A user asked for help with removing users from the local Administrators group when they are not allowed those privileges. Other members suggested using a script through the Action > System Scripts or utilizing the Compliance module. The conversation also touched on using specific triggers and including tags or device groups in the criteria for running the script. Ultimately, the user was able to find a solution through the use of device tags in the Scripts capabilities. The conversation can be found in the #channel channel.
Read the entire article here...
ControlUp for Compliance (Secure DX)
ControlUp for Compliance (Secure DX) training and support-related archives from inside the ControlUp Community on Slack.
Adding Claude to ControlUp Compliance Patch Catalog
A team member asked about potentially adding Claude to the ControlUp Compliance patch catalog but it is not currently available. However, there are plans to integrate AI and have a key focus on this in the coming year. The team member can raise a support ticket and mention @member to have the request sent to the development team. It is important for vendors to engage with the team so packages can be provided.
Read the entire article here...
Read the entire article here...
Remediation of VDIs with ControlUp for Compliance
A user asked about using CU4C to remediate vulnerabilities on VDIs. It was suggested that both the CU4C and VDI Agents must be installed based on documentation, but this may change when ControlUp Agent ONE is released.
Read the entire article here...
Read the entire article here...
Understanding ControlUp’s App Catalog List
A user asked if there is a maintained list of apps that are covered under ControlUp's app catalog. The list is pulled from their back end database and it is best practice to include all apps at scoping. This information cannot be copied easily and there is not a public list available as it can change daily.
Read the entire article here...
Read the entire article here...
Creating a Device Matching Workflow in ControlUp
Multiple members had a discussion on how to create a workflow that would synchronize devices from an Entra ID dynamic group into ControlUp using tags. The matching issue is caused by Entra ID and ControlUp having different device identifiers. Various solutions were presented, such as using a custom query or the Split String node, and eventually a solution was found using the Get Custom Data node. Further details and a visual example can be seen in the discussion.
Read the entire article here...
Read the entire article here...
Understanding the API Rate Limit and Cooldown Period at ControlUp
A user asked about the cooldown period for the API rate limit and received information from a colleague stating that there is a limit of 60 requests per user per minute or 200 per minute for the entire organization, with the cooldown period showing up in the header of the API query for retry attempts. The user was unsure if this applied to compliance APIs as well and was reassured that the limit is consistent across all APIs.
Read the entire article here...
Read the entire article here...
Automating Installation of Compliance Agent on New Devices in ControlUp
Users discuss automatically installing compliance agent on new devices on ControlUp. There is currently no supported way of doing, but a new update will allow for this and controlling the version deployed. One user shares their workaround using a script. Other customers have done similar but it is not a supported method, however a new update will provide ability to push versions to specific tags or device groups.
Read the entire article here...
Read the entire article here...
Writing Events to System Events Log with Custom SecureDX Scripts in ControlUp
A user asked about writing events to the system events log using custom issue scan/remediation scripts in SecureDX. Another user confirmed that the same formatting used for normal scripts should work. However, it was noted that missing options in the CU4C scripts may prevent this from working.
Read the entire article here...
Read the entire article here...
Setting up ControlUp Compliance for macOS with JamfPro as the MDM
A discussion about setting up Compliance for macOS with JamfPro as the MDM was had, with a user mentioning that they were prompted for additional approvals despite having imported the configuration profile from ControlUp's site. Others suggested adding additional configurations to the Profile Policy and raised the question of whether the "Local Network" option can be added using the PPPC Utility. Discussion also took place about whether documentation could be improved for this service.
Read the entire article here...
Read the entire article here...
Security concerns regarding ControlUp for Compliance
A user encountered an issue where C:\Program Files\ControlUp\Cu4Compliance\cu4csvc.exe was being blocked by an ASR rule. They suggested that this be added to the documentation on the support site and a discussion about this update will happen internally. Two key locations for CU4C functionality are C:\Program Files\ControlUp\CU4C and C:\ProgramData\ControlUp\CU4C. To further address security concerns, a user is referred to a relevant Knowledge Base article.
Read the entire article here...
Read the entire article here...
