14-day trial, no credit cardStart now

Discovery mode

A time-bounded audit-only override on an endpoint group. While it is active the API rewrites every rule action to audit server-side, so agents in that group see a policy where nothing blocks. Events still flow, so you can see what would have been blocked.

Rollout

Why it exists

Block by default is the right default. But before turning it on for 200 machines you want a few weeks of "what actually gets plugged in here" data. Discovery mode is that.

How to enable

From Endpoint groups, open the group detail page and toggle Discovery mode with a window. Set the toggle off, or set the until-date to the past, to switch the group into enforcement.

What changes

  • Agents in the group receive a policy where every rule action is audit
  • The agents log events as audit and disable nothing
  • The events page shows what would have been blocked
  • Other endpoint groups in the same workspace are unaffected

End of window

The agent enforces the end of the window itself, so enforcement resumes on time even if the endpoint is offline or has not polled recently. Toggling discovery off early changes the policy etag, so agents pick that up on their next poll. Either way, no manual push is needed.

  1. Create an endpoint group for the rollout, for example Engineering pilot
  2. Start from the seeded default policy, or author your own
  3. Turn discovery mode on for the group
  4. Deploy to the pilot machines
  5. Watch the events page and add allow rules for the legitimate devices that show up
  6. End discovery mode and verify nothing legitimate gets blocked
  7. Roll out to the remaining machines in that group

Something missing or wrong here? Tell us. Documentation gaps get filled fast.