Skip to main content

Devices

The Devices page lists every device Navigator has consolidated across all your connectors: laptops, servers, and other endpoints.

How devices are consolidated

If the same physical device is reported by more than one connector (for example, it shows up in both your MDM and your EDR), Navigator matches those records into a single consensus device rather than showing duplicates. Matching uses the strongest available identity signal first, a directory device ID when your connectors provide one, falling back to hostname, serial number, or MAC address overlap when it doesn’t.

Each consensus device keeps track of exactly which connectors reported it (shown as source icons on the row) and what each one said for every field, so you can always see where a value came from and whether your sources agree.

What’s shown

Common fields include hostname, manufacturer/model, OS platform/version, encryption status, hardware specs (CPU, RAM, storage), IP addresses, and whether the device has agent-based coverage (EDR/MDM). Not every connector reports every field; a field left blank means no connected source has reported it yet, not that the value is genuinely empty.

  • Basic search filters by whatever you type against the device’s name/identifying fields.
  • The facet rail on the left lets you filter by source, OS family, and known risk conditions (like end-of-life OS). Counts shown next to each filter always reflect your whole device inventory, not just what’s currently filtered in.
  • Source Overlap shows exactly which combination of connectors reported each device (e.g., “seen by Entra + Intune + Defender”), useful for spotting devices that are only partially covered.
  • Advanced Search lets you build more complex filters, including ones that reference a different asset type (e.g., “devices with a Critical vulnerability”).

Device Detail

Clicking into a device shows:

  • Overview: the consensus record’s key fields at a glance.
  • Attributes: every field, compared side-by-side across each reporting source, with disagreements flagged.
  • Activity: the field-level change history for this specific device.
  • Software / Vulnerabilities tabs: appear only when this device has real, resolved data in those categories.

Deactivating a device

Admins can manually deactivate a device when IT already knows it’s out of scope right now, without waiting for a connector to stop reporting it. This works on a single device (the “Deactivate” button on its detail page) or in bulk (select devices in the list and use the Deactivate button in the bulk toolbar). Both require an admin role.

Deactivating a device:

  • Excludes it from the Active Devices count on the Dashboard immediately.
  • Hides it from the default Devices list — a “Show deactivated devices” link brings it back into view.
  • Does not delete the device record or any of its history. Everything Navigator has ever learned about that device — its attributes, source records, software, vulnerabilities — stays exactly as it was; deactivation only changes whether it’s counted and shown by default.

If a connector later reports genuine activity on a deactivated device (a real sign-in or sync check-in, not just being re-listed by a directory sync), Navigator automatically switches it back to active and clears the deactivation.

Why deactivation keeps the record instead of deleting it

Navigator already has a separate, automatic mechanism for devices no connector reports anymore: after a period of no activity, a device is retired and hidden from every view, with no way to bring it back into view short of a real new observation. That’s the right behavior for routine hygiene, but it’s the wrong fit for a deliberate, human decision — hiding a device with no way to review it again would defeat the point of an admin choosing, right now, to mark it out of scope.

Deactivation is a separate, explicit state for exactly that reason: it’s reviewable (the “Show deactivated devices” toggle) and reversible (either manually, via Reactivate, or automatically, the next time real activity is seen), rather than a one-way disappearance. The device record itself is never a candidate for deletion as part of this — Navigator’s asset history (change history, past findings, source records) only stays meaningful for as long as the device row it points back to still exists, so the design keeps deactivated devices around rather than removing them.

Known gap: deactivation isn’t yet shown in a device’s Activity tab

Deactivating or reactivating a device is a real, admin-initiated event, but it doesn’t currently appear in that device’s own Activity tab or in Telemetry’s Recent Activity feed — those are built around changes a connector reports, and a manual override isn’t attributed to a connector the same way. This is a known open item, not a deliberate decision that it should stay invisible there.