Academy Central
----
Weather

Monitoring SaaS-Connected Devices

監控 SaaS 連線裝置

Overview | 概述

Devices are the gateway to your SaaS data. The Devices Inventory in Falcon Shield connects the dots between devices, users, and SaaS access — turning fragmented device data into actionable security intelligence.

裝置是存取 SaaS 資料的入口。Falcon Shield 中的裝置清單串連了裝置使用者SaaS 存取權之間的關聯,將零散的裝置資料轉化為可操作的安全情報。


Why Device Visibility Matters | 為什麼裝置可見性很重要

BenefitDescription好處說明
Immediate Security ImpactIdentify privileged users on compromised devices即時安全影響發現特權使用者使用被入侵的裝置
Operational ExcellenceMap device-to-user relationships in seconds營運卓越幾秒內建立裝置與使用者的關聯
Risk-Based ApproachPrioritize device risks based on user privileges基於風險的方法依使用者權限優先處理裝置風險
Strategic ValueSupport secure hybrid work at scale策略價值大規模支援安全的混合辦公

Device Identification & Merging | 裝置識別與合併

Falcon Shield merges devices based on:

Falcon Shield 根據以下條件合併裝置:

  • User email address (reported by the SaaS app)

  • Device ID / Serial Number

  • Device type (mobile, laptop, desktop)

  • Device name

  • 使用者電子郵件地址(由 SaaS 應用程式回報)

  • 裝置 ID / 序號

  • 裝置類型(行動裝置、筆電、桌上型電腦)

  • 裝置名稱

If the same device is reported for two different email addresses, it appears as two separate rows — preventing devices from being lost during user migrations.

如果同一裝置以兩個不同的電子郵件地址回報,它會顯示為兩筆獨立的紀錄 — 避免裝置在使用者遷移過程中遺失。


Available Columns | 可用欄位

ColumnDescription欄位說明
NameDevice name名稱裝置名稱
UserAssociated user使用者關聯的使用者
PlatformDevice platform平台裝置平台
OSOperating system作業系統作業系統
OS VersionOS version number作業系統版本作業系統版本編號
ManagedOrganization-managed?受管理是否由組織管理
CompliantMeets compliance policies?合規是否符合法規要求
OwnershipOrg-owned or personal?所有權組織所有或個人所有
Last SeenMost recent activity date最後活動最近活動日期
IntegrationsReporting SaaS apps整合回報的 SaaS 應用程式
Device ChecksSecurity check results裝置檢查安全檢查結果
VulnerabilitiesKnown CVEs漏洞已知 CVE

Filters and Grouping | 篩選與分組

Key Filters | 關鍵篩選器

FilterUse Case篩選器使用情境
Privileged RolesFind admin users on risky devices特權角色發現高風險裝置上的管理員使用者
VulnerabilitiesIdentify devices with known CVEs漏洞發現有已知 CVE 的裝置
EncryptedCheck encryption status across apps加密跨應用程式檢查加密狀態
ManagedDistinguish org-owned vs. personal受管理區分組織所有與個人裝置
CompliantFilter non-compliant devices合規篩選不符合規範的裝置

Grouping | 分組

Group results by Platform, OS, or OS Version to identify patterns across your device fleet.

平台作業系統作業系統版本分組結果,以識別裝置群組中的模式。

Multiple filters within the same filter = OR logic. Filters across different filter types = AND logic.

同一篩選器內的多個篩選條件 = OR 邏輯。不同篩選器類型之間 = AND 邏輯。


Device Inventory Templates | 裝置清單範本

Privileged Users with Non-Compliant Devices | 特權使用者使用不合规裝置

Why it matters | 為什麼重要: Privileged users accessing SaaS from devices with critical vulnerabilities create a dangerous attack surface. These users have elevated permissions that could be exploited if their device is compromised.

說明: 特權使用者從有嚴重漏洞的裝置存取 SaaS 會造成危險的攻擊面。如果他們的裝置被入侵,這些使用者的高權限可能被利用。

Stale Devices | 閒置裝置

Description | 說明: Devices that appear functional but may be compromised in ways that don't trigger alerts. Attackers design malware to operate stealthily on such systems.

說明: 外觀正常但可能已被入侵且未觸發警報的裝置。攻擊者設計惡意軟體在此類系統上隱密運作。

Devices with Critical Vulnerabilities | 有嚴重漏洞的裝置

Description | 說明: High-severity flaws that can be exploited to gain unauthorized access, elevate privileges, or execute malicious code. Unpatched vulnerabilities create entry points for attackers.

說明: 可被利用來取得未授權存取、提升權限或執行惡意程式碼的嚴重漏洞。未修補的漏洞為攻擊者創造入口。

Unencrypted Devices | 未加密裝置

Description | 說明: Devices lacking data protection mechanisms. In the event of loss or theft, all stored data becomes readily accessible, violating many compliance requirements.

說明: 缺乏資料保護機制的裝置。在裝置遺失或被竊時,所有儲存的資料將變得容易存取,違反許多法規要求。


Related Modules | 相關模組

ModuleDescription關聯模組說明
User InventoryCorrelate device data with user identity使用者清單將裝置資料與使用者身分關聯
Applications InventoryTrack apps connected to your SaaS應用程式清單追蹤連接到 SaaS 的應用程式
Identity GovernanceEnforce access policies based on device trust身分治理根據裝置信任度執行存取策略
DCU MatrixPrioritize risk based on device contextDCU 矩陣根據裝置情境優先處理風險