Mohsin Anwar Sharif

An installed agent is not a working control.

Security consoles count devices that have an agent. They do not tell you whether that agent is online, whether its engines are running, or whether the device is missing from other tools. I built a workbook that joins ten security tools against the asset inventory and answers the real question: which devices are actually protected?

Agent present
–
Actually protected
–

All figures on this page come from a fictional 1,500-device estate across six entities. No employer data is used.

Explore the estate

This is the management view the workbook produces. Filter by entity or device type; every figure recalculates from the device-level data.

In-scope devices
EDR agent present
EDR verified protected
Present but not protected
Average control score

Protection by entity

ProtectedPresent, not protectedNo EDR

Days since last patch

Coverage by tool

Zscaler, DLP and Intune do not apply to servers.

Last seen on the web proxy

Devices that need action

Agent present, not protected. The reason column is what goes to the platform team or, where local admin rights are needed, to infrastructure.

DeviceEntityTypeReasonPatch

How the workbook reaches an answer

Each step feeds the next. The report is only released when the reconciliation checks pass.

  1. Start from the inventoryThe asset register defines the population. Non-persistent VDI is listed but excluded from percentages.
  2. Normalise every nameEach tool export gets a cleaned key, so "pc01", "PC01 " and "PC01" match.
  3. Join ten toolsSentinelOne, Trend Micro, Defender, Intune, Entra ID, ManageEngine, NAC, NAC exclusions, Zscaler and DLP.
  4. Check health, not presenceSentinelOne counts only if online with all expected engines healthy; Defender only if the sensor is active.
  5. Classify and scoreProtected, present but not protected, or no EDR; plus a control score over the checks that apply to each device type.
  6. Reconcile, then reportBuckets must add up to the in-scope population before figures go to management.

What I fixed in my own tool

Version 1 was built by hand at work and ran our biweekly reporting. Rebuilding it, I found defects that affected the numbers. These are the ones that mattered.

About this work

The original workbook, its design and every formula in it were built by me, by hand, while running endpoint security operations for a multi-country bank. This public version rebuilds the same design on fictional data, corrects the defects above, and was produced with AI assistance under my direction. The method, the checks and the judgement about what counts as protected are mine, and I can walk through any cell of it.

The workbook, a Power BI version of the model, and a walkthrough recording are available on request.