Multi-Tenant Management — Settings Inheritance for Subscriber Accounts

Applies To: WatchGuard Advanced EPDR, WatchGuard EPDR, WatchGuard EDR, WatchGuard EPP, WatchGuard EDR Core

To access the multi-tenant management UI for endpoint security, your Service Provider account must have an active WatchGuard Endpoint Security license in its inventory.

In the Endpoint Security management UI, Subscriber accounts can create and assign security settings profiles to the computers and devices they manage. They might also receive settings that a Service Provider created and assigned to them. This topic describes settings inheritance when a Service Provider assigns settings to a managed Subscriber account.

For information on how to assign settings to managed Service Provider accounts, go to Multi-Tenant Management — Settings Inheritance for Service Provider Accounts.

Service Providers cannot assign security settings of delegated accounts in the multi-tenant management UI.

Settings profiles that Service Providers assign to a managed Subscriber account are read-only in the Subscriber account. The settings profile includes a green Service Provider label (The Service Provider label.) to differentiate it from profiles created manually at the account-level.

Screen shot of Service Provider Endpoint Manager, Service Provider tag

Ownership of these settings profiles (that is, who can edit and delete them) is based on who created the settings profile (Service Provider or Subscriber). Refer to the appropriate section:

Editable Settings — Scan Exclusions and Authorized Software

By default, the managed accounts to which you assign a settings profile cannot edit or delete the configuration. You can configure some settings profiles to allow the managed account to add scan exclusions or add authorized software. When you configure this option, the settings profile shows the Editable Exclusions or Editable Settings in the management UI for the recipient account.

The managed account can then add exclusions or software programs, but they cannot delete or edit the list of exclusions or authorized software programs you defined. If you configure the option to then be non-editable, the exclusions or authorized software programs the managed account added will no longer apply. Only the exclusions from your Service Provider account apply. If you change the option again to be editable, then the exclusions or authorized software programs that the managed account added are restored and applied.

Changes made by a Service Provider to the settings assigned to a tenant account automatically reflect in the tenant account Endpoint Security management UI. The changes propagate to the target devices in real-time or within 15 minutes when real-time communication is disabled. For more information, go to Disable Real-time Communication.

Settings Exceptions

If the account group has devices with settings that were directly assigned, a yellow caution symbol shows beside the account name in the list. You are prompted to keep the settings that are directly assigned or to overwrite the local settings and inherit all settings from the account group.

When Service Providers assign a security settings profile to an account or account group, the settings are applied to the All group and inherited by any sub-groups. If any of the sub-groups, computers, or devices have manually assigned settings, an exception occurs and WatchGuard Endpoint Security does not assign the settings profile.

When Service Providers assign settings in the multi-tenant management UI, they can view exceptions on the Settings page. If the list of accounts shows a black number in the colored line, this part of the account list is collapsed and some accounts have exceptions to the settings profile they assigned. Double-click the number to show the accounts with exceptions.

Screen shot of Service Provider Endpoint Manager, settings exceptions

To review manually applied settings, you must open the Endpoint Security management UI for the account.

Related Topics

Multi-Tenant Management of Settings Profiles

Multi-Tenant Management — Assign Endpoint Security Settings to Managed Accounts

Settings Inheritance in Subscriber Accounts

Restore Inheritance in Subscriber Accounts