EDR Policy Compliance Discovery
Continuous EDR policy compliance monitoring with automated remediation for non-compliant devices.
- Runs periodic checks on all managed endpoints for EDR policy compliance
- Identifies devices with missing or misconfigured EDR agents
- Marks violations as NEW or existing based on entity tracking
- Notifies device owners and security team
- Creates ticket with violation summary for IT remediation
- Auto-resolves when devices return to compliance
What EDR Policy Compliance Discovery does
EDR Policy Compliance Discovery answers a question most fleets cannot answer on demand: which devices are not covered by our EDR policy right now. On a recurring schedule it checks every managed endpoint for a missing or misconfigured EDR agent, marks each violation new or already known, notifies the device owner and the security team, and opens a ticket with a violation summary for IT to work. When a device comes back into compliance, the ticket resolves itself, so the open ticket count is a live measure of coverage rather than a backlog.
Who EDR Policy Compliance Discovery is for
Security and IT leaders who have to report EDR coverage as a number, and the endpoint teams who have to close the gap.
EDR coverage gets reported from license counts and enrollment lists, which is not the same as coverage. Devices arrive without the agent, get reimaged and never re-enrolled, or sit in a state the policy does not accept, and there is no recurring process that finds them. The gap is real, it grows, and nobody can size it without a manual export.
How EDR Policy Compliance Discovery works
A recurring schedule, configurable per tenant.
- Check endpoints against policy
Runs a periodic compliance check across all managed endpoints rather than sampling.
- Identify non-compliant devices
Surfaces devices with a missing EDR agent, and devices whose agent is present but misconfigured against policy.
- Mark new versus existing violations
Uses entity tracking so a violation already being worked stays on its ticket instead of being raised again.
- Notify owner and security team
Alerts the device owner and the security team through each recipient's preferred channel.
- Ticket the violations
Creates a ticket with a summary of the violations for IT to remediate.
- Auto-resolve on compliance
Closes the ticket once the affected devices return to a compliant state.
A current, ticketed picture of every endpoint outside your EDR policy, with owners notified and tickets that close themselves as coverage is restored.
Capabilities
- Recurring fleet-wide compliance checks - Every managed endpoint is checked against policy on a schedule, not on request.
- Missing and misconfigured agent detection - Catches both devices with no EDR agent and devices whose agent does not satisfy the policy.
- New versus existing violation tracking - Entity tracking keeps repeat findings on their original ticket rather than multiplying them.
- Owner and security notifications - Both the person holding the device and the team accountable for coverage are told.
- Violation summary tickets - IT gets a ticket describing what is out of policy, not a raw device list.
- Self-closing remediation loop - Tickets resolve automatically when devices return to compliance, so open tickets track the real gap.
Main use cases
Reimaged laptop that never came back - A device is reimaged and returned to its user without the EDR agent reinstalled. The next compliance run finds it, notifies the owner and security, and tickets it - instead of it living unprotected until someone happens to look.
Sizing the coverage gap for a board report - Leadership asks what percentage of the fleet is covered. Open violation tickets are the live answer, and because they auto-resolve on compliance, the number reflects today rather than the last manual audit.
Closing the loop after a rollout - An EDR policy change rolls out to the fleet. The agent surfaces the devices the rollout missed, tickets each one, and clears the tickets as the stragglers come into line.
Integrations
| Integration | Role in the agent flow |
|---|---|
| Your connected EDR (e.g. CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, Palo Alto Cortex) | Source of agent presence, policy state, and per-device compliance signal |
| Your connected MDM (e.g. Jamf Pro, Microsoft Intune, Hexnode, JumpCloud) | Supplies the managed device inventory the compliance check runs across |
| Harmony Service Desk | Native ticketing - creates the ticket, tracks it, and records the outcome |
| Harmony Notifications | Delivers updates through each recipient's preferred channel: Slack, Teams, or email |
FAQ
A device with a missing EDR agent, or one whose agent is present but misconfigured relative to your policy. Both are reported as violations so neither hides behind an enrollment count.
Meet more Agents