Security consoles count devices that have an agent. They do not tell you whether that agent is online, whether its engines are running, or whether the device is missing from other tools. I built a workbook that joins ten security tools against the asset inventory and answers the real question: which devices are actually protected?
All figures on this page come from a fictional 1,500-device estate across six entities. No employer data is used.
This is the management view the workbook produces. Filter by entity or device type; every figure recalculates from the device-level data.
Zscaler, DLP and Intune do not apply to servers.
Agent present, not protected. The reason column is what goes to the platform team or, where local admin rights are needed, to infrastructure.
| Device | Entity | Type | Reason | Patch |
|---|
Each step feeds the next. The report is only released when the reconciliation checks pass.
Version 1 was built by hand at work and ran our biweekly reporting. Rebuilding it, I found defects that affected the numbers. These are the ones that mattered.
The original workbook, its design and every formula in it were built by me, by hand, while running endpoint security operations for a multi-country bank. This public version rebuilds the same design on fictional data, corrects the defects above, and was produced with AI assistance under my direction. The method, the checks and the judgement about what counts as protected are mine, and I can walk through any cell of it.
The workbook, a Power BI version of the model, and a walkthrough recording are available on request.