Trusted devices
Serverless Security Stack
By default, Elastic Defend policies have device control enabled, with access level set to block all operations. This prevents external storage devices from connecting to protected hosts.
Trusted devices are specific external devices that are allowed to connect to your protected hosts regardless of device control settings. Create trusted devices to avoid interfering with expected workflows that involve known hardware.
By default, a trusted device is recognized globally across all hosts running Elastic Defend. You can also assign a trusted device to a specific Elastic Defend integration policy, enabling the device to be trusted by only the hosts assigned to that policy.
Add a trusted device to exempt it from device control:
- Go to the Trusted Devices page using the navigation menu or the global search field.
- Click + Add trusted device. The Add trusted device flyout opens.
- Name your trusted device and give it a description.
- In the Conditions section, specify the operating system(s) and the
Device ID. - Select an option in the Assignment section:
- Global: Assign the trusted device to all Elastic Defend integration policies.
- Per Policy: Assign the trusted device to one or more specific Elastic Defend integration policies.
- Click Add trusted device.
The Trusted devices page displays all the trusted devices that have been added to the Elastic Security app. To refine the list, use the search bar to search by name, description, or field value.
You can individually modify each trusted device. You can also change the policies that a trusted device is assigned to.
To edit a trusted device:
- Click the actions menu (…) on the trusted device you want to edit, then select Edit trusted device.
- Modify details as needed.
- Click Save.
You can delete a trusted device, which removes it entirely from all Elastic Defend integration policies.
To delete a trusted device:
- Click the actions menu (…) on the trusted device you want to delete, then select Delete trusted device.
- On the dialog that opens, verify that you are removing the correct device, then click Delete. A confirmation message appears.