ControlUp currently offers a native, first-party integration exclusively with ServiceNow for IT service management (ITSM) purposes. This integration provides advanced functionality beyond typical ticket creation: it can update an originally created ticket automatically if the same issue recurs, close the ticket when the issue resolves, and reopen it if the problem reappears, based on configurable recurrence and timing settings. Additionally, this ServiceNow integration is embedded directly into the device overview and specific device details user interface within ControlUp, providing seamless operational visibility.
Other ITSM systems are supported primarily through ControlUp Workflows, which offer integration capabilities with several platforms including Jira Service Desk, Freshservice, Zendesk, TOPdesk, and Halo ITSM, using broad REST-based connectivity. ManageEngine ServiceDesk Plus and its on-premises version also have integration options available behind feature flags. While Jira is integrated for workflows, it does not yet have a native ControlUp integration matching ServiceNow’s level of direct functionality.
Regarding Ivanti Neurons ITSM, there is currently no native or first-party integration with ControlUp. No active development plans or timelines have been announced for such an integration. Ivanti Neurons is also not included in the existing set of ITSM connectors available in ControlUp Workflows. However, users interested in integrating Ivanti Neurons can leverage the Workflows platform’s custom integration feature, which allows interaction with Ivanti’s REST API to build tailored solutions fitting organizational needs. Although this requires some configuration effort, it is the recommended alternative until an official integration is developed.
The ControlUp team has acknowledged requests for additional native ITSM integrations beyond ServiceNow, including Ivanti Neurons and Jira, and has indicated these will be considered for future roadmap development. However, no estimated time of arrival (ETA) is provided at this stage. For now, leveraging the robust Workflows engine with available connectors and custom API integrations offers the best path forward for integrating ITSM systems other than ServiceNow.
For detailed guidance on configuring Workflows, custom integrations, and the native ServiceNow integration, users can refer to ControlUp’s official documentation at https://docs.controlup.com and the ControlUp Academy at https://cuacademy.controlup.com.
Read the entire article here...
Scripts Related Training & Support Archives
Scripts training and support-related archives from inside the ControlUp Community on Slack.
Automating Detection and Remediation of Stuck BitLocker Encryption on Windows 11 Endpoints with ControlUp Real-Time Automation Engine
When deploying hundreds of Windows 11 endpoints managed by Intune, a common issue with BitLocker encryption is that the process sometimes becomes stuck at a certain percentage completion. While manually pausing and restarting the encryption process resolves the issue within minutes, automating this detection and remediation can save considerable time and ensure consistent endpoint security.
Using ControlUp Real-Time Automation Engine (CU4D), such automation is achievable by leveraging scripted detection and remediation. One approach is to create a single script that both detects the encryption status and initiates a restart of the encryption process if it remains stuck at the same percentage. This script can be deployed across all affected devices and scheduled to run periodically, for example, once per day, to identify any stuck BitLocker jobs and resolve them promptly.
A more modular approach involves creating two separate scripts: a detection script and a remediation script. The detection script would check the current encryption percentage, and if it identifies a stuck state, it writes the status to a custom index attribute within ControlUp. An alert can then be configured based on the value of this custom attribute. When the alert triggers due to a stuck encryption status, the remediation script executes automatically to restart the BitLocker encryption, ensuring a timely resolution without manual intervention.
This method harnesses ControlUp's ability to store custom scripted outputs in custom indices and link those to alert triggers, thus providing a robust, automated way to handle encryption stalls on Intune-managed Windows 11 devices. For further details on configuring custom scripts, custom indices, and alerts in ControlUp, administrators can refer to ControlUp's documentation at https://docs.controlup.com and explore automation capabilities in the ControlUp Academy at https://cuacademy.controlup.com.
Read the entire article here...
Read the entire article here...
How to Report Horizon Client Versions Across User Sessions Using ControlUp
A common requirement for managing VMware Horizon environments is the ability to report on the endpoint client versions—referred to as "HZ Client Version"—used by users to connect to the Horizon infrastructure. This need becomes particularly important in hybrid environments where users connect from both managed internal devices and unmanaged BYOD (Bring Your Own Device) endpoints. Tracking client versions helps administrators identify devices running outdated Horizon clients that require upgrades to ensure security, compatibility, and optimal performance.
Within ControlUp, the Horizon client version information can be accessed via several mechanisms. The VDI - Details view in the ControlUp console displays the HZ Client Version associated with each session, providing a straightforward way to see the current client version used. For programmatic or historical data extraction needs, ControlUp also offers a real-time data API (https://api.controlup.io/reference/gettables) which can retrieve live session details including client versions. Additionally, the "initial HZ client version" field recorded in the Session Activity report captures the client version that was used to start the session. This field, although labeled as "initial," effectively serves as a snapshot of the client version at session start.
However, because users in hybrid scenarios may connect multiple times throughout the week from different devices or update their Horizon client between sessions (for example, by disconnecting, updating, and reconnecting), it is important to consider that the client version can vary across sessions. The "initial HZ client version" is tied to each individual session start, so accumulating this information over a period allows administrators to identify all versions in use and target users on outdated clients. Pulling session activity reports over time and correlating the client versions used enables identification of BYOD devices needing updates even if the same user connects from multiple endpoints.
In summary, the "initial HZ client version" contained in ControlUp’s Session Activity reports is the key field for tracking Horizon client versions across user sessions. The ControlUp real-time data API further facilitates custom querying and automation for this reporting. For detailed exploration of session data, the VDI - Details view complements these options with an at-a-glance interface. Using these tools, administrators in hybrid environments are able to efficiently monitor and manage Horizon client versions on both managed and BYOD devices, ensuring compliance and performance consistency.
Read the entire article here...
Read the entire article here...
Troubleshooting Missing Unified Access Gateway Metrics in ControlUp Due to Horizon API Version Limitations
When configuring the connection to VMware Unified Access Gateway (UAG) in ControlUp version 9.2.5.634, a common issue arises where the UAG appears connected but does not show any metrics or visibility under the EUC Environment or the DEX Connection Servers section. Although the initial connection test succeeds, UAG metrics are missing from the interfaces, leading to confusion about what might be incorrectly configured.
One critical root cause identified is related to the Horizon REST API version supported by the UAG and Connection Servers. ControlUp relies on Horizon’s Monitor Gateways API version 5 to retrieve UAG data, but many Horizon environments running version 2412 or earlier only support versions 3 or 4 of this API. This incompatibility prevents ControlUp from properly monitoring the UAG, resulting in the absence of UAG metrics despite a seemingly successful connection configuration. This limitation is not explicitly detailed in ControlUp’s documentation, making it an easy pitfall for users in older Horizon environments.
Users who upgraded their Horizon Connection Servers to version 2603 reported that after refreshing the UAG settings in ControlUp, UAG metrics became visible and functional, confirming that full UAG monitoring support requires Horizon environments with API version 5 or newer. For those in unsupported environments, the UAG section will fail to sync correctly, although some other synchronization data like "NIC" sync may still appear. This partial failure causes issues with automatic EUC syncs, which will fail on an hourly schedule unless UAG syncs are disabled. Manual syncs from the ControlUp Console, however, still function as a workaround until an official fix or workaround is provided by support.
In light of these findings, users experiencing missing UAG metrics should verify the Horizon API version compatibility and consider upgrading their Horizon environment if UAG monitoring is required. It is also advisable to coordinate with ControlUp support to analyze logs and explore potential short-term solutions. Additional monitoring configuration details can be found in ControlUp’s official documentation on monitoring OmniSaaS and UAG here: https://support.controlup.com/docs/monitor-omnissa-unified-access-gateway. This document clarifies the expected behaviors and limitations with UAG monitoring in various Horizon versions.
Read the entire article here...
Read the entire article here...
Managing Disk Usage on Laptops with ControlUp SIP Agent
ControlUp provides a scripting engine within ControlUp for Desktops, enabling IT administrators to distribute and execute scripts across devices in their environment. This functionality allows for tasks such as IT administration and data collection. ([support.controlup.com](https://support.controlup.com/docs/scripting-guide?utm_source=openai))
To utilize this feature, navigate to ControlUp for Desktops > Configuration > Scripts to view and manage your scripts. The Scripting Guide offers comprehensive instructions on running scripts in ControlUp for Desktops. ([support.controlup.com](https://support.controlup.com/docs/scripting-guide?utm_source=openai))
For managing disk usage on laptops equipped with the SIP agent, you can adapt existing scripts designed for VDI environments. The Scripting Guide provides detailed information on creating and managing scripts, which can be tailored for laptops. ([support.controlup.com](https://support.controlup.com/docs/scripting-guide?utm_source=openai))
Additionally, the ControlUp Script Library offers a collection of useful scripts compiled by ControlUp, which can be imported and customized for your specific needs. ([controlup.com](https://www.controlup.com/scripts/?utm_source=openai))
By leveraging these resources, you can effectively monitor and manage disk usage on laptops using the SIP agent, similar to the capabilities available for VDIs.
Read the entire article here...
Read the entire article here...
How to Deploy ControlUp Agent via GPO in VDI Environments with MSI Silent Install and PowerShell Automation
Deploying the ControlUp Agent for VDI environments via Group Policy Object (GPO) does not have a dedicated official knowledge-base article, as the installation approach aligns with generic MSI silent installs used in other deployment methods like SCCM or PDQ. The official ControlUp documentation regarding local machine connection and agent communication is the primary reference for deployment: https://support.controlup.com/docs/connect-to-your-machines-locally and https://support.controlup.com/docs/agent-outbound-communication.
For non-persistent VDI setups that use a gold master image, the recommended method is to install the ControlUp agent MSI directly on the master image with specific MSI properties: `MASTER_IMAGE=true`, along with the `AUTHKEY` and `RegistrationKey`. This avoids the need for repeated installations on cloned machines via GPO. For persistent, domain-joined virtual machines, using a GPO Computer Startup Script to run an msiexec command is preferred over GPO Software Installation because it allows passing required MSI properties. An example command line looks like this:
`msiexec /i \\share\ControlUpAgent-xxxx.msi /qn AUTHKEY="" RegistrationKey="" MASTER_IMAGE=true`
The authentication keys are retrieved from the Real-Time Console under Settings → Agent. The Registration Key is mandatory starting from version 9.0. Machines must be manually added to the organization tree unless the agent version is 9.0.5 or higher, which supports self-registration.
When GPO deployment is not optimal, if remote RPC or WMI connectivity is available, deploying the agent remotely via the ControlUp console or Monitor is simpler. For cloud-managed endpoints, Microsoft Intune is the officially documented deployment method.
A practical example was shared demonstrating a PowerShell script to deploy the ControlUp Agent MSI for VDI within a Nerdio scripted action context. The script copies the MSI from a UNC file share to a local temporary path, validates that the MSI file is correctly copied (including a check on the MSI magic bytes), and then executes the msiexec command with silent installation flags, the authentication keys, and logging enabled. It captures and reports installation exit codes and prompts when a reboot is required. The script also includes a post-installation check to list ControlUp-related services to confirm the agent installed and started as expected.
This approach encapsulates the best practice for deploying ControlUp agents in VDI environments using GPO, balancing MSI property requirements, version-specific authentication mechanisms, and practical scripting for automation. For detailed agent deployment contexts and command-line references, the ControlUp official documentation remains the authoritative source: https://support.controlup.com/docs/connect-to-your-machines-locally and https://support.controlup.com/docs/agent-outbound-communication.
Read the entire article here...
Read the entire article here...
How to Configure Low Disk Space Alerts by Percentage in ControlUp for Devices
In ControlUp for Devices (CU4D), setting up an alert to notify an administrator when any device's OS disk free space drops below a certain threshold can be configured through the Events > Alert Rules section. To create an alert for low disk space, a user needs to define the appropriate category, metric, condition, and value that represent the target threshold.
The recommended approach is to use an alert rule that monitors the free space on the OS disk. While the initial example provided in the community discussion suggested a value-based threshold (e.g., a specific number of gigabytes free), it is also possible to configure an alert based on a percentage of free disk space. This is important for flexibility as percentages provide a more relative and scalable measure across devices with different disk sizes.
To implement this, the alert should be defined in the category related to storage or disk metrics. The metric to monitor would be the percentage of free space available on the OS disk. The condition would then be set to trigger when this percentage falls below a certain value (such as 10%). Once the alert triggers, it can be configured to send an email notification to administrators. Furthermore, ControlUp’s integration with script actions can automate responses to these alerts, such as running a system disk cleanup or presenting a user prompt to clean up space.
For detailed steps and additional options, users are encouraged to refer to the official ControlUp documentation on alert rules and script actions, as well as the ControlUp Knowledge Base and Academy resources at https://docs.controlup.com and https://cuacademy.controlup.com. These resources provide comprehensive guidance on setting conditions, selecting metrics, and automating remediation workflows based on alerts.
Read the entire article here...
Read the entire article here...
How IP Restrictions Affect REST API Access and How to Configure the IP Allow List in ControlUp
When IP Restrictions are enabled in a ControlUp organization, they apply not only to user sign-in at app.controlup.com but also to REST API calls that use API keys or tokens for authentication. Initially, there was confusion about this behavior, with one party assuming that IP Restrictions only affected user sign-ins via the web application and would not restrict API calls. However, further investigation clarified that IP Restrictions do indeed apply to API requests.
The key issue encountered was that reporting workflows that fetch machine statistics via the REST API started returning "Unauthorized" errors after IP Restrictions were enabled. Although the API tokens used for authentication were verified as valid and not expired, the requests failed due to the IP restriction settings.
The resolution involves adding the public egress IP addresses of the systems making the API calls (such as those running the reporting workflows) to the organization's IP Allow List in ControlUp. This setting is accessible under Settings → Security → IP Allow List in the ControlUp management console. Once the calling system’s IP addresses are added to the allow list, API calls from those IPs will be authorized, provided a valid API token is also used.
For more detailed guidance, official ControlUp documentation and references include the API endpoint for managing IP allow lists (https://api.controlup.io/reference/orgipallowlistpubliccontroller_create) and the knowledge base article on IP Allow Lists (https://support.controlup.com/docs/ip-allow-list). These resources offer comprehensive instructions for configuring the IP Allow List to control API access securely.
Read the entire article here...
Read the entire article here...
Widget Wednesday #25: Building Dashboard Widgets with Audit Log Data
This week’s Widget Wednesday introduces a new data source for ControlUp Dashboards: the Audit Log.
Read the entire article here...
Read the entire article here...
NEW ControlUp Disk cleanup script that actually asks the user what to delete
Chris Twiest demos a new interactive disk cleanup utility built by Sebastien Perusat and now baked into the product. Instead of silently cleaning from the system context, it prompts the end user with what can be reclaimed and lets them choose — recycle bin, temp files, browser cache. Works on Windows and macOS, can be triggered manually or from an alert, writes results to a data index and a device event, and is fully editable. Available in the script library now.
Read the entire article here...
Read the entire article here...


