DriveLock Product Feedback & Ideas
Share your ideas for DriveLock.
Teilen Sie Ihre Ideen mit DriveLock.
74 results found
-
Reports should also have a Excel export choice.
I've now seen a few clients who want a report in XLSX format. That they can forward to another department for automating some feature of the rollout software. As far as I know, only PDF is possible, but I could be wrong, of course.
5 votes -
Erweiterung der unterstützten Dateitypen
Um die Kontrolle bezüglich Dateityp-Definitionen zu erweitern, wäre es hilfreich, wenn Drivelock folgende Archive unterstützt:
- .TAR
- .GZ
- .TAR.GZ
Wenn keine Kontrolle möglich ist, würde nur eine Sperrung übrig bleiben, welches die Funktionalität im Daily-Business einschränkt6 votes -
Notification when Files are moved to %LocalAppData%\Temp\DlDeleted
When ZIP files that contain prohibited files (File Filter) are cut and pasted (Strg+X -> Strg+C) to a USB mass storage device, DriveLock moves them to %LocalAppData%\Temp\DlDeleted instead. This is done to prevent data loss, since the files are deleted by Strg+X and cannot arrive at the destiniation due to the blocking of the file transfer
We would appreciate the following Changes:
a) Instead of moving it to %LocalAppData%\Temp\DlDeleted, the file should be moved back to its original location
b) If a) is technically infeasible, the user should be notified by DriveLock that their file has been moved to %LocalAppData%\Temp\DlDeleted.…4 votes -
Support for more Archive-Formats in File Filter
can only examine the contents of .ZIP, .7z and .rar archives.
We would like DriveLock to support more archive and compression formats like: .gz, .tar, .bz2, .xz and .zst.
Support of disk images like .iso files would also be appreciated4 votes -
Cleanup deleted Accounts
Hi,
Currently, there is no automatic cleanup within the DOC.
There are users within the DOC who have the “Active Directory Account” type. As soon as Drivelock's sync with AD detects that this account no longer exists, the account should also be deleted within the DOC, with a corresponding log entry.
This would help keep the environment clean without the need for custom scripting.3 votesThanks for the suggestion. As a first step, we plan to provide a manual delete option for users in the DOC. This would allow administrators to remove obsolete Active Directory accounts directly without requiring custom scripts.
Automatic cleanup could be considered separately, as this requires additional handling for references such as user group memberships.
-
Collect "DLL started" and "DLL blocked" events without blocking them while Application Control Whitelisting of EXE files is still active
In a customer environment, where only the launch of EXE files is controlled by DriveLock, it is currently not possible to collect information about how Application Control would handle DLLs with the current policy set.
In order to collect "DLL started" and "DLL blocked" events, you have to change the "Scan- and Block-Mode" to include DLLs. This forces you to choose between Simulation Mode, which also affects the handling of EXE files, or "Active"-Mode, which would block all unknown DLLs immediately.
We would appreciate a feature that allows us to determine which DLLs would be blocked in our environment before…4 votes -
Policy Management mit REST API & ServiceNow Integration für Automatisierung
REST API für ServiceNow-Integration, um das Management von DriveLock Policies vollständig zu automatisieren und in bestehende Enterprise-Prozesse zu integrieren.
Dabei sollte die automatisierte Erstellung und Änderung von Policies, einzelner Policy-Einstellungen und Whitelist-Regeln sowie die Zuweisung von Policies möglich sein.
Für Enterprise-Organisationen ist es entscheidend Automatisierung und Orchestrierung zu ermöglichen.
1 vote -
Bitlocker-Wiederherstellungskennwörter im Stapel für alle Clients exportieren
Die Schaffung einer Möglichkeit alle Bitlocker-Wiederherstellungskennwörter im Stapel aus Drivelock zu exportieren zu exportieren?
1 vote -
Zertifikatsablaufdatum soll angezeigt werden
Das Ablaufdatum bzw. die Eigenschaften eines Zertifikats (Gültig von... bis) soll als Spalte auswählbar sein. Zum einen in der Eventansicht, aber ebenfalls unter Security Controls - Applications - Certificates um eine Auswertung der bald-ablaufenden Applikationen zu erstellen.
Ein Warnhinweis für bald-ablaufende Zertifikate die in einer Regel verwendet werden, wäre optimal um Sperrungen zu verhindern.
1 vote -
Zertifikatsablaufdatum soll angezeigt werden
Das Ablaufdatum bzw. die Eigenschaften eines Zertifikats (Gültig von... bis) soll als Spalte auswählbar sein. Zum einen in der Eventansicht, aber ebenfalls unter Security Controls - Applications - Certificates um eine Auswertung der bald-ablaufenden Applikationen zu erstellen.
Ein Warnhinweis für bald-ablaufende Zertifikate die in einer Regel verwendet werden, wäre optimal um Sperrungen zu verhindern.
1 vote -
Automatic alerts for expiring API-Keys and Information regarding last API-Key Usage
We need the capabilities to send out notifications about API keys which are expiring in X days or weeks.
Also an overview about the last usage of an api key would be very helpful.
These two options would help us to fulfill compliance and security standards.2 votes -
Automatic Recovery Key Backup in EntraID
It would be nice if the Drivelock agent would initiate the Powershell command "BackupToAAD-BitLockerKeyProtector" everytime the agent sets or changes the recovery key.
This would help to utilize the self-service from myaccount.microsoft.com for the end user to get their recovery keys via another device on their own.1 vote -
Erweiterung der zeitlichen Steuerung für temporäre Freigaben in Device/Drive Control (DOC)
Im Zuge der Migration von Funktionen aus der DMC nach DOC ist uns aufgefallen, dass temporäre Freigaben für Geräte und Laufwerke aktuell auf 35.700 Minuten begrenzt sind. In der DMC konnte der Zeitraum frei gewählt werden. Ist das so gewollt oder gibt es einen techn. Erklärung?
Gerade für längerfristige Ausnahmen (z. B. Smartphones, USB Drives für den tägl. Gebrauch oder ext. HDD's, die jeweils jährl. rezertifiziert werden müssen) ist diese Einschränkung unpraktisch und führt zu unnötigem Verwaltungsaufwand.
Alternativ wäre es auch möglich, wenn Regeln selbst auch zeitlich befristet werden könnten (Start- und Enddatum). Nach Ablauf des definierten Zeitraums sollten sie…
1 vote -
Verbesserung der Barrierefreiheit von Windows-Toast-Benachrichtigungen in Application Control und Port Control
Im Rahmen der Barrierefreiheitsanforderungen möchten wir einen Feature Request für DriveLock Application Control und Port Control einreichen.
Aktuell werden die Windows-Toast-Benachrichtigungen von DriveLock nicht von Screenreadern (z. B. NVDA) vorgelesen, sofern die Benachrichtigung nicht im Fokus ist.
Dadurch können sehbehinderte oder blinde Anwender sicherheitsrelevante Benachrichtigungen nicht wahrnehmen.
Wir wünschen uns daher eine Anpassung der Implementierung, sodass die von DriveLock erzeugten Windows-Toast-Benachrichtigungen von gängigen Screenreadern zuverlässig erkannt und vorgelesen werden, ohne vorher durch ein Klick das Fenster in den Fokus gerät.
Die Umsetzung dieses Anliegens ist für uns von hoher Priorität. Daher würden wir uns über eine Einschätzung freuen, mit welchem…
1 vote -
Feature Request – Native Let's Encrypt / ACME-Integration für automatisierte Zertifikatsrotation (90-Tage-Zyklen)
Beantragt wird die Implementierung einer nativen oder offiziell unterstützten Automatisierungsschnittstelle für das ACME-Protokoll (z. B. Let's Encrypt) zur automatischen Beantragung, Erneuerung und Bindung von SSL/TLS-Zertifikaten für den DriveLock Enterprise Service (DES) und das DriveLock Operations Center (DOC).
DriveLock sollte den Prozess durch eine integrierte Automatisierungslogik übernehmen, die im Hintergrund nahtlos mit ACME-Clients wie win-acme interagiert oder einen nativen ACME-Client in den DES integriert.
Eine robuste Umsetzung sollte folgende Kernfunktionen umfassen:
Zertifikats-Beantragung & Renewal-Triggering: Ein konfigurierbarer Job innerhalb der DriveLock-Konsole, der (ähnlich wie win-acme per Scheduled Task) rechtzeitig vor Ablauf (z. B. an Tag 60) die Erneuerung anstößt.
Unterstützung für DNS-01…
1 vote -
Choose modules/options which are allowed for temporary unlock
We have a role-based setup in our company that allows the Helpdesk role to grant temporary unlocks in urgent situations. However, certain options and modules should not be accessible to this role.
In particular, for Application Control, it is critical that the Helpdesk can perform only a standard Application Control unlock. The options under “Executable files to add to the local hash database”, specifically:
Files written to the computer during the unlock period
Executables (and DLLs) launched during the unlock periodmust not be available to the Helpdesk role. These capabilities should be restricted exclusively to the Administrator role.
A…
3 votes -
Self Service
Hi,
when using Self Service for application control, we have communicated the following settings to our administrative users, when installing software.1) Start Self-Service before starting the installation proccess
2) Disable Application Control during Unlock Period, Add Application launched... (checked), Executable files added to the local hash database: FIles written during unlock period (checked), Require user approval .... (checked)
3) Timespan and reason givenAppControl is now unlocked and the software will be installed
When ending the Self Service of AppControl, a list of files is displayed, where the files can be selected from, which have to be added to…
1 vote -
Customizing Multiple-Line-Chart-Widgets
Für eine übersichtliche Gestaltung eines Custom Dashboards sollte es möglich sein, Multiple-Line-Charts Widgets zu customizen.
Beispiel UseCase wäre die Darstellung der Auslastung und Verteilung auf die einzelnen LinkedDES.
Zweiter UseCase, wie veile Events von einem bestimmten Type oder ID sind über eine Woche aufgetreten.2 votes -
Nach Beschreiben eines USB Datenträgers Datei sollte Datei lesbar sein
Hallo,
nach dem Beschreiben eines zuvor, an einer Index Scanstation gescannten USB-Wechseldatenträgers kann die Datei anschließend nicht mehr geöffnet bzw. angezeigt werden. Dadurch ist es derzeit leider nicht möglich, die eigene Datei auf dem Wechseldatenträger nochmals zu kontrollieren.Es sollte möglich sein, dass die Datei nach dem Beschreiben an einem sicheren PC weiterhin lesbar bleibt, solange der USB-Datenträger noch am PC angeschlossen ist.
Bitte prüfen Sie dieses Verhalten nochmals.
Vielen Dank im Voraus.
1 vote -
Direkter Link aus E-Mail-Benachrichtigung zum Event im DOC
Direkter Link aus E-Mail-Benachrichtigung zum Event im DOC
Beschreibung:
E-Mail-Benachrichtigungen zu Sicherheitsereignissen enthalten derzeit keinen direkten Zugriff auf das zugehörige Event in der zentralen Management-Konsole (DOC).Anforderung:
Bereitstellung eines direkten Links in der E-Mail-Benachrichtigung, der Anwender unmittelbar zum entsprechenden Event im DOC führt.Nutzen:
Schnellere Analyse und Reaktion auf Ereignisse
Reduzierter manueller Suchaufwand im DOC
Effizientere Bearbeitung durch Support und Administratoren1 voteVielen Dank für den Vorschlag. Wir nehmen das als Feature Request auf.
Ein direkter Deep Link auf ein einzelnes Event ist aktuell technisch nicht möglich, da einzelne Events im DOC keine eigene URL besitzen. Eine mögliche Lösung wäre jedoch, die Event-Ansicht bereits passend gefiltert zu öffnen – z. B. anhand des Zeitstempels des Events. Alternativ könnte zukünftig auch ein eindeutiger Event-Identifier verwendet werden.
- Don't see your idea?