Skip to content

DriveLock Product Feedback & Ideas


Share your ideas for DriveLock.

Submit improvement ideas, explore existing ones, and vote on what matters most.

Teilen Sie Ihre Ideen mit DriveLock.

Reichen Sie Verbesserungsvorschläge ein, sehen Sie bestehende Ideen und stimmen Sie ab.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback

24 results found

  1. SB-Freigabe weiter einschränken als Geräte-Typ

    In den Eigenschaften einer SB-Freigabe ist es lediglich möglich einzuschränken, ob Laufwerke / Geräte / Smartphones etc. freigegeben werden können. Es kann nicht weiter differenziert werden, welche Geräteklassen freigegeben werden können z.B. sollen nur USB-Controller freigegeben werden dürfen nicht aber Smartcard readers o.ä. .

    8 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  2. Inventory Daten dediziert löschen

    DriveLock sollte die Möglichkeit besitzen, Inventorydaten dediziert zu löschen. Hierbei sollten zwischen Drives / Devices / Applikationen usw. unterschieden werden können.
    In Kundenumgebungen die schon über mehrere Versionen hinweg bestehen, ist die Auswertung der Daten derzeit einfach zu unübersichtlich. DIe Möglichkeit den Rechner aus dem Operations Center zu löschen und danach das Inventar neu einzulesen ist m.E. nicht ausreichend.

    8 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  3. Reports should also have a Excel export choice.

    I've now seen a few clients who want a report in XLSX format. That they can forward to another department for automating some feature of the rollout software. As far as I know, only PDF is possible, but I could be wrong, of course.

    5 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  4. Drivelock Firewall logs

    The computer logs should be extended by a special firewall event list. the list should have columns and layout like in common firewalls from sophos, fortinet, etc..
    The list should contain source ip, hostname, port
    destination ip, hostname, port
    requested url
    timestamps

    these events should be available in computer details and in a global list where I can search for computer name, port, etc...

    our hardware firewalls can only monitor traffic (allowed and denied request) between firewall zones. drivelock could fill the gap and list traffic between hosts in a zone.

    also it is much easier to find blocked ports…

    5 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  5. Defender Management - Identify outdated AV signatures correctly

    The defender dashboard should not flag hosts as having an "outdated antivirus definition" when the "Last contact (DriveLock Agent)" is overdue as well.

    This indicates an "offline" wokstation rather than a not working antivirus-update and is therefore confusing.

    5 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  6. Collect "DLL started" and "DLL blocked" events without blocking them while Application Control Whitelisting of EXE files is still active

    In a customer environment, where only the launch of EXE files is controlled by DriveLock, it is currently not possible to collect information about how Application Control would handle DLLs with the current policy set.
    In order to collect "DLL started" and "DLL blocked" events, you have to change the "Scan- and Block-Mode" to include DLLs. This forces you to choose between Simulation Mode, which also affects the handling of EXE files, or "Active"-Mode, which would block all unknown DLLs immediately.
    We would appreciate a feature that allows us to determine which DLLs would be blocked in our environment before…

    4 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  7. Support für Yubikeys 2FA DOC

    Sehr geehrte Damen und Herren,
    wir nutzen aktuell Yubikeys als 2. Faktor für unsere Admin PCs.
    Das gleiche benötigen wir für das DOC.
    Könnten Sie im DOC Support für Smartcards hinzufügen?
    Die Yubikeys sind hier sehr viel praktischer, als die Token App.

    4 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  8. DOC Should integrate AD attributes first- and last-

    For company using number as login name it is not easy for DOC admin to identifiy on which PC a user is working. The DOC should integrates in the views operation>computers and operation>users the AD attributes firstname and lastname in order to be able to quickly identify loginname with real user. The column chooser functionallity should of course offers this two new attributes to be shown.

    4 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  9. 3 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  10. Verknüpfung beim Inhaltstest von Dateien sollte frei wählbar sein

    Bei bspw. klassifizierten Dokumenten nach ISO 27001 sollte es möglich sein den Inhaltstest bspw. so zu definieren z.B. Typdefinition docx und ("Intern" oder "Öffentlich") und nicht ("Vertraulich" oder "Streng Vertraulich") . So kann sichergestellt werden das nur docx-Dateien exportiert werden dürfen die als Intern oder Öffentlich klassifiziert sind. Für diesen Ansatz müssten bestimmt Regeln auch negiert werden können.

    3 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  11. Dynamische Benutzergruppen

    Aktuell besteht nur die Möglichkeit eine statische Benutzergruppe im DOC zu erstellen. Für unser Berechtigungskonzept benötigen wir jedoch auch hier dynamische Benutzergruppen, da wir uns auf das Active Directory beziehen. Mit mehreren dynamischen Benutzergruppe könnten wir uns viele AD-Berechtigungsgruppe sparen und gezielt Geräte bzw. Laufwerke innerhalb vom DOC berechtigen.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  12. Software Filterungsoption im Inventory - Nur aktuell installierte Software

    Hallo, bei der Nutzung des Inventory und der installierten Software wäre es super, wenn es eine neue Filteroption gibt. Es geht konkret darum, dass Software (sowohl gerade installierte, als auch alte nicht mehr installierte) aufgeführt wird, die nicht richtig gefiltert werden kann. Es fehlt die Option nach Software zu filtern, die auch den Haken unter "Installed" gesetzt haben.

    Im Moment muss man auf jede Software klicken, um zu sehen, ob diese auch installiert ist und kann nicht global filtern nach "ist wirklich auch gerade in dem Moment installiert".

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  13. Kampagnen fehlen im DOC die Triger

    Leider fehlen die Trigger wen die Kampagnen im DOC erstellt wird.
    So bekommen die User nicht mit das für die Gruppe eine neue Kampagne erstellt wurde.
    Bitte die Trigger wieder implementieren so das man einstellen kann das die Kampagnen nach Logon oder nach Event z.B. USB Stick einstecken gestartet werden soll.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  14. DOC configuration options for agent status outdated policy

    as soon as a new version of a policy is published, the computer status in the DOC change to Warning outdated policy. This should be configurable with either an offset ( policy version is not smaller than actual policy - offset ) or with a number of days ( new policy version exists since X days but still not deploy on the agent)

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  15. Automatic Recovery Key Backup in EntraID

    It would be nice if the Drivelock agent would initiate the Powershell command "BackupToAAD-BitLockerKeyProtector" everytime the agent sets or changes the recovery key.
    This would help to utilize the self-service from myaccount.microsoft.com for the end user to get their recovery keys via another device on their own.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  16. Self Service

    Hi,
    when using Self Service for application control, we have communicated the following settings to our administrative users, when installing software.

    1) Start Self-Service before starting the installation proccess
    2) Disable Application Control during Unlock Period, Add Application launched... (checked), Executable files added to the local hash database: FIles written during unlock period (checked), Require user approval .... (checked)
    3) Timespan and reason given

    AppControl is now unlocked and the software will be installed

    When ending the Self Service of AppControl, a list of files is displayed, where the files can be selected from, which have to be added to…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  17. Ability to Filter what syslog events I want to forward

    I know I can enable my events to be forwarded to a remote Syslog server, but we're missing an option to filter what events will actually be sent, at the source, in this case our DES tenant.
    That would be important for narrowing the data ingestion in our XDR, and also would enable us to better manage alerts and block incidents directly in MS Defender for example, in our case is only for Blocked Processes, eventId 473.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    Thanks for the feedback. We will track this as a feature request.

    Until source-side filtering is available in DriveLock, you should also be able to filter or discard unwanted events on the receiving SIEM/XDR side and only process the relevant event types, such as Event ID 473.

  18. SB Freigabe auf konkrete Regeln in AC beschränken

    Die SB-Freigabe sollte für die Module mehrfach hinzufügbar sein und in AC sollte dies auf konkrete Regeln eingrenzbar sein, damit z. B. nur eine Regel, die z. B. den Datei-Upload von Browser verbietet deaktiviert werden kann und nicht die komplette AC.
    Weiterhin wäre die Umbenennung der SB-Freigabe im Taskbar-Informationsbereich für ein besseres Verständnis der Endnutzer sinnvoll, so dass man dies z. B. als „Upload entsperren“ oder ähnlich benennt. Wer dies selten nutzt, wird nicht wissen was mit SB-Freigabe gemeint ist, da Anleitung beim Endnutzer auch oft nicht gelesen werden…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    I don’t think a temp unlock based on a rule is a good idea. The end user does not know what else is allowed or blocked when a rule is temporarily disabled.

    If we are able to support temp unlocks for binaries at some point, the Unlock UI could also show applications that were unable to perform certain actions because of ABC, which could then be temporarily allowed.

  19. SAML Anmeldung mit UPN

    Aktuell wird für die SAML-Authentifizierung immer der Identifier des Benutzers verwendet.
    Bei AD-Benutzern wird die SID verwendet. Die SID kann jedoch mit dem System als SAML-Response übergeben werden.
    Somit ist der SAML Login mit einem AD-User nicht möglich, wenn die Response keine SID enthält.

    Die SAML Einstellung sollten die Möglichkeit bieten sich mittels UserPrincipalName anzumelden.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
  20. user feature permission summary tab

    We use the DriveLock default user rights roles and if a functionality for e.g. the helpdesk is missing, we create a separate role for each function or right in order to be able to assign permissions more granularly. The disadvantage of this approach is that it quickly becomes confusing and inefficient in the user permission/user role overview or research.
    A separate item under the respective selected user, in which all cumulative rights from the respective assigned roles are then listed, e.g. analogous to the role interface, in order to gain a quick overview of what the corresponding user is really…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
← Previous 1
  • Don't see your idea?