EDR installation across the managed device estate
Every endpoint visible to RMM — and therefore known to exist and be in use — should also be running the EDR agent. A device active enough to appear in RMM is exactly the device most likely to need protection.
Interpret the result in context
Agent installation is distinct from agent health, policy configuration and active monitoring. Use this check to identify installation coverage gaps, then verify protection in the EDR console.
Configure the expectation.
Use this baseline as a starting point. You can also build your own controls and standards from integration data, with client-specific requirements and documented exceptions.
A fixed baseline expectation
This shipped control has no adjustable numerical threshold. Review its applicability and record approved exclusions for the client.
Review. Remediate. Verify.
Use one-click remediation where the integration and action support it, or the evidence to guide the technician’s next step.
- 01
Match the RMM device to the corresponding endpoint record.
- 02
Confirm platform eligibility and deploy the approved EDR agent.
- 03
Refresh installation evidence and check agent health with the security tool.
A completed action is only part of the record. Refresh the supporting evidence to establish whether the finding has cleared.
Make your baseline part of every client review.
Connect checks, findings and remediation to the same client record.