Device Agents
Monitor each machine's security posture with a lightweight agent for macOS and Windows.
Device agents extend active monitoring from the browser and inbox to the device itself. The agent evaluates a baseline security-posture pack locally (osquery-based) about once an hour and reports only the pass/fail results — no file contents or browsing data leave the machine. Each report is scored server-side as Healthy, At Risk, or Critical and appears in the Monitoring Hub under the Device monitor type, with a full posture report a click away.
What gets checked
macOS — disk encryption (FileVault), System Integrity Protection, Gatekeeper, remote access and sharing services, automatic login, EDR/AV agent presence, application firewall (and stealth mode), automatic software updates, third-party root certificates, unsigned launch daemons/agents, guest login, and third-party kernel extensions. Reported for context: Time Machine backup configuration and recency, pending updates, MDM enrollment, local administrator accounts, third-party launch items, and installed remote-access and tunneling tools.
Windows — disk encryption (BitLocker, including all capable drives), UEFI Secure Boot, antivirus health, User Account Control, Remote Desktop disabled, SMBv1 disabled, automatic logon disabled, EDR/AV agent presence, Volume Shadow Copy service not disabled, Windows Firewall and automatic updates via Security Center, non-default SMB shares, unsigned startup items, the built-in Guest account, local password policy, and a backup mechanism present (backup agent or OneDrive folder backup). Reported for context: removable-storage write policy, startup items, local administrator accounts, MDM enrollment, consumer cloud file-sync clients, and installed remote-access and tunneling tools.
A failed check's severity drives the verdict: any high or critical failure marks the device Critical; lower-severity failures mark it At Risk; all passing marks it Healthy. Checks marked info are inventories and facts rather than pass/fail controls — they appear in the report for context and never count as failures or affect the verdict.
The full, current check list for each platform is shown on the macOS Agent and Windows Agent pages.
Already running an EDR?
If your machines already run CrowdStrike Falcon or Microsoft Defender for Endpoint, you do not have to install our agent to get device coverage. The CrowdStrike Falcon and Microsoft Defender integrations connect a read-only credential and produce a daily health run per protected device: sensor online, sensor healthy, prevention policy or antivirus status, and whether any alerts are waiting on an admin. Those runs appear in the same Device view and device reports as agent scans, with the target suffixed (EDR), and feed the attestation report's Device Posture section alongside the agent's checks. Running both on the same machine is fine; the two rows are kept separate.
Setup
- Create a Device Monitor key. In the Monitoring Hub Monitors view, create a monitor with the type Device Monitor and set its seat assignment to the seated member who uses the machine. The key is shown once — copy it.
- Download the agent from the macOS Agent or Windows Agent page. The macOS
.pkgis signed and notarized. The Windows.msiis signed with an EV code-signing certificate; SmartScreen may still flag a fresh release while the certificate builds reputation, so verify it against the SHA-256 checksum shown next to the download. - Install and enroll.
- macOS (Terminal):
sudo bldeviceagentctl enroll— it prompts for the device key. - Windows (elevated PowerShell):
& "C:\Program Files\Blue Lantern Device Agent\bldeviceagentctl.ps1" enroll— it prompts for the device key.
- Watch the reports. The agent scans about once an hour; each run appears in the hub with the hostname as target. Pair it with an alert on the Critical or At Risk verdicts to hear about posture drift without watching the dashboard.
Billing
Device monitoring is covered only by a Seat License. The monitor's seat assignment must be an active seated (monitored) member of your organization, and all of that member's monitors share their seat's daily fair-use budget. See Seat Licenses & Pricing.
Security notes
- The device key is scoped to submitting posture scans only — it cannot run other tools or read any account data. Revoke the key (Monitors view, or the Account page's API Keys panel) and the agent stops.
- Reports are capped in size and evaluated server-side; the agent's own summary is never trusted for the verdict.
- On both platforms the enrolled key is stored with restrictive permissions (root-only on macOS; a SYSTEM/Administrators-only ACL on Windows) and is never logged.