Find the machines that need a person
The two lists on RMM > Devices that decide where a tech looks first: the card of installs that never joined, and the roster's own needs-attention order, with the sort, the bulk picks and the ten filters behind the Filters button.
What you will have
- Know what lands on the Installs that need attention card, and what a row on it means.
- Read the roster's own order, and the line that separates the machines needing a person from the rest.
- Sort the roster your own way, and put the default order back.
- Pick several machines and act on them together.
- Find the ten filters behind the Filters button, and see at a glance which ones are set.
- Open a machine's own Security tab, and know what makes its cards appear or stay hidden.
Why it works this way
The install card sits above the roster because the machines on it are not in the roster at all. They tried to join and never got that far.
One row on that card is one problem on one machine, however many times it has been tried. A different problem, or the same machine name at a different client, gets its own row.
The roster opens sorted by what needs a person, not alphabetically. A healthy machine is still on the list, under the line.
Only the search box, Client and Status stay on the bar, because almost every question uses one of those three. The rest sit behind the Filters button so the bar stays readable.
Steps
Open RMM, then Devices.
The page opens on the roster of every enrolled machine across every client. Above it sits Installs that need attention, with a count of the rows on it. The card is hidden whenever there is nothing on it.
Open RMM, then Devices. Read one row on the card.
A row names the machine and the client it was for, what stopped it, when, and the reference the report came in under. Rows land here for three reasons: the install stopped at a step, the service started and then kept stopping, or the install worked and the machine still has not connected after ten minutes.
Read one row on the card. Check the count beside a machine's name.
The same problem on one machine stays one row, however many times somebody has tried. The count says how many reports that one row holds, and the reference beside it says which attempt the newest one was.
Check the count beside a machine's name. Use View report to read the whole thing, or Dismiss once you have dealt with it.
View report opens the machine's own report: the installer's own checklist, step by step, marked as the person at the machine saw it, and the log from that machine. Dismiss clears every report for that same problem at once, so it does not come back one at a time. A new problem on that machine later still shows up. This card makes no ticket and sends no mail.
Warning: Dismiss clears every report for that problem on that machine, not only the row you pressed it on.Use View report to read the whole thing, or Dismiss once you have dealt with it. Under the card, use the three buttons above the roster.
All is everything you have. Needs attention keeps only the machines above the line. Offline keeps the machines that are dark.
Under the card, use the three buttons above the roster. Find the line inside the list.
Everything above the line needs a person. A critical alert comes first, then a machine nobody has heard from in over a day, the quietest first, then an open alert or third party app updates that are broken. The line itself says how many other machines there are, and those are sorted by last check-in, newest first.
Find the line inside the list. Click a column heading to sort your own way.
The bar then says which column you sorted by, and Reset puts the needs-attention order back. While your own sort is on, the line inside the list goes away, because the list is no longer split.
Click a column heading to sort your own way. Tick the boxes on the left to pick machines.
A bar appears above the list with Move to another client and Remove, and Clear selection to drop the picks again. The box in the header picks every machine on the page.
Warning: Both buttons act on every machine you have ticked, not only the row you are looking at.Tick the boxes on the left to pick machines. Press Filters for the rest of them.
The panel holds ten more: Approval, Agent, Version, Ring, Warranty, Type, OS, Alerts, Patches, and Active or Archived. A Tags filter joins that panel once at least one machine on the roster carries a tag, and stays hidden until then.
Press Filters for the rest of them. Set one and look back at the bar.
A number on the Filters button says how many are set, and every filter you set also shows under the bar with an X to take it off. The list narrows as you go. The web address uses the same names, so an old bookmark or a link a workmate sent you still works.
Set one and look back at the bar. Read the report that View report opens.
It names the machine, the client, its agent version and its OS, then the same seven-row checklist the person at the machine watched, marked the same way: a check for what it reached, a cross for where it stopped, and a hollow circle for what it never got to. Below the checklist sits the reason in Windows' own words, then Show log for the raw detail underneath, collapsed until you ask for it. The last line names who it was reported by and the reference again, so a code you read out over the phone and the report you opened here are always the same one.
Read the report that View report opens. Open a machine's own Security tab.
It carries this machine's security posture: which drives are encrypted with a gated reveal for the BitLocker key, the escrowed local admin password (LAPS), and the NIST 800-171 baseline it is scored against. Each of those is its own card, and each stays hidden until the agent has reported that kind of data. Underneath them, Isolation & trust holds the two switches beside the machine's own trust receipt: Quarantine, which turns the agent away at its next check-in, and Telemetry, which is what is feeding this page's own CPU, memory and disk figures. Both switches need the RMM edit permission to change, and this card only shows once a live agent is enrolled or the machine carries an approval on record.
Open a machine's own Security tab.
Other ways to do this
The three pickers that stay on the bar
The search box, Client and Status sit on the bar itself, beside the Filters button.
If it did not work
- No install card at the top: nothing has failed on install, or every report has been dismissed. The card is hidden when there is nothing on it.
- No Tags filter in the panel: no machine on the roster carries a tag yet.
- The list will not sort the way you expect: the needs-attention order wins until you click a column heading, and Reset brings it back.
- A machine that could not reach us at all never makes this card: no report was sent, so there is nothing to show. It leaves a copy on its own desktop instead, named ezCyber-install-report.txt, for whoever is sitting at it.
- A machine with no live agent and no approval on record shows no Isolation & trust card and none of the other Security cards either. The tab reads "No security data yet" instead, never a switch with nothing behind it.
Questions this page answers
Why are some devices at the top of the list?
Every device you have is on this list, healthy ones too. The ones that need a person are sorted to the top. A critical alert comes first. Then a machine we have not heard from in over a day, the quietest one first. Then an open alert, or third party app updates that are broken. Under those there is a line that says how many other devices there are. Those are sorted by last check-in, newest first. The three buttons above the list narrow it: "All" is everything, "Needs attention" keeps only the rows above the line, and "Offline" keeps the machines that are dark. Click a column heading to sort your own way. The bar then says which column you sorted by, and a "Reset" link puts the top-of-list order back. Tick the boxes on the left to pick machines; a bar appears with "Move to another client" and "Remove" for all of them at once.
Where did the rest of the filters go?
Three buttons sit above the bar for the questions people ask most: "All", "Needs attention" and "Offline". The rest are behind the "Filters" button. The search box, Client and Status stay on the bar because almost every question uses one of those three. The button opens a panel with ten more: Approval, Agent, Version, Ring, Warranty, Type, OS, Alerts, Patches, and Active/Archived. A Tags filter joins that panel once at least one device on the roster carries a tag; until then it stays hidden. A small number on the button says how many of them are set. Every filter you set also shows under the bar with an X to take it off, so you can always see why the list looks the way it does. The web address still uses the same names, so an old bookmark or a link a workmate sent you still works.
What is the reference on an install row?
It is a short code like INS-7K2Q. The person at the machine sees the same code on the installer window. It reads "Report sent to" and then your name and the code. So they can read it out to you over the phone. Each machine gets one code per install. If they press Retry, the same row is updated. It is not a second row. The row then says which attempt it is. If the machine could not reach us at all, no report is sent. A copy is saved on their desktop instead. The file is named ezCyber-install-report.txt.
What is the Security tab for?
It puts this device's security posture in one place. You see which drives are encrypted, and you can reveal a BitLocker recovery key. That reveal needs the right permission and is written to the audit log. You also see the escrowed local admin password (LAPS) and the NIST 800-171 baseline this device is scored against. If a live agent is enrolled, two switches sit beside the device's trust receipt: Quarantine and Telemetry. Quarantine turns the agent away at its next check-in. Changing either switch needs the RMM edit permission. A device with no live agent shows no switches at all, not a dead control.
Was this helpful?