DriveLock Product Feedback & Ideas
Share your ideas for DriveLock.
Teilen Sie Ihre Ideen mit DriveLock.
82 results found
-
Restart option after agent update
Currently, a reboot before updating the agent can be configured via the option "Reboot to update agent". This causes the users to be logged out first, then DriveLock is updated and then a reboot occurs. If users logs on immediately afterwards, they can work for 2-3 minutes before a reboot occurs without further warning.
It would be better for the users if the update would happen in the background without reboot (similar to push install/push update via the DCC). The user should get after successful update a message that he should close all programs because the computer reboots. This reboot…
13 votesI don't see it as particularly important, because a reboot during an update is usually not useful. only FFE and FDE actually need a reboot - but only later when the agent is already running again and not when the msi is finished.
-
USB tethering
Add an option to block connecting to the Internet by using usb tethering on your smartphone (android and apple).
Usb tethering creates a Remote NDIS based Internet Sharing Device.
11 votesWorks as designed. This can be solved by controlling network cards and then explicitly blocking this smartphone "network card". This is not a workaround but a solution.
-
Automatic client uninstallation when license revoked
Client, which are in a licensed PUSH-OU get the agent automatically installed.
If the client is removed from this, the agent should also be uninstalled again (as with FDE).
The DCC/DOC must also be "informed" about this.
Background is that with a Client with an agent - if necessary inadvertently in the "wrong" OU was installed - but is outside of the "Licensed Group" can neither be administered nor even devices allowed without the agent clean - unfortunately only by "hand" is removed. With geographically distant devices within the organization, this leads to significant problems. With a "network rule" even…
11 voteswe consider automatic uninstallation to be potentially dangerous. We recommend the use of a software distribution solution (UEM)
-
Identifying a computer using IP address (or some other unique value) vs hostname
In a customer environment where many computers share the same hostname (eg. machines in a large distributed convenience store infrastructure), it would be very useful to be able to register the computer via its IP address or some other unique value, instead of just relying on hostnames/FQDN. Perhaps a feature to allow the customer to select the IP address (or a unique agent registration ID) to be used in our management and operations consoles - without the need for scripting or a convoluted workaround.
8 votesThank you for your feedback. We understand the need to uniquely identify computers in environments where identical hostnames are used across different domains within the same tenant.
Supporting this scenario would require coordinated changes across several DriveLock components, including careful consideration of update scenarios and backward compatibility. Due to the scope and complexity involved, we are currently unable to prioritize this request.
-
Security Education - create your own quiz
The possibility to create your own questionnaire for security awareness content (as you know it from the prefabricated content).
8 votes -
DCC/DOC: Restart agent service via remote connection
Occasionally there will be a need to manually restart the main DL agent service (enforce policy update, etc.). Suggesting to add the possibility to perform agent service restart while connected remotely using DCC or DOC. This is to be restricted to specific admins/operators only.
6 votesThank you for your suggestion. We do not currently plan to add an option to restart the DriveLock Agent service remotely through DCC or DOC.
The agent is designed to apply configuration and policy changes without requiring a service restart. Situations in which a restart is necessary should therefore be investigated as a technical issue through the appropriate support channel.
For this reason, we are closing this request.
-
Full support of IPv6 protocoll
All DriveLock components are able to communication using IPv6. An admin can configure IPv6 addresses in the relevant sections in the DriveLock Management Console and the DriveLock Control Center.
6 votes -
Security Awareness Calendar
It should be possible that when you create new campaigns, that I create, for example, several user login campaigns and every day / every week a different campaign is displayed, without the need to intervene. A kind of predefined schedule.
So that I can set granular, Monday campaign 1, Wednesday 2, Friday 3 always at user login.
Or even campaign 1 in week X on day Y, campaign 2 in week Z on day A,..........
And of course also for event triggered and for rule based.5 votesIt is possible to select the start and end of a campaign from the DOC using the calendar selector. For recurring campaigns, we only offer the option of selecting the type of repetition, but not the exact day of the week. This feature is canceled
-
Security Awareness - EInstellungen für Kampagnen von der DMC in das DOC übertragen
Die Einstellungen für Awareness Kampagnen, welche in der DMC verfügbar sind, sollten auch über das DOC verfügbar sein.
Trigger: Zu welchem Ereignis soll die Kampagne angezeigt werden?
Wann/ wie oft soll die Kampagne wiederholt werden?
Benutzer muss bestätigen
Vollbild ja / nein?4 votesDriveLock is introducing a new security awareness solution. Please contact your sales representative.
-
Format BitLocker2Go USB removables like in Encryption2Go
In Encryption2Go it is possible to format the USB removables before encryption and keep the data if necessary - these options are completely missing in BitLocker2Go.
4 votesThe options exist because in the old days everything was formatted with FAT, where you could not create containers larger than 4 GB. This made things easier for the customer. This is not necessary with BitLocker To Go.
-
DriveLock License Management (expire dates) over DOC, within an Enterprise Environment
DES Servers, running into an an protected Enterprise Environment configured according Microsoft's Recommendation
for an Enterprise-Access-Modell, should be able to renew their License Date (Maintenance Date) over the DOC,
without having direct Internet access, and without getting each year a new license to activate by phone.
An Implementation idea is maybe a Windows 10 Client System running DOC Companion, while the Client have
Internet Access over a Company Proxy Server, to renew the License at the DES Server backend.4 votesif you issue a new license annually (or whenever the maintenance is extended), then you don't even need one without activation, because the mmc does the activation and you can run it on a computer with internet access or use the telephone activation. You can either activate by telephone or issue the customer with a license without activation. Subscription licenses have to be reissued anyway, at least until now
-
DL2GO hidding the original drive letter
After mounting the stick with DL2Go the original letter should be hidden and there should be no windows error, because this is confusing for the user.
4 votesOur development team evaluated possible technical solutions to hide/show drive letters in Windows “on the fly”. Currently (with Windows 10) it is not possible to manually hide existing drive letters (1) in a reliable way, (2) on the fly without any user interaction and (3) without possibly hacking into Windows core features.
Because of these circumstanced we will not be able to deliver the demanded feature, although we understand the customer value for it. -
DriveLock File Protection: Support for NetApp Fileserver with SMB-Shares
DriveLock should support NetApp file servers in addition to SMB shares from Windows servers for storing centrally managed folders. NetApp products are often used in enterprises as storage solutions.
Currently, a centrally managed folder cannot be used on a NetApp-provided SMB share.4 votes -
Persistant File Encryption
As a user I want to have files automatically encrypted when saved into a specific directory, but when I copy or move this file out of this directory it should stay encrypted until an authorized user explicitly stores a decrypted version or manually decrypts it.
4 votes -
Use my existing SCORM content in Security Awareness Campaigns
Our company has existing trainings/videos in standard SCORM 1.2 format and we would like to use this content within DriveLock's security awareness campaigns.
Currently only SCORM material published by DriveLock can be used.4 votesDue to the low number of votes and comments of the last year this feature request is declined for now.
-
Display estimated remaining scan time when a USB stick is inserted
We would like to see approximately how long the scan takes as soon as a USB stick is inserted.
3 votesUnfortunately, this issue cannot be resolved at the moment. To scan, we call the command line version of the Defender MpCmdRun.exe. While this action initiates the scanning process, it does not provide any feedback or progress updates.
-
Freitexteingabe bei Awarenesskampagnen
Es gibt ja schon die Möglichkeit, bei Security Awareness Kampagnen den User zu "nötigen", einen Haken zu setzen bzw. eine gewisse Zeit ein Bild zu betrachten.
Was ist von der Idee zu halten, dem User nach gesehenem Video / gelesenem Text / betrachtetem Bild ein Freitext-Feld mit der Antwort auf eine Frage befüllen zu lassen?
Frage und Antwort werden dokumentiert und können ggf. im Nachgang besprochen werden.3 votes -
Security Awareness Statistik in DOC aufräumen oder in Arcive verschieben
Statistics in DOC
Arcify or clean up to get a better overview3 votesA lot has happened in the area of awareness evaluations since 23.2 and this area will be expanded with 24.1.
-
Controlling Defender Core Isolation with Drivelock Policy Setting
It should be possible to control the memory integrity setting of the Core Isolation Feature within the Windows Defender Antivirus via Drivelock policy.
In addition, you should be able to hide the feature for your clients.
3 votesThank you for your valuable feedback! While this specific feature isn't on our current roadmap, we continuously evaluate requests, and we'll keep your input in mind for future improvements.
-
Netzwerkconnection anhand des primären DNS-Suffix bei jedem Verbindungsaufbau
Wir würden gerne die Netzwerkrichtlinien von Drivelock nutzen, damit die verwalteten Clients sich ausschließlich mit unserem Domänennetzwerk verbinden und im laufenden Betrieb auch die Netzwerkschnittstellen wechseln können. Dies würden wir gerne anhand des primären DNS-Suffix abfragen.
Momentan gibt es diese Möglichkeit bereits, doch wird diese Abfrage lediglich einmalig abgefragt und nicht bei jedem erneuten Verbindungsaufbau.
Wir wollen unseren Clients ermöglichen, dass sie sich sowohl über Wlan, als auch über Kabel verbinden und auch während einer Sitzung wechseln können.
Um dies zu erreichen, müsste unter dem Kartenreiter "Action" im Eigenschaftenfenster der Netzwerkrichtlinien eine Auswahl ähnlich wie "Disable network connection until new…3 votesThe functionality you require should already be possible today. However, if the card is deactivated, it is not possible to recognize whether the correct DNS suffix is present in order to reactivate the card. However, if the card is activated manually, this is already possible today.
DriveLock checks the network connection again with every policy update and network change.
Firewall rules can also be set up to control the network connection; it may be possible to do this via the firewall by setting up a rule that blocks all connections as long as the device is not in the correct network. If an attempt is made to access the wrong network, a corresponding firewall rule must be created that blocks everything (with the exception of the rules required for a network change). In the event of a change to the correct network, the corresponding rule must be removed again.
If…
- Don't see your idea?