Device management
Working with enrolled endpoints
The endpoint view, what each panel tells you, and the order to read them in.
Last updated
The endpoint view is where most technician time is spent. It gathers everything the platform knows about one machine, and it rewards being read in a particular order when you are diagnosing something.
Start with state and health history rather than with the current snapshot. A machine that is online now but has flapped six times today is telling you something quite different from one that has been steadily online, and the current state alone cannot distinguish them.
Move to the action log next. It records what the platform has done to this machine — patch scans, installs, compliance scans, remediation actions, terminal sessions — with the operator identity attached. Before you form a theory about why a machine started behaving differently on Tuesday, check whether something was done to it on Tuesday. This is the single highest-yield habit in endpoint troubleshooting and it is consistently skipped.
Then inventory. Hardware inventory tells you what the machine is; software inventory tells you what is on it and at what version. Both are collected by the agent rather than typed in by a person, which makes them trustworthy in a way that manually maintained asset spreadsheets are not.
Patch position sits alongside inventory and is the fastest route to "is this machine exposed". Where a machine is behind, the patch view tells you what is missing rather than only that something is.
The asset timeline is reachable from here and widens the frame from the machine to the thing. It carries assignment changes, lifecycle events and history that predates the current operating-system install, which is why it can answer questions the endpoint record alone cannot.