# EDR Policy Compliance Discovery

**Categories:** Security

Continuous EDR policy compliance monitoring with automated remediation for non-compliant devices.

- Runs periodic checks on all managed endpoints for EDR policy compliance
- Identifies devices with missing or misconfigured EDR agents
- Marks violations as NEW or existing based on entity tracking
- Notifies device owners and security team
- Creates ticket with violation summary for IT remediation
- Auto-resolves when devices return to compliance

## What EDR Policy Compliance Discovery does

EDR Policy Compliance Discovery answers a question most fleets cannot answer on demand: which devices are not covered by our EDR policy right now. On a recurring schedule it checks every managed endpoint for a missing or misconfigured EDR agent, marks each violation new or already known, notifies the device owner and the security team, and opens a ticket with a violation summary for IT to work. When a device comes back into compliance, the ticket resolves itself, so the open ticket count is a live measure of coverage rather than a backlog.

## Who EDR Policy Compliance Discovery is for

**Persona:** Security and IT leaders who have to report EDR coverage as a number, and the endpoint teams who have to close the gap.

**Pain point:** EDR coverage gets reported from license counts and enrollment lists, which is not the same as coverage. Devices arrive without the agent, get reimaged and never re-enrolled, or sit in a state the policy does not accept, and there is no recurring process that finds them. The gap is real, it grows, and nobody can size it without a manual export.

## How EDR Policy Compliance Discovery works

**Trigger:** A recurring schedule, configurable per tenant.

1. **Check endpoints against policy** - Runs a periodic compliance check across all managed endpoints rather than sampling.

2. **Identify non-compliant devices** - Surfaces devices with a missing EDR agent, and devices whose agent is present but misconfigured against policy.

3. **Mark new versus existing violations** - Uses entity tracking so a violation already being worked stays on its ticket instead of being raised again.

4. **Notify owner and security team** - Alerts the device owner and the security team through each recipient's preferred channel.

5. **Ticket the violations** - Creates a ticket with a summary of the violations for IT to remediate.

6. **Auto-resolve on compliance** - Closes the ticket once the affected devices return to a compliant state.

**Outcome:** A current, ticketed picture of every endpoint outside your EDR policy, with owners notified and tickets that close themselves as coverage is restored.

## Capabilities

- **Recurring fleet-wide compliance checks** - Every managed endpoint is checked against policy on a schedule, not on request.
- **Missing and misconfigured agent detection** - Catches both devices with no EDR agent and devices whose agent does not satisfy the policy.
- **New versus existing violation tracking** - Entity tracking keeps repeat findings on their original ticket rather than multiplying them.
- **Owner and security notifications** - Both the person holding the device and the team accountable for coverage are told.
- **Violation summary tickets** - IT gets a ticket describing what is out of policy, not a raw device list.
- **Self-closing remediation loop** - Tickets resolve automatically when devices return to compliance, so open tickets track the real gap.

## Main use cases

**Reimaged laptop that never came back** - A device is reimaged and returned to its user without the EDR agent reinstalled. The next compliance run finds it, notifies the owner and security, and tickets it - instead of it living unprotected until someone happens to look.

**Sizing the coverage gap for a board report** - Leadership asks what percentage of the fleet is covered. Open violation tickets are the live answer, and because they auto-resolve on compliance, the number reflects today rather than the last manual audit.

**Closing the loop after a rollout** - An EDR policy change rolls out to the fleet. The agent surfaces the devices the rollout missed, tickets each one, and clears the tickets as the stragglers come into line.

## Integrations

| Integration | Role in the agent flow |
| --- | --- |
| Your connected EDR (e.g. CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, Palo Alto Cortex) | Source of agent presence, policy state, and per-device compliance signal |
| Your connected MDM (e.g. Jamf Pro, Microsoft Intune, Hexnode, JumpCloud) | Supplies the managed device inventory the compliance check runs across |
| Harmony Service Desk | Native ticketing - creates the ticket, tracks it, and records the outcome |
| Harmony Notifications | Delivers updates through each recipient's preferred channel: Slack, Teams, or email |

## FAQ

### What does "non-compliant" mean here?

A device with a missing EDR agent, or one whose agent is present but misconfigured relative to your policy. Both are reported as violations so neither hides behind an enrollment count.

### How is this different from EDR Misconfiguration Detection?

This agent asks whether a device meets your EDR policy at all, including devices with no agent. Misconfiguration Detection assumes the agent is there and audits how it is configured: protections, tamper settings, versions, sensor health, exclusions.

### Does it install the EDR agent on non-compliant devices?

The flow described here detects, notifies, tickets, and auto-resolves on return to compliance. Whether installation or policy reapplication is automated depends on what your endpoint management integration is configured to do; the agent itself drives the detection and remediation loop.

### Will the same device be ticketed every run?

No. Violations are marked new or existing through entity tracking, so a device already on an open ticket stays there rather than generating a new one each cycle.

### What needs to be connected first?

An EDR integration supplying agent and policy state, an MDM or asset source supplying the managed device inventory, a desk for the tickets, and the schedule and notification routing configured for your tenant.

## Related agents and features

- [**EDR Misconfiguration Detection**](/agents/edr-misconfiguration-detection) - Sibling monitor that audits how an installed EDR agent is configured, rather than whether policy is met
- [**EDR Status Discovery**](/agents/edr-status-discovery) - Sibling monitor covering EDR agent health: inactive agents, outdated versions, threats, and stale scans
- [**Unencrypted Assets**](/agents/unencrypted-assets) - Sibling monitor for a different endpoint control: devices missing disk encryption
- **Harmony Service Desk** - Receives the tickets this agent opens and carries the audit trail of what happened