Skip to content

DriveLock Product Feedback & Ideas


Share your ideas for DriveLock.

Submit improvement ideas, explore existing ones, and vote on what matters most.

Teilen Sie Ihre Ideen mit DriveLock.

Reichen Sie Verbesserungsvorschläge ein, sehen Sie bestehende Ideen und stimmen Sie ab.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback

82 results found

  1. Share custom DOC dashboards & widget via UserVoice

    Suggesting to allow and facilitate sharing of custom DOC dashboards and widgets created by DriveLock users (customers, resellers, consultants, etc.) via UserVoice or any other suitable platform.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    declined  ·  0 comments  ·  UX / UI / DOC  ·  Admin →
  2. Too many messages, event ID: 129, because of locked devices

    Every time a user connects an iPhone or Android phone to a computer, our Drivelock server gets a message that a device has been connected there. This is not allowed by us and the device will be locked, then different
    Messages are sent Event ID: 129.
    Now my question, is it possible to create a rule in these cases:
    That the user always gets a message (bigger message, not only in the systray) to disconnect the device immediately until he disconnects the device? So that always new messages appear, which the user must click away and he is quasi forced…

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

  3. Client update feedback message

    It would be good to see if a client performs an update installation after the release or gives a status that something is happening.
    Often we have the problem that users unintentionally turn off the devices during the drivelock installation, because they don't know that one is running. A popup or something like that would be nice.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

  4. Agent Updates with Citrix 2016 Desktop

    We use Citrix 2016 Desktop as an alternative to software distribution in our agency. With agent updates, the respective end devices should always be rebooted as soon as possible. However, we cannot set this in the update policy because the users cannot see the reboot warnings in the Citrix session, they only appear on the Citrix host. The devices would then just reboot and kick the users out of the Citrix session.

    We would need to find a way to make the message visible in the Citrix desktop. Perhaps the reboot warning could also appear in the Windows notifications. We…

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Others  ·  Admin →
  5. EDR new responses (email, snmp, ...)

    actually responses definition include Powershell, Batch, Command line, Awareness and taken picture. It should be extend to E-Mail, SNMP Trap and Web-hook. At least E-Mail should be implement. That way one could decide to send E-Mail based on filtered event.

    It is actually possible to send E-Mail for a complete event-type but not to define further condition under which the E-Mail should be sent ( user, folder, computer, etc, ...). Of course it is possible to write script but E-Mail is already there in the solution.

    It sould be although possible to restrict the action repetition if one action (f.e…

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    Fine-grained notification logic (E-Mail/SNMP/Webhooks based on filtered events) is better handled by external SIEM/SOAR or automation platforms. Implementing this within the EDR response engine would duplicate functionality and conflict with the current platform architecture strategy.

  6. Change Agent User Interface

    Dear DriveLocker,
    it would be nice if you could show the self-service unlock as a tile on the agent user interface.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

  7. Temporary unlock with scripts

    Sometimes a temporary unlock is almost a daily routine I notice with some customers. Example: PCx, 30 minutes free for USB. With input of PC and time, maybe even from-to (the from is not possible yet) would be very nice with a script. I need to be able to trigger this remotely of course.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    As there have not been any additional votes on this idea, we will not implement such kind of functionality into DriveLock.

    Also because it would introduce a way to bypass security features currently available.

  8. Power management

    Actions under "power management" should have the option for notebooks in docking station or without alternative with ethernet/power supply or without connection. Otherwise, there is a risk that a notebook in the notebook bag performs an action. It would also be good to configure power options with all setting options as under Windows to establish itself as a central device management solution.

    2 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    Currently most customers do not use these settings and so we will probably deprecate this feature in a future release.

    Therefor we will not put efforts into further enhancing this capability.

  9. Nicht definierte Geräteklassen sperren

    Die Kontrolle von Geräten, bzw. Geräteklassen greift nur für bekannte und konfigurierte Geräteklassen. Angeschlossene Geräte, die keiner der vorhandenen Geräteklasse zugeordnet sind werden nicht gesperrt/kontrolliert.

    Es wäre also hilfreich eine Regel in "Geräteklasse" für "unbekannte Geräteklassen" zu definieren, die alle Gerät abdeckt, für die noch keine Geräteklasse existiert.

    Somit kann sichergestellt werden, dass die Gerätekontrolle auch wirklich für alle Geräte konfiguriert werden kann.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    Thank you for your feedback. We have reviewed this request and decided not to implement it.

    Blocking unknown device classes could create a high risk of unintended side effects on system stability. Therefore, device control should continue to be configured using known and explicitly defined device classes.

  10. Automatisierte Authentifizierung der DriveLock PBA im internen Netzwerk

    In unserer Umgebung wäre es äußerst hilfreich, wenn die DriveLock PBA so konfiguriert werden könnte, dass bei erkannter Verbindung zum internen Unternehmensnetzwerk keine Benutzerinteraktion erforderlich ist und der Bootvorgang automatisch direkt in das Windows-Betriebssystem übergeht.

    Ziel:
    - Im internen Netzwerk: Automatischer Bootvorgang ohne Benutzereingabe (z. B. Passwort).
    - Außerhalb des Netzwerks: Beibehaltung der vollständigen PBA-Authentifizierung zur Sicherstellung der Gerätesicherheit.

    Ein vergleichbares Verhalten lässt sich bei einer reinen BitLocker-Implementierung über die Verwendung von Netzwerkzertifikaten (Network Unlock) realisieren.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    declined  ·  0 comments  ·  Encryption  ·  Admin →
  11. DOC: X-XXS-Protection aktivieren

    DOC: Durch ein Audit ist aufgefallen das der Parameter X-XXS-Protection nicht gesetzt ist. Da dies als Abweichung gilt wäre es gute wenn dieser Paramter gesetzt werden könnte

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Others  ·  Admin →
  12. Integration of Windows Hello (PIN) in the PBA for login

    Please integrate Windows Hello (at least PIN) into your PBA as an additional login option.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    Pre-Boot Authentication (PBA) is a security measure that occurs before the operating system starts. It ensures that only authorized users can boot the system.

    Windows Hello is Microsoft’s modern authentication framework that supports:

    - PIN, Face recognition, Fingerprint login

    Important: Windows Hello only works after Windows has started. It's part of the Windows login process, not pre-boot.

    Windows Hello is a post-boot authentication mechanism.

    PBA takes place before the OS loads, often in a custom mini-OS or bootloader from security vendors.

    This means Windows Hello cannot be used in traditional PBA environments, unless a vendor mimics its behavior (e.g., using a similar PIN mechanism).

    Windows Hello cannot be directly integrated into traditional PBA because it is tied to Windows.

    What is possible: PIN-based authentication in the PBA, similar to Windows Hello, but not using its APIs.

    What I would find more interesting is MFA with an authenticator app (i.e., displaying…

  13. Funktionen bei Mehrfachselektion ermöglichen

    Da nach Behandlung von Schwachstellen z.B. durch Softwareupdates die Schwachstelle nicht automatisch aus der Übersicht entfernt wird, muss diese manuell "ausgeblendet" werden.
    Treten nun an einem Rechner zu einem bestimmten Produkt mehrere Schwachstellen auf, wäre es vorteilhaft man könnte in der Mehrfachselektion alle betroffenen Schwachstellen markieren und gesammelt "ausblenden".
    Leider stehen bei der Mehrfachselektion keine Funktionen zur Verfügung.

    "Multiple (474) items are selected. No additional information or actions available"

    Beispiel:
    An einem Client ist Software XYZ veraltet und es werden mehrere Schwachstellen aufgeführt. Ich aktualisiere Software XYZ an diesem Client und möchte nun alle Schwachstellen ausblenden. "Ausblenden für alle Computer"…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    Once the scan is run again after the necessary patches have been applied, the identified vulnerabilities will be automatically closed. Consequently, we believe that implementing this feature request is unnecessary from our perspective.

  14. 1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

  15. Customizable Language and Text for Security Awareness Invitation Emails

    Es wäre sehr Hilfreich wenn man de Standard Sprache innerhalb der Domäne Festlegen könnte.
    Und wenn man den Text der vom DOC verteilten E-Mail selbst anpassen kann.
    Das zum Beispiel der Display Name statt des Logins nach dem Hallo kommt

    Und der Text zum Test in der Mail dem CI entspricht.
    Da der Standard Text der DriveLock Awareness E-Mail von vielen Mitarbeitern als Spam war genommen wurde.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

  16. Filter im Knoten Betrieb - Agenten Ferncontrolle

    In der DMC sollte es möglich sein unter dem Knoten einen Filter zu implementieren, so das man z.b. Nach dem Computernamen oder dem angemeldeten Nutzer Filtern kann. Bei ca. 10000 Computern ist ohne Filter ein suchen sehr mühselig

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

  17. Check PBA Prerequisites - availibility of CA-certifiate "Microsoft Corporation UEFI CA 2011"

    Many new notebook systems of the manufacturers HP and Lenovo are shipped with the CA-certifictate
    "Microsoft Corporation UEFI CA 2011" disabled in their firmware settings.

    The DriveLock-PBA is signed with this CA-certificate. So this CA-certificate needs to be enabled and
    available on a system in advance of installing the DriveLock-PBA.

    The installation routine of the DriveLock-PBA should verify if this CA-certifiacte is enabled and available on a system
    when attepmpting to install the PBA, and write a message of level=Error when detecting this CA-certificate is not available
    on a system.
    With this enhancement the administrator of a DriveLock environment will…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Encryption  ·  Admin →

    Since version 23.1 there is a message with EventID=757 “SecureBoot is enabled but the Microsoft Corporation UEFI CA 2011 certificate is missing.”. This function is therefore already implemented. Please configure this event in a policy so that it is sent from clients to the DES.

  18. Freigabe von Softlinks (via mklink erzeugt)

    Bei der Freigabe von Pfaden werden keine Softlinks (via mklink erzeugt) berücksichtigt. Hilfreich wäre eine Ausnahme für Softlinks (via mklink erzeugt) als Ausnahme zu definieren, während der Ursprungspfad per WL Regel gesperrt bleibt.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    Thank you so much for your suggestion regarding the allowance of soft links created via mklink.

    Our system currently resolves paths upon access, meaning we ultimately only see the resolved path, not the soft link itself. As a result, we're unable to differentiate or specifically allow soft links without impacting existing security mechanisms. Therefore we unfortunately have to reject this request.

    We really appreciate your understanding and are here if you have further questions or feedback.

  19. Wiederholung von Fehlgeschlagenen Installationen

    Wir lassen Drivelock automatisch Installieren, indem Drivelock bestimmte AD-Verzeichnisse scannt.
    Jetzt ist der Server aber ausgelastet oder Systeme sind zu dem Zeitpunkt nicht mehr am Netzwerk, da die Systeme nach der Installation des Betriebssystems ausgeschaltet werden und dann erst im AD verschoben werden.
    Der Scann des ADs erfolgt anscheinen nur zu jeder vollen Stunde und dies lässt sich leider nicht ändern.

    Kann man implementieren, dass Drivelock fehlgeschlagene Installationen (Netzwerkname wurde nicht gefunden, RPC-Server ausgelastet etc) nicht regelmässig wiederholt?

    RPC-Server ausgelastet vielleicht zur nächsten vollen Stunde immer wieder.
    Netzwerkname nicht gefunden alle 8 Stunden.

    Allgemein finde ich es als Verantwortlicher etwas…

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Others  ·  Admin →
  20. PC Neustart bei Push-Installation verzögern

    Beim Update besteht ja über die Konfig die Möglichkeit, den Reboot des Clients zu verzögern.
    Bei der Pushinstallation, wenn man den Restart anklickt, erfolgt dieser ja nahezu sofort, ohne das die Möglichkeit besteht Daten zu sprichern.

    Toll wäre es, wenn man hie die selben Einstellungen wie bei einem Update machen könnte, um dem Benutzer die Möglichkeit zu geben, den Neustart z.B. in eine Pause zu legen.

    Den es ist Dumm, wenn der Neustart plötzlich während der Arbeit erfolgt. z.B. bei einem Meeting, Videokonferenz, Kundengespräch etc.

    1 vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Others  ·  Admin →
  • Don't see your idea?