Help Center

Third-party software Contact us

Device configuration

Device configuration overview

Device configuration is the process of setting up and organizing endpoints so they can be used as scope for creating policies, scans, and monitoring profiles.

Endpoint-level actions—including monitoring, reporting, and policy enforcement—should be executed against a defined set of configured devices, which makes device configuration a prerequisite for all other setups.

DataSecurity Plus enables administrators to configure:

  • Individual devices: Standalone endpoints that can be managed independently.
  • Device groups: Logical collection of endpoints that can be managed as a single unit.

Why is configuring endpoints as device groups recommended?

Configuring endpoints in groups is beneficial, as it:

  • Scales efficiently across a large numbers of devices.
  • Reduces repetitive configuration effort.
  • Ensures consistent settings across devices.
  • Minimizes configuration errors.
  • Simplifies ongoing maintenance, including onboarding new endpoints through centralized updates.

Prerequisite for creating device groups:

  • Ensure that endpoints are available through configured domains or workgroups in DataSecurity Plus before creating device groups. Find the steps to configure domains here.
  • You are signed in using an Admin account, with access to Admin Console.

How to create a device group

The steps below outline how to create a device group:

  • Open the DataSecurity Plus console. Choose Admin Console from the Apps drop-down at the top.
  • Go to Administrative Settings > Device Groups. In the Device Groups page, click + Create Group.
  • On the Create Group page, enter an appropriate Group Name and Description.
  • Under Assign Members, choose whether to add endpoints to the group manually or using OUs.
  • To add endpoints manually:

    Click +Add Device. In the Select Devices pop-up, choose the domain from which you want to add devices. Use the drop-down to switch between configured domains and select the endpoints you want to add. Review your selection in the Selected Devices tab, which lists all endpoints selected across all domains, along with their canonical names. Click Create Group after review.

    To add endpoints using OUs:

    Click +Add OU. In the Select OUs pop-up, choose the domain from which you want to add OUs. Use the drop-down to switch between configured domains and select the OUs you want to add. Review your selection in the Selected OUs tab, which lists all OUs selected across all domains, along with their canonical name. Click Create Group after review.

Note:
  • A device group can include endpoints directly or from selected OUs across multiple domains.
  • Only machines from the selected root OU are added to the device group; child OU machines are excluded unless those OUs are added separately.

Device group membership constraints

A device that is already a member of an existing group cannot be added to another group, meaning a device can belong to only one group.

Likewise, if a device already belongs to a group, the OU containing that device cannot be added to another group. DataSecurity Plus displays an error listing the devices with conflicting membership. Users can either:

  • Override the existing membership, wherein the device is removed from it's previous group and added to the new one

    or

  • Remove the conflicting OUs from the new group before creating it.

Note: Only endpoints and OUs that are not already members of another group appear in the selection list.

How to manage a device group

The steps below outline how to manage endpoints within a device group:

  • Open DataSecurity Plus console. Choose Admin Console from the Apps drop-down at the top.
  • Go to Administrative Settings > Device Groups. The Device Groups page lists all device groups currently configured in DataSecurity Plus, along with the number of devices in each group.
  • Click the edit icon next to the group name to update the group name or description, or to add and remove endpoints. Click Update Group after making the necessary changes.

To delete device groups, select them on the Device Groups page and click the Delete icon next to Search. Click OK in the confirmation pop-up.

Note: Policies are automatically reevaluated whenever a device group's membership changes.

Best practices for grouping devices

Device groups are designed to enable precise control over a large and diverse endpoint environment, so it is important to organize endpoints into groups that reflect your organization's hierarchical structure and security requirements.

Admins can group endpoints by:

  • Departments or business functions such as Human Resources, Finance, and Engineering.
  • Security and risk profile, for example endpoints that handle sensitive data versus general purpose workstations.
  • Region, for example APAC and EMEA, to address region specific compliance requirements.
  • User roles, for example administrative systems, executive endpoints, and shared machines.

Configuring individual endpoint devices

The steps below are used to configure endpoint devices individually:

  • Open DataSecurity Plus console. Choose Endpoint DLP from the Apps drop-down at the top.
  • Go to Configurations > Devices. In the Configured Workstation(s) page, click +Add Workstations at the top right corner.
  • In the Add Workstation(s) page select the domain or workgroup from which you want to add the endpoints.
  • To add a domain that is not listed, click Domain and follow the steps listed here.

    To add a workgroup that is not listed, click Workgroup and follow the steps listed here.

  • Click + in the Select Workstation(s) field to add the required endpoints
  • In the Select Workstation(s) pop-up choose the desired endpoints and click Select.
  • Choose the Security Policies you want to apply for the selected endpoints.
  • In case you want to add specific folders to be monitored within the selected workstations, click Select Local Folders to Monitor and enter the path of local folder. Sample: C:\Users\admin\desktop\NewFolder or D: and click Add.
  • Click Install Agent and Finish.

Don't see what you're looking for?

  • Visit our community

    Post your questions in the forum.

     
  • Request additional resources

    Send us your requirements.