Device Control Audit & Reports
Audit connected and blocked devices, trace file activity, review shadow copies, and inspect supported hardware on demand.
Endpoints
Audit connected and blocked devices
Review device connections, users, identifiers, timestamps, and enforcement outcomes across managed endpoints.
Device Audit
Device Audit shows the devices that most recently connected to managed endpoints. Each record includes the managed device, logged-in user, connected-device type, unique identifier, connection timestamp, and the last action: Allowed or Blocked.

Use Column to choose which fields appear. Use Export to download the report as PDF, XLSX, or CSV, with the option to hide personal information.
When no policy is applied, audit reports are generated automatically every 24 hours.
When a policy is deployed, reports follow the duration configured in that policy.
- To request an immediate report for one device, navigate to Device Control → Insights → Managed Computers.
- Select the computer, open Device Audit, and select Update now.
See how to configure device audit settings.
Blocked Devices
Blocked Devices lists peripherals prevented from accessing managed endpoints. Records include the managed device, logged-in user, blocked-device type, unique identifier, and blocked-connection timestamp.

Choose visible fields with Column and export the report as PDF, XLSX, or CSV. Personal information can be hidden during export.
Files
Trace file activity and shadow copies
Investigate file operations and retain evidence of files transferred to external devices.
File Tracing
File Tracing reports the files involved in endpoint activity and the actions performed on them:
- Creating
- Opening
- Modifying
- Copying
- Moving
- Deleting
- Renaming

Choose visible fields with Column and export the report as PDF, XLSX, or CSV. Personal information can be hidden during export.
File Shadowing
File Shadowing stores a copy of every file transferred from a PC to an external device. The File Shadow Report identifies the file name, the destination external device, and the network path where the shadow copy is stored.

Choose visible fields with Column and export the report as PDF, XLSX, or CSV. Personal information can be hidden during export.
See how to configure file shadow settings.
Inspection
Inspect devices on demand
Use Device Manager to retrieve current hardware details and related policy and report information without waiting for refresh.
Device Manager
Device Manager shows every supported hardware device connected to a computer. It also provides on-demand access to device-specific policies, Device Audit, File Tracing, and File Shadowing reports without waiting for the refresh cycle.
- Navigate to Insights → Managed Computers.
- Select a computer and open Device Manager.

Select Update Now to retrieve the most recently connected devices, including the parent device instance path, vendor ID, product ID, and serial number.