschlossenen Druckern, Headsets etc.
Im Daily Business kommt es oft dazu, dass man gerne wissen würde welche Seriennummer der Anwender benutzt. Benutzt er einen Drucker von uns oder einen anderen Drucker?
Das kann man auch auf Headsets ausweiten. Weiterhin hilft dies natürlich dann auch um eine Inventur zu stützen.
3 votes -
Support for High Availability, Disaster Recovery with SQL Availability Group
Support for High Availability, Disaster Recovery with SQL Availability Group:
https://learn.microsoft.com/en-us/dotnet/framework/data/adonet/sql/sqlclient-support-for-high-availability-disaster-recovery#connecting-with-multisubnetfailover3 votes -
Verknüpfung beim Inhaltstest von Dateien sollte frei wählbar sein
Bei bspw. klassifizierten Dokumenten nach ISO 27001 sollte es möglich sein den Inhaltstest bspw. so zu definieren z.B. Typdefinition docx und ("Intern" oder "Öffentlich") und nicht ("Vertraulich" oder "Streng Vertraulich") . So kann sichergestellt werden das nur docx-Dateien exportiert werden dürfen die als Intern oder Öffentlich klassifiziert sind. Für diesen Ansatz müssten bestimmt Regeln auch negiert werden können.
3 votes -
Policy Assignments via DOC should include full path of AD objects
Actually , policy assignment in the DOC only shows f.e the name of the OU but not the AD Path. For organization using the same OU Name but under different path it is not possible to identify which OU to choose. Other objects might have the same problem.
3 votes -
Automatic alerts for expiring API-Keys and Information regarding last API-Key Usage
We need the capabilities to send out notifications about API keys which are expiring in X days or weeks.
Also an overview about the last usage of an api key would be very helpful.
These two options would help us to fulfill compliance and security standards.2 votes
- Don't see your idea?