Multi-Tenant Management — Settings Inheritance for Subscriber Accounts

Applies To: WatchGuard Advanced EPDR, WatchGuard EPDR, WatchGuard EDR, WatchGuard EPP

To open the multi-tenant management UI for endpoint security, your Service Provider account must have an active WatchGuard Endpoint Security product license in its inventory.

In the Endpoint Security management UI, Subscriber accounts can create and assign security settings profiles to the computers and devices they manage. They might also receive settings that a Service Provider created and assigned to them. This topic describes settings inheritance when a Service Provider assigns settings to a managed Subscriber account.

For information on how to assign settings to managed Service Provider accounts, go to Multi-Tenant Management — Settings Inheritance for Service Provider Accounts.

Service Providers cannot assign security settings of delegated accounts in the multi-tenant management UI.

Settings profiles that Service Providers assign to a managed Subscriber account are read-only in the Subscriber account. The settings profile includes a green Service Provider label (The Service Provider label.) to differentiate it from profiles created manually at the account-level.

Screen shot of Service Provider Endpoint Manager, Service Provider tag

Ownership of these settings profiles (that is, who can edit and delete them) is based on who created the settings profile (Service Provider or Subscriber). Refer to the appropriate section:

Inherited Editable Settings

By default, the managed accounts to which you assign a settings profile cannot edit or delete the configuration. You can configure some settings profiles to allow the managed account to make additions. You can enable the account to make additions for these settings:

  • Scan exclusions
  • Authorized software
  • Allowed IP addresses for Endpoint Access Enforcement

When you enable changes, the settings profile shows an Editable Exclusions, Editable Settings, or Editable Protocols label in the management UI of the recipient account. The managed account can make additions, but they cannot delete or edit the list you defined.

If you reconfigure the option to be non-editable, any additions that the managed account made no longer apply. Only the exclusions from your Service Provider account apply. If you change the option again to be editable, then the exclusions, authorized software programs, or allowed IP addresses that the managed account added are restored and applied.

Changes made by a Service Provider to the settings assigned to a tenant account automatically reflect in the tenant account Endpoint Security management UI. The changes propagate to the target devices in real-time or within 15 minutes when real-time communication is disabled. For more information, go to Disable Real-time Communication.

Settings Exceptions

If the account group has devices with settings that were directly assigned, a yellow caution symbol shows beside the account name in the list. You are prompted to keep the settings that are directly assigned or to overwrite the local settings and inherit all settings from the account group.

When Service Providers assign a security settings profile to an account or account group, the settings are applied to the All group and inherited by any sub-groups. If any of the sub-groups, computers, or devices have manually assigned settings, an exception occurs and WatchGuard Endpoint Security does not assign the settings profile.

When Service Providers assign settings in the multi-tenant management UI, they can view exceptions on the Settings page. If the list of accounts shows a black number in the colored line, this part of the account list is collapsed and some accounts have exceptions to the settings profile they assigned. Double-click the number to show the accounts with exceptions.

Screen shot of Service Provider Endpoint Manager, settings exceptions

To review manually applied settings, you must open the Endpoint Security management UI for the account.

Related Topics

Multi-Tenant Management of Settings Profiles

Multi-Tenant Management — Assign Endpoint Security Settings to Managed Accounts

Settings Inheritance in Subscriber Accounts

Restore Inheritance in Subscriber Accounts