Skip to content

EDR Integration #4091

Description

@abhishek9686

Summary

Integrate with Endpoint Detection and Response (EDR) platforms so Netmaker can use endpoint security posture and threat signals when granting or revoking network access.

Goals

  • Use EDR health/threat status as a zero-trust posture signal
  • Automatically restrict or revoke access for compromised or unhealthy endpoints
  • Improve incident response by correlating network access with endpoint security events
  • Align Netmaker with enterprise EDR stacks (e.g. CrowdStrike, SentinelOne, Microsoft Defender)

Scope (initial)

  • Integration(s) with one or more major EDR providers
  • Posture checks (agent present, healthy, no critical detections) at access time
  • Policy actions: allow / warn / deny / quarantine network access
  • Audit trail of posture-based access decisions

Related

  • MDM Integration (device management vs endpoint threat posture)
  • Network Alerts / SIEM (notify and export posture-driven events)

Success criteria

  • Admins can require healthy EDR posture for access
  • Compromised/unhealthy devices can be automatically denied or isolated per policy
  • Posture decisions are logged and investigable

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status
    Q3 2026

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions