The Endpoint Encryption Unsuccessful Device Logon widget shows all devices (managed endpoints) that had unsuccessful logon attempts by any user. Unsuccessful device logon events may represent a security breach or the user may have forgotten their logon credentials.
Column |
Description |
---|---|
Device Name |
The computer name of the endpoint. |
Policy |
The policy managing the endpoint. |
Events |
The number of unsuccessful logon attempts. Click the number to view the Endpoint Encryption Unsuccessful Device Logon report. |
Unsuccessful Device Logon Report
The following table explains the Endpoint Encryption Unsuccessful Device Logon report. Use it to understand how to read the report details.
Header |
Example |
Description |
---|---|---|
Event Timestamp |
07/02/2012 01:56 pm |
When the event occurred. |
Policy |
GP1 |
The title of the policy controlling the endpoint. |
Device Name |
TREND-4136D2DB3 |
The computer name used by the endpoint. |
Device ID |
1fabfbff-0001-06e5-000c-297085710000 |
The unique ID established after the Security Agent was installed on the endpoint and a new endpoint was registered with PolicyServer. |
IP Address |
10.1.152.219 |
The endpoint IP address. |
Agent |
Full Disk Encryption |
The currently installed Security Agent. |
User Name |
user325 |
The user name used to attempt to log on to the endpoint. |
Display Name |
Mary Jones |
The first and last name of the Apex Central user account. If the specified user name is not a valid Apex Central user name, the column shows "Not Recorded". |
Event |
Unsuccessful Fixed Password Login |
The logged event including the authentication method. |