×
×
×
×

Configure Inactive Computer Policy

Configure Inactive Computer Policy

This document provides a comprehensive guide to configure Inactive Computer Policy- Scope of Management (SoM) policy. It covers step-by-step instructions for setting options for deleting computers that have not reported to the Central Server in the specified time and notification preferences.

How to Configure Inactive Computer Policy?

Navigate to Agent > Inactive Computer Policy. This will open Inactive Computer Policy View.

Inactive Policy
  • When computers are inactive for long time:
    • If you enable Notify me if a computer has not contacted Central server in the past 'n' days: The computers that has not contacted the Central server in the specified days, will be notified via mail address configured in the notification settings.
    Note
    • After devices are deleted from the console, the agent installed on them will be uninstalled the next time they connect to the server. To re-add these computers to management, you'll need to reinstall the agent.
    • Make sure the time to remove a device from SoM is longer than the time set to get notified when a device doesn't contact the server.
    • If you select Notify me if a computer has not contacted the Central server in the past 'n' days: The computers that has not contacted Central Server in the number of days specified will be notified via the mail address configured in the notification settings.
    • If you enable Move computer(s) to the Staged Computers page and notify me if they haven't contacted the Central Server in the past 'n' Days:Computers meeting the inactivity criteria will be moved to the Staged Computers view but the agent will not be uninstalled from the endpoint. You will also receive an email notification.
      • Automatically add computer(s) back to management if they re-establish contact with the Central Server:Enabling this option ensures that if a staged computer comes back online, it will automatically be moved back to the active managed list without manual admin intervention.
    • If you select Delete and Notify me if a computer has not contacted the Central server in the past 'n' days: The computers that has not contacted Central Server in the number of days specified will be deleted and notified via the mail address configured in the notification settings.
      • Remove MDM enrollment Profile:If the inactive computer is a mobile device or a modern managed endpoint with an MDM profile, selecting this will remove the associated MDM profile configurations, apps, and corporate data from the device.
    • Schedule starts at: The Central Server will check for last contact time of the agents. If the specified criteria is met, it will send notification or remove the computer from the scope of management. This schedule will run at the specified time everyday.
    • Notification SettingsEnter the Email address where you want to receive all the inactivity alerts configured above

Click Save to apply the policy.

How to Configure Sync Settings

The discovery of computers from Active Directory for a specific domain depends on the configured sync schedule for that domain. To update or change the schedule, Navigate to Agent > Domains > Select the desired domain > Modify Sync Details

Set Targets to be Synchronized

  • Navigate to Agent > Active Directory Sync > Add Targets.
  • Select synchronization targets by Domains, Organizational Units (OUs), or Groups within AD.
Note

Only Domain or OU/Groups can be added at a time, as OUs are part of a Domain.

targets to be synchronised for som policy sync

Notification Settings

Configures specific email alerts to receive updates on changes and activities within the SoM, keeping administrators informed.

How to configure notification settings?

Navigate to Agent > Active Directory Sync > AD Sync Settings. This will open Active Directory Sync view.

Under Notification Settings,

  • Email Address: Enter the email address to receive notifications about changes in the Scope of Management. Kindly note that Mail server has to be configured to receive notifications.
som policy notification settings

How to Exclude Computers from Agent Installation?

If you do not want to install agents on specific computers that have been newly added to Active Directory, you can exclude them from agent deployment.

Steps to Exclude Computers from Agent Installation:

  1. Navigate to Agent > Active Directory Sync.
  2. Next to the Show option, select Added Computers.
  3. Choose the computers you want to exclude from agent installation.
  4. Click Exclude Computers to prevent agent deployment on these devices.

To view the excluded computers, go to Show and select Excluded Computers.

som policy exclude computers

Staged Computers

Staged computers refers to the computers listed are not under active management yet, but are eligible and ready to be managed as needed. To learn more about Staged Computers refer to this document.