Device Status and Security Posture

Device Status and Security Posture

Device Status

Device status indicates whether a device can be onboarded and used by TSFA. It reflects the device’s provisioning state and compatibility, not its security condition.

Depending on its status, a device may be fully operational, require additional configuration, or be unsupported due to hardware or firmware limitations. These status values help administrators identify devices that require attention before they can be fully managed.

Status Values

Status

Description

Active

Device is onboarded, compliant, and actively reporting data

Pending

This status may occur for one of three reasons:

·       The UEFI/BIOS is not supported or requires an update.

·       Onboarding or provisioning failed.

Unsupported

The device model is not supported by TSFA

Eligible

The device does not have a TSFA license but qualifies for one.


TSFA Security Posture

Security posture represents the security condition of a device based on events generated by the device.
Devices continuously emit events, which are sent to the cloud and processed using predefined rules. These rules evaluate events and determine the device’s current security posture.

Events are also surfaced as incidents, which provide visibility into detected issues and historical activity. Security event Incidents support monitoring and analysis but do not change the underlying event processing logic.

As new events are received, the system recalculates and updates the device’s posture to reflect the latest state.

Process


To view security event incidents:
  1. Go to Device Management > Devices.
  2. Select a device from the list.
  3. In the device details page, select the Issues & Errors tab.
  4. In the search box, click the filter arrow and select Security Events.
Alternatively, you can view all incidents across devices:
  1. Go to Device Insights > TSFA Security > All incidents tab.
  2. This tab displays incidents from all devices in the organization. For more information, see Incident Overview.

Security Posture Values

Posture

Description

Healthy

No issues detected

Unhealthy

Device is reporting events, but configuration or security issues are detected

Suspect

Device is reporting events, and potential risk is identified based on rule evaluation

Uninitialized

Device is not reporting data correctly or cannot communicate with the system


For information about Device Status and Security Posture issues, see Security Event Log Reference, and Troubleshooting TSFA.

Integration with SentinelOne
If the TS XTR Firmware Intelligence connector is configured, TSFA automatically sends security posture change events to SentinelOne. For more information, see Configuring SentinelOne Connector.