Multi-Tenant Management of Settings Profiles

Applies To: WatchGuard Advanced EPDR, WatchGuard EPDR, WatchGuard EDR, WatchGuard EPP, WatchGuard EDR Core

To access the multi-tenant management UI for endpoint security, your Service Provider account must have an active WatchGuard Endpoint Security license in its inventory.

Settings vary for WatchGuard Advanced EPDR, EPDR, EDR, EDR Core, and EPP. Throughout this documentation, WatchGuard Endpoint Security refers generally to all products. If you do not have a setting in the Endpoint Security management UI, it is not supported by your product.

On the Settings page, Service Providers can create and edit security settings profiles, and then assign them to managed accounts (Subscriber or Service Provider) or a group of accounts, similar to a template. Settings profiles can help reduce administration time and settings inheritance enables quicker assignment of settings to account groups and sub-groups and the computer and devices in these groups.

Service Providers cannot manage the security settings of delegated accounts in the multi-tenant management UI.

Screen shot of Service Provider Endpoint Manager, Workstation and server settings

For information on how to centrally assign a security settings profile, go to Multi-Tenant Management — Assign Endpoint Security Settings to Managed Accounts.

To open a multi-tenant endpoint security settings profile from WatchGuard Cloud:

  1. From Account Manager, select a Service Provider account.
    To select your own Service Provider account, select Overview. Or, select a tier-n Service Provider account.
  2. Select Configure > Endpoints.
  3. On the Settings page, select the type of settings you want to see.

For more information on how to create, copy, edit, and delete security settings profiles, go to Manage Settings Profiles.

Multi-tenant settings profiles that you create can include these settings:

Per-Computer Settings

Use these settings to configure features of the endpoint security product installed on user computers, such as agent visibility, software updates, anti-tamper protection, two-factor authentication (2FA), and shadow copies. For information on the available settings, go to Configure Per-Computer Settings.

Remote Control (Advanced EPDR only)

Use these settings to configure remote access to user computers. For more information on the available settings, go to Configure Remote Control Settings (Windows Computers).

Workstations and Servers

Use these settings to specify how the endpoint security product reacts to threats, including network attack settings, Audit mode, and Advanced Security Policies (Advanced EPDR only), and to set administrator rules for access to network resources to minimize the attack surface. For information on the available settings, go to Configure Workstations and Servers Security Settings.

Indicators of Attack

Use these settings to enable or disable the Indicators of Attack you want to detect. In Advanced EPDR, you can also enable or disable Advanced IOA. For more information on the available settings, go to Configure Indicators of Attack Settings.

Risks

Use these settings to configure the risks you want to detect on your devices and to set the risk level. The risks available depend on your WatchGuard Endpoint Security product. For information on the available settings, go to Configure Risks Settings.

Program Blocking

Use these settings to specify which programs to block when they try to run. For information on the available settings, go to Configure Program Blocking Security Settings (Windows Computers).

Authorized Software

Use these settings to specify programs that you do not want WatchGuard Endpoint Security to block during classification. For information on the available settings, go to Configure Authorized Software Settings (Windows Computers).

Mobile Devices

Use these settings to specify how the endpoint security product reacts to threats on iOS and Android phones and tablets. For information on the available settings, go to Configure Mobile Device Security Settings.

Patch Management

Use these settings to specify how the Patch Management module discovers new security patches published by vendors for the Windows operating systems and third-party software installed across the network. For information on the available settings, go to Configure Patch Management Security Settings.

Data Control

Use these settings to specify how the Data Control module monitors personal data on your network. For information on the available settings, go to Data Control Settings.

Encryption

Use these settings to specify how the Full Encryption module monitors the encryption status of network computers and centrally manages the corresponding recovery keys. For information on the available settings, go to Encryption Settings.

Related Topics

Multi-Tenant Management — Assign Endpoint Security Settings to Managed Accounts

Multi-Tenant Management — Settings Inheritance for Subscriber Accounts

Multi-Tenant Management — Settings Inheritance for Service Provider Accounts