Security

EDR Status Discovery

Maintains endpoint protection coverage by continuously detecting agent issues such as inactive installs, outdated versions, stale scans, or active threats.

EDR Status Discovery
  • Runs periodic checks on EDR agent status across all managed endpoints
  • Identifies devices with missing, disabled, or outdated agents
  • Distinguishes newly flagged endpoints from those already being tracked
  • Notifies device owners and the security team about coverage gaps
  • Opens a ticket for IT to restore protection
  • Auto-resolves once the agent returns to a healthy state

What EDR Status Discovery does

EDR Status Discovery is Harmony's automated workflow for proactively discovering which company devices have endpoint detection and response (EDR) gaps. Running on a configurable schedule, Harmony queries all managed devices, evaluates each against configurable health criteria - inactive agents, outdated versions, active threats, stale scans, or missing agents entirely - and surfaces the results as an IT desk ticket with a full CSV report. Device owners can also be notified directly with a personalized summary of their affected devices.

Who EDR Status Discovery Is For

Persona

IT security and operations teams responsible for maintaining EDR coverage across the device fleet.

Pain point

EDR agents can silently drift into a non-functional state - going inactive, falling behind on version updates, or stopping scans - without anyone noticing until a threat is missed. Manual MDM audits are time-consuming and infrequent. This workflow gives IT a continuous, automated view of EDR health across the fleet without requiring any manual query.

How EDR Status Discovery Works

Trigger

A cron schedule fires (default: daily at 8 AM UTC). The schedule and timezone are configurable per tenant.

  1. Query managed devices

    The workflow fetches all managed devices from Asset Management and evaluates each against up to five configurable conditions: agent inactive/degraded, agent version outdated, active threat count above threshold, last scan older than N days, or no agent installed at all.

  2. Notify device owners (optional)

    If notifications are enabled, Harmony groups flagged devices by owner and sends each owner a single "Endpoint Security Alert" message via Slack or Teams. A per-device frequency gate (default: 7 days) prevents repeated notifications. VIP employees can be excluded.

  3. Generate CSV report

    All flagged devices (with notification status) are serialized into a CSV report attached to the ticket.

Outcome

A ticket titled "Devices With EDR Issues Detected" is created in the IT desk, giving the security team a trackable work item to remediate each gap.

Capabilities

  • Five-condition EDR health evaluation - Checks for inactive/degraded agents, outdated agent versions, active threats above a threshold, scans older than a configurable number of days, and devices with no agent at all - any single condition flags the device.
  • Direct owner alerts - Optionally sends each device owner a grouped notification listing all their affected devices with per-device issue details, enabling self-service action before IT intervenes.
  • Notification frequency gate - Tracks when each device was last reported to its owner and suppresses repeat alerts within the configured window, preventing notification fatigue.
  • VIP employee exclusion - Configurable option to skip owner notifications for employees marked as VIP.
  • CSV report with notification history - The IT ticket CSV includes all flagged devices with asset details, issue reasons, and last notification date.
  • Targeted runs - Supports scoping a run to specific employee IDs for focused audits rather than the full fleet.
  • Multi-vendor support - Works with any EDR provider connected to Harmony's asset management layer - CrowdStrike, SentinelOne, and Microsoft Defender for Endpoint are confirmed integrations.
  • Configurable schedule - The cron schedule and timezone are fully configurable per tenant (default: daily).

Main use cases

Daily EDR Coverage Verification - The security team wants a daily confirmation that every managed device has an active, up-to-date EDR agent with no open threats. The workflow runs automatically each morning, evaluates all managed devices against the configured thresholds, and creates a ticket with a full CSV of any findings. The security team starts each day with a current, actionable view of EDR gaps.

Discovering Devices Never Enrolled in EDR - A batch of new laptops was set up by a contractor who forgot to install the EDR agent. They show up in asset management but have no agent. The include_no_agent flag detects all devices in asset management with no EDR record and includes them in the report with the reason "No EDR agent installed."

Notifying Employees About Their Own Device's EDR Issues - A device owner's EDR agent has been inactive for days but hasn't been noticed at the IT level. With owner notifications enabled, the workflow sends the device owner a direct message listing their affected devices and the specific issue - prompting them to contact IT or take action before the gap becomes a security incident.

Compliance Reporting on Endpoint Security Coverage - A security audit requires evidence that the organization monitors EDR agent health across all managed devices. The workflow provides recurring, dated tickets and CSV reports showing that EDR status is actively monitored - creating the audit trail the compliance team needs.

Integrations

IntegrationRole in the agent flow
CrowdStrikeEDR data provider - syncs agent status, version, threat count, and last scan date into Asset Management
SentinelOneEDR data provider - same role as CrowdStrike (configured per tenant)
Microsoft Defender for EndpointEDR data provider - same role (configured per tenant)
Asset Management API (internal)Normalized source of all managed device records and EDR health data
Service Desk (internal)Ticket created with CSV attachment; tracked by the security team for remediation
Notifications system (Slack/Teams)Delivers per-owner "Endpoint Security Alert" messages when notifications are enabled

FAQ

It's a scheduled Harmony workflow, not an interactive chatbot. It runs on a cron schedule (default: daily), evaluates all managed device EDR health against configurable thresholds, and produces owner notifications and/or an IT ticket. No user conversation is needed.

Meet more Agents