ManageEngine Endpoint Central features
发布时间:2026-09-11 | 浏览:2
Endpoint Central is a unified endpoint management and security solution. Every feature below from patching to EDR to DLP is built into one platform.
Patch and update management
Secure and stabilize operating systems, applications, and mobile apps with automated patches and updates.
Automated patching
'Set-and-forget' automation of patching - right from scanning, detecting, and testing, to deploying the patches.
99% first-pass success link
Test and approve
Test patches for stability and compatibility on a testbed before deploying them.
User-centric deployment policies
Customize deployment schedules with pre- and post-deployment checks, installation time flexibility, and post-installation reboot options.
Third party patching
Install tested patches for third-party desktop applications and set up automatic updates for mobile apps.
1100+ applications link
Decline patches
Perform selective patching by declining problematic/less critical patches, temporarily or permanently.
Vulnerability remediation
Utilize continual vulnerability intelligence, rigorous assessments, and rapid remediation to mitigate threats.
Vulnerability assessment
Scan, detect, prioritize vulnerabilities based on severity, age, exploit code disclosure, and more.
Zero-day mitigation
Get notified of zero day patches, deploy prebuilt & tested mitigation scripts before actual fixes are released.
Security configurations management
Identify misconfigurations in OSs, applications, browsers, and audit firewalls, anti-virus for CIS compliance.
Web server hardening
Inspect web servers for insecure configurations and receive security recommendations to fix them.
High-risk software audit
Audit and eliminate end-of-life software, peer-to-peer, insecure remote desktop sharing software.
Compliance Customization
Stay compliant with 130+ CIS benchmarks, UK Cyber Essentials, and NIST standards, with customizable CIS policies.
Endpoint Detection and Response
Continuously monitor endpoint activity, detect advanced threats in real time, and rapidly contain attacks before they spread.
Endpoint activity monitoring
Gain complete visibility into endpoints by continuously correlating process, file, network, registry, and user activity to uncover suspicious behaviour.
Threat detection and investigation
Identify and investigate known and unknown threats using behavioural analytics, threat intelligence, and MITRE ATT&CK-mapped indicators of compromise.
AI guided forensic analysis
Accelerate threat investigations with Zia AI-guided forensic insights, attack timelines, and contextual threat analysis.
Intelligent alert triage
Leverage Zia AI to correlate and prioritise alerts, quickly surfacing high-risk threats and accelerating incident response.
Incident response
Contain active threats by isolating compromised endpoints, terminating malicious processes, and rolling back infected systems to a clean state.
Proactively search across 30 days of recorded endpoint activity to uncover hidden, dormant, and low-and-slow threats before they escalate.
Malware Protection
Next-gen antivirus
Proactively detect, prevent, and mitigate malware threats with our robust, patented technology.
Multi-layered detection
Use AI-assisted behavior-based detection and deep-learning based anti-virus for online/offline reactive malware security.
MITRE TTPs-based incident forensics
Examine anomalous detections within the kill chain framework for comprehensive analysis.
Contextual threat remediation
Immediately contain malware by quarantining infected devices and neutralizing attacks in real-time.
Anti-Ransomware
Locking out ransomware threats with top-tier encryption shields, heuristic analysis, and single-click recovery.
Behavior detection engine
Driven by AI/ML, ensures rapid identification of ransomware behavior with an exceptional 99.5% accuracy.
Device quarantine & incident analysis
Efficiently quarantine infected devices and conduct thorough incident analysis for comprehensive security.
Single-click recovery
Incremental VSS shadow copy backups, enabling swift restoration and rollback in ransomware incidents.
Browser security
Secure multiple browsers, monitor usage trends, and comply with compliance standards like STIG.
Browser restriction
Mandate the use of only trusted/approved browsers in your network.
Add-ons and extension management
Monitor installations and usage of add-ons, extensions and plugins across various browsers.
Browser lockdown
Enforce a kiosk mode allowing only approved websites and web apps.
Browser isolation
Isolate unauthorized websites to create a secure sandbox, to avoid sensitive data exposure.
Java rules manager
Assign the appropriate Java versions to web apps based on specific site requirements.
Automatically redirect legacy web apps to legacy browsers when open in modern browsers.
Application control & privilege management
Set installation permissions, monitor privileges, and ensure zero-trust security with role-based and time-based privileges for applications.
Allowlist & blocklist
Prohibit software installation, block executables, create self-updating allowlists and blocklists.
Application privilege management
Apply role-based access and permissions to applications.
Global child process control
Control and monitor the execution of child processes.
Admin rights removal
Remove unnecessary admin rights to reduce the attack surface and enforce least privilege.
Just-In-Time access
Provision users with temporary and limited privileges precisely when needed.
Conditional access
Ensure only authorized devices have access to Exchange services.
Enable per-app VPN to secure connections at the application level.
Try a fully functional 30-day free trial
Detect and encrypt sensitive data, define rules for authorized usage, and ensure secure transmission.
Sensitive data discovery & classification
Scan and identify locations with sensitive data and classify them based on pre-defined or custom data rules.
Data leak prevention
Prevent data leakage, intentional or accidental, by controlling data behavior while at rest, in use, and in motion.
Containerization
On BYODs, separate and encrypt work data from personal data with logical containers.
De-provisioning wipe
Remotely wipe or factory reset lost/stolen devices to secure corporate data.
File tracing and mirroring
Monitor sensitive file transfers and create mirror copies when necessary.
Data encryption
Leverage BitLocker and FileVault to implement encryption policies with minimal user intervention.
Secure Private Access
Replace traditional VPNs with granular, application-level access that connects users only to authorized resources on trusted devices.
Zero trust-based access control
Enforce least-privilege access with identity verification, device trust validation, and granular access policies.
Application-based access control
Define internal applications by name, DNS, and port, and organize them into app segments aligned to teams or departments for granular, policy-driven access.
User and device verification
Continuously validate user identity and device trust before allowing access to private applications.
Secure tunneling
Establish encrypted, application-level tunnels between users and private resources without exposing the corporate network.
Comprehensive access auditing
Track and audit all access activity from a centralised console to detect suspicious behaviour and simplify compliance reporting.
Asset management
With live notifications and predefined inventory reports, discover, track, and control all your hardware, software, and digital assets.
Asset monitoring
Real-time discovery, tracking and reporting of software and hardware by OS, manufacturer, age and device type.
License management
Track, document and be notified of the expiry dates, over-usage and under-usage of software licenses.
Warranty management
Keep tabs on soon-to-expire, expired and unidentified warranty details of software and hardware.
Certificate management
Simplify the creation, distribution and renewal of trust certificates and user-signed certificates.
Create a virtual fence based on a geo-location and mark devices leaving them as non-compliant trigger a set of actions.
Power management
Control the power consumption of devices with power schemes.
USB device management
Prevents unauthorized download and upload on USB and peripheral devices.
Application distribution
Remotely distribute and monitor user-based and device-based MSI, EXE, and mobile apps across the network.
Pre-defined templates
Deploy applications effortlessly using pre-defined, tested templates with inbuilt install/uninstall switches.
10,000+ available link
Software repository
Store packages in a central file location like Network Share repository or HTTP repository for access, retrieval or backup.
Over-the-air mobile app distribution
Distribute, install and update mobile apps to devices, silently and automatically.
Software metering
Collect usage counts and duration to reduce expenses from unnecessary renewals and upgrades.
Self-service portal
Publish application and patches to the self-service portal and empower users to install applications on their own.
Enterprise app catalogue
Build an app catalog for easy discovery and installation of organization-approved applications.
Digital Employee Experience
Transform endpoint telemetry into actionable insights to monitor performance, track experience, and resolve issues proactively, all within the same console.
App & device performance metrics
Leverage real-time telemetry to track CPU, memory, GPU, disk usage, and app crashes. Spot early warning signs of device or app slowdowns before they impact users.
Move beyond surface-level alerts with built-in Root Cause Analysis. Correlate telemetry across device models, apps, and configurations to quickly isolate the “why” behind performance issues.
Automated remediation workflows
Turn insights into actions with automated remediation. Build detection-to-resolution workflows that fix recurring problems, without waiting for tickets.
Experience scoring & benchmarking
reliability, performance, responsiveness, and app reliability. Compare against baselines to uncover underperforming devices.
Extensible action library
Leverage pre-built scripts, workflows, and dashboards, or build your own, to remediate .
Book our experts for a free demo
Remote access and troubleshooting
Perform system operations remotely with multi-user collaboration if you need to troubleshoot a device.
Enable remote connectivity from anywhere and perform operations with handy widgets.
Recorded sessions
Record each session for supervision and audit purposes.
Perform disk cleanups and disk de-fragmentation to upkeep endpoints.
Broadcast computer/user specific announcements, along with the event priority, right on the screen.
Collaborative troubleshooting
Engage all stakeholders in issue resolution with comprehensive multi-technician support.
Cross-channel user interaction
Resolve issues via text, calls, and video with end-users for prompt support.
OS imaging and deployment
Implement modern techniques for customizing and automating disk imaging and deployment.
Online and offline imaging
Image live and shutdown machines, using intelligent online and offline imaging techniques.
Zero touch deployment
Deploy OSs to remote machines in bulk without physical intervention using PXE, USB and ISO.
Deploy OS to machines out of your network using standalone deployment.
Hardware independence
Deploy the image to any system, irrespective of the hardware or vendor type.
Customized deployment templates
Customize images with deployment templates for different roles/departments.
User profile migration
While creating image, migrate the personalized user settings and configurations.
We fit your budget and exceed your expectations. Reach us for a personalized quote today!
Configuration management
Centralize and manage user-based and computer-based configurations for improved efficiency.
System configurations
Use pre-defined configurations for users and computers for base-lining.
40 and more link
Profile management
Create, publish and associate profiles to devices and groups to apply configurations.
Kiosk management
Lockdown devices to use settings, apps and policies approved by IT team for enhanced control.
Script repository
Use custom scripts or scripts templates built by us to perform for unique tasks.
350 and more link
Reporting and auditing
Ensure compliance with regulations and generate comprehensive reports for auditing purposes
Audit-ready templates
Ensure compliance with audit-ready templates for various regulatory requirements.
Active directory reports
Utilize out-of-the-box Active Directory reports on users, computers, groups, OUs, and domains.
Compliance standards
Meet HIPAA, GDPR, CIS, ISO, PCI and other compliance standards with Endpoint Central's dedicated features.
Mobile Device Management with Endpoint Central
Bring corporate-owned and personal devices under centralized control across Android, iOS, iPadOS, macOS, Windows, ChromeOS, and tvOS, from the same console you already use for desktops and laptops.
Device enrollment & inventory
Automate onboarding across Apple, Android, and Windows devices, and track every enrolled device in real time with instant lock, reset, or wipe if it's lost or stolen.
Profile & policy management
Push Wi-Fi, VPN, and security profiles over the air, and enforce passcode, content, and data loss prevention policies automatically by department.
App & content management
Bulk deploy and silently update approved apps across the fleet, and distribute files through a secure viewer with access revoked instantly for lost devices.
Mobile security & data protection
Block untrusted networks and sideloaded apps, cut off jailbroken devices automatically, and keep BYOD data encrypted in a separate, wipeable container.
Kiosk & rugged device management
Lock devices to a single app or kiosk mode, and manage rugged, Google Play-free hardware with OEMConfig profiles from 22+ manufacturers.
Remote troubleshooting
Take remote control of devices across 25+ OEM brands, with in-session chat and file transfer for faster fixes, all AES-256 encrypted.
Disk encryption management
Centralized encryption control
Manage BitLocker, FileVault, TPM, and protector settings across Windows and Mac endpoints from a single console.
Granular policy deployment
Map flexible encryption policies to custom groups and deploy them via secure agent-server communications.
Automatic encryption at scale
Deploy encryption policies to multiple users simultaneously through a single-step deployment with zero manual intervention.
Secure recovery key management
Automate key generation and securely store or retrieve recovery keys via Active Directory or cloud services.
Close encryption blind spots
Ensure every device is encrypted, every key is secured, and no endpoint goes undetected or unprotected.
Automated compliance reporting
Auto-generate audit-ready reports and enforce encryption policies organization-wide without manual effort.
Server Management
Full server lifecycle management
Deploy OS images, configure system settings, and install software, managing every server from provisioning to decommissioning.
Unified multi-OS caching
Replace separate OS caches with one unified caching server, centralising updates, patches, and software distribution.
Self-service patch control
Lets application owners schedule patches within operational maintenance windows via a self-service portal.
Streamlined I&O and application owner collaboration
Integrate with Zoho Creator to automate multi-level patch approvals and generate deployment drafts automatically.
Remote monitoring and maintenance
Continuously monitor server health and remotely check logs, restart services, modify configurations, and apply patches.
Vulnerability detection and CIS compliance
Detect vulnerabilities across apps, servers, OSs, and browsers with out-of-the-box CIS Benchmark policies for immediate remediation.
Let us take care of your endpoints, while you take care of your business.
» Patch Management Process
» Windows Patch Management
» Mac Patch Management
» Linux Patch Management
» Patch Deployment
» Deploying Non-Microsoft Patches
» AntiVirus Update
» Third Party Patch Management
» Windows Updates
» Service Pack Deployment
» Patch Management Reports
» Software Repository
» Software Installation
» Windows Software Deployment
» Mac Software Deployment
» Self Service Portal
» Vulnerability management & Threat mitigation
» Browser security
» Device control
» Application control
» BitLocker management
» Malware Protection
» Anti-Ransomeware protection
» Endpoint Detection and Response
» Secure Private Access
» Advanced, Automated Deployment Methods
» Hardware Independent Deployment
» Modern Disc Imagining
» Windows 10 Migration
» Remote OS Deployment
» Customize OS Deployment
» IT Asset Management process
» Asset Tracking
» Software Metering
» Warranty Management
» Software License Compliance
» Prohibited Software
» Block Application
» Software Assets
» Hardware Assets
» Mobile Device Management for iOS devices
» Mobile Device Management for Android
» Mobile Device Management for Windows
» Mobile Application Management (MAM)
» Bring Your Own Device (BYOD)
» Remote Desktop Sharing
» Shutdown & Wake On tool
» Check Disk & Clean Disk
» Check Disk & Clean Disk
» Custom Script
» USB Device Mgmt